A Comprehensive Review on Windows Forensic Based Ransomware Detection and Analysis
Yogeshwar Prajapati, Krupali Gosai, Sushil Kumar Singh · 2024
With the advent of new technologies, hackers are increasingly using ransomware to lock victims’ files or whole workstations and demand payment. This malicious software encrypts user files, then keeps them for ransom. Ransomware attacks frequently target sectors like financial institutions, government agencies, and healthcare facilities. Encryption ransomware and lock screen ransomware are two types of malwares that infiltrate computers in various ways. To protect themselves from these attacks, individuals and organizations must make network security a key priority. Windows forensic techniques are used by investigators from many industries to track down and analyse ransomware infections, which in turn allows them to gather evidence of attacks and mitigate their impacts. A multi-method survey is presented here. We go into detail about the many types of ransomwares, how they are classified, and how they may be defeated, as well as the methods, tools, and attacks that can be used.