Get clean. Get back online. Without paying.
Reimaging removes the symptom. Finding how they got in is what stops it happening again.
Eradication that hunts persistence rather than payloads, a clean-room rebuild so recovery doesn't become re-encryption, and staged restoration that brings the business back in the order the business actually needs.
First hour
Where recovery is won or lost
Clean-room
Nothing restored into a dirty estate
No payment
Recovery planned without funding crime
Staged restoration
Restored into verified-clean environment · credentials rotated
Strain identified
LockBit-family
Entry vector
Closed
Persistence found
4 hosts
Backup integrity
Validated · offline copy
Worked to
If it's happening right now
The first hour decides how bad this gets.
Most of the damage we're called in to undo was done by well-meaning people reacting fast in the first sixty minutes. Do these things; avoid these others.
Do this
Isolate, don't destroy
Pull affected systems off the network. Do not wipe, reimage, or rebuild — you will erase the evidence needed to find the entry vector, and you'll rebuild straight back into it.
Preserve everything
Keep logs, ransom notes, encrypted samples, and email. Stop log rotation if you can. This is what identifies the strain and proves what happened.
Protect the backups first
Disconnect or lock backup systems immediately. Attackers target them deliberately, and a backup reachable from a compromised network is already at risk.
Don't do this
Don't power everything off
Shutting a machine down destroys memory evidence that can reveal keys, processes, and the operator's tooling. Isolate at the network instead.
Don't contact the attacker yet
Opening a channel starts a clock and a negotiation you haven't prepared for. Get advice and legal counsel involved before any contact.
Don't restore yet
Restoring into an estate that is still owned re-encrypts your last good copy. Clean first, then restore — in that order, every time.
Systems encrypted right now?
Isolate, preserve, and call. We'll tell you what to protect in the next ten minutes.
Which team you need
Investigate and prove. Or eradicate and restore.
In a major ransomware event you want both, running in parallel — incident response owns the investigation and the command function while this practice owns eradication and recovery engineering. For a contained infection with no regulatory dimension, this alone is enough.
Not sure which?
Call the incident line either way. Triage is the same conversation, and we'll bring the right team — you shouldn't have to diagnose your own emergency before asking for help.
Question
What happened, and how far?
Output
Evidence & root cause
Audience
Regulator, insurer, counsel
Discipline
Investigation
This service
Question
How do we get clean and back up?
Output
A working, verified-clean estate
Audience
IT, operations, the business
Discipline
Restoration engineering
What we handle
Not just the thing that announced itself.
Ransomware is the loudest malware, not the most common. Most of what we remove was quiet, and had been there far longer than anyone assumed.
Ransomware & wipers
Encryption and destruction events, including double-extortion cases where data was stolen before anything was locked.
Banking trojans
Credential and session theft targeting financial applications — the dominant commodity threat against Indonesian institutions.
Webshells & server implants
Persistent access dropped on internet-facing servers, often months before anyone notices, and the usual root of repeat defacement.
Rootkits & bootkits
Implants that survive reimaging by living below the operating system, in firmware or the boot chain.
RATs & backdoors
Remote-access tooling providing hands-on-keyboard control, frequently left behind after the initial intrusion.
Cryptominers
Resource theft that is rarely the real problem — it's proof someone else can execute code on your infrastructure.
Supply-chain implants
Malicious code arriving through a trusted update, library, or managed-service provider connection.
Dormant persistence
No active payload, just a way back in — scheduled tasks, rogue accounts, and forgotten service principals.
The method
Clean first. Restore second. Never the reverse.
Seven stages, in an order that matters more than any single technique in it.
Isolate & preserve
Contain the spread without destroying the evidence. Network isolation, forensic images and log capture before any remediation touches a disk.
Identify
Strain and family identification, entry vector, dwell time, and the full IOC set needed to sweep every other system you own.
Eradicate
Remove payload and persistence — scheduled tasks, services, registry keys, boot records, webshells, rogue accounts, and stolen credentials.
Clean-room rebuild
Stand up a verified-clean environment with rotated credentials and closed vectors. Nothing gets restored into a dirty estate.
Restore
Backup integrity tested before trust is placed in it, then staged restoration ordered by business criticality with validation at each tier.
Verify & watch
Estate-wide IOC sweep and a defined period of heightened monitoring, because reinfection usually arrives from a system nobody checked.
Harden
Close the vector that let them in and fix the conditions that let them spread — segmentation, privilege, MFA, and backup isolation.
Why reimaging alone fails
- The entry vector is still open — they walk back in the same way
- Credentials were stolen before encryption; new machines, same logins
- Persistence sits on a system nobody flagged as affected
- Backups restore the implant along with the data
- Firmware and boot-level implants survive the rebuild entirely
The payment question
We plan your recovery assuming you won't pay.
Whether to pay is a board decision made with your own legal counsel — never a technical one, and never one made at 3am under pressure from a countdown timer. What we owe you is an accurate picture of what payment does and doesn't buy.
It doesn't guarantee recovery
Attacker-supplied decryptors are routinely slow, partial, or corrupt data as they run. You are trusting the engineering of someone who just extorted you.
It doesn't unsteal your data
If information was exfiltrated before encryption, a key returns nothing. 'Proof of deletion' cannot be verified, by you or by anyone.
It may carry legal exposure
Depending on the group behind the attack, payment can breach sanctions and financial-crime obligations. That question belongs to counsel, before any contact.
It marks you
Organizations that pay are disproportionately targeted again, sometimes by the same operators using the access they never gave up.
Our position, stated plainly
Zentara does not negotiate with threat actors and does not handle or transfer ransom payments.
We will give you the technical facts you need — strain, exfiltration evidence, realistic recovery paths and timelines with and without a key — so that you and your counsel can make an informed decision. Then we recover you the best way available.
Always checked first
Some ransomware families were built badly or had keys leaked, and free decryptors exist. Correct strain identification is occasionally the difference between a free recovery and a catastrophic one — so it's the first thing we do, every time.
The backup reality check
Recovery speed is decided long before the attack.
Nothing determines how this ends more than the state of your backups on the day it happens — and that is the one variable you can still fix right now.
Reachable backups aren't backups
If it's on the domain and mounted, the attacker had it too. Immutable or genuinely offline copies are the ones that survive.
Untested backups aren't backups
Most organizations discover their restore process is broken during the only event that matters. Test restores on a schedule, not in a crisis.
Incomplete backups aren't recovery
Databases without application state, or servers without configuration, restore to something that doesn't run the business.
Not in an incident right now?
Then this is the cheapest hour you will ever spend on ransomware: verify that at least one backup copy is genuinely offline or immutable, and actually restore from it as a test. Most organizations we recover discover the answer during the incident. Yours doesn't have to.
Reporting duties start early
The 72-hour clock may already be running.
Ransomware with data exfiltration is a personal-data breach in most realistic scenarios — which under UU PDP means written notification to the authority and affected individuals, with additional OJK or BSSN obligations depending on your sector. We provide the technical facts your counsel needs to make that call.
What you get
Proof it's gone — and how it got in.
Pairs with
Recovery ends. Exposure doesn't.
Build the program
Pairs well with
Incident Response & Digital Forensics
The investigation half — evidence, root cause, and the answers a regulator will want.
Managed SOC
The weeks after an incident are when you're most likely to be probed again. Detection you don't have to staff.
Threat Hunting
Prove the estate is genuinely clean rather than merely quiet — a hunt after recovery finds what survived.
Security Awareness & Phishing Simulation
Most infections still arrive through a person. Close the vector that opened the door.
FAQ
Straight answers, including the uncomfortable ones
What executives and IT leads ask during a ransomware event — answered the way we'd answer them on the call.
They're siblings and they usually run together, but they answer different questions. IR & Digital Forensics investigates and proves — what happened, how, how far it went, and the evidence a regulator or insurer will ask for. This practice eradicates and restores — get clean, get the business running, and make sure it doesn't come back. In a major ransomware event you want both: IR runs the investigation and the command function while we run eradication and recovery engineering. For a contained malware infection with no regulatory or legal dimension, this service alone is usually enough.
Encrypted? Isolate, preserve, and call.
Don't wipe anything. Don't restore yet. Don't contact the attacker. Bring us in and we'll tell you what to protect in the next ten minutes — then get you clean and back online.