Educause Security Discussion mailing list archives

Re: [EXTERNAL] SECURITY Digest - 3 Oct 2019 (#2019-192)


From: "Hollis, Michael" <Michael.Hollis () UNTHSC EDU>
Date: Thu, 3 Oct 2019 22:08:42 +0000

I would e interested as well.

Thanks,
Mike

Get Outlook for iOS<https://aka.ms/o0ukef>
________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of SECURITY 
automatic digest system <LISTSERV () LISTSERV EDUCAUSE EDU>
Sent: Thursday, October 3, 2019 5:00:00 PM
To: SECURITY () LISTSERV EDUCAUSE EDU <SECURITY () LISTSERV EDUCAUSE EDU>
Subject: [EXTERNAL] SECURITY Digest - 3 Oct 2019 (#2019-192)

There are 2 messages totalling 1305 lines in this issue.

Topics of the day:

  1. Ransomware Playbook (2)

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&amp;sdata=tQN2S9xCgjRGrjYPOGouZzxbVA3VgeXKz%2BZpUzRLFpo%3D&amp;reserved=0

----------------------------------------------------------------------

Date:    Thu, 3 Oct 2019 21:32:01 +0000
From:    Larry Carson <larry.carson () TJC EDU>
Subject: Re: Ransomware Playbook

I'm interested too, thank you!

Larry Carson

Office of Technology Services
903.510.2989
[TJC 
Logo]<https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.tjc.edu%2F&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&amp;sdata=vb%2FL%2BDo1JUb%2Bp%2FQ5kXF4Cf1FZ0nSmnehZPVh7pqsvAg%3D&amp;reserved=0>
PO Box 9020, Tyler, TX 75711
1400 East Fifth St., Tyler, TX 75798

Attention: The information contained in this message and/or attachments is intended only for the person or entity to 
which it is addressed and may contain confidential and/or nonpublic material. Any review, retransmission, dissemination 
or other use of, or taking of any action in reliance upon, this information by persons or entities other than the 
intended recipient is prohibited. If you received this in error, please contact the sender and delete the material from 
any system and destroy any copies.

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&amp;sdata=tQN2S9xCgjRGrjYPOGouZzxbVA3VgeXKz%2BZpUzRLFpo%3D&amp;reserved=0

------------------------------

Date:    Thu, 3 Oct 2019 21:59:32 +0000
From:    Dewight Fredrick Kramer <dfkramer () UCDAVIS EDU>
Subject: Re: Ransomware Playbook

We have looked into this here at UC Davis but have not developed anything formal, as such we would also be interested!

Thank you,


Dewight F. Kramer
Assistant CISO
University of California, Davis
One Shields Avenue
Davis, CA 95616
(530)752-1700
dfkramer () ucdavis edu<mailto:dfkramer () ucdavis edu>
https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsecurity.ucdavis.edu&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&amp;sdata=I7M3RY0jFabRwC8GruRj%2F%2Bh4%2BLRk4z8Sy1uGtTUaAyA%3D&amp;reserved=0<https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsecurity.ucdavis.edu%2F&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&amp;sdata=lfgvk8PqPSqJgxsx9sq7lEFoooI%2FQ1PGVoDGftkL6UI%3D&amp;reserved=0>


From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of "King, Ronald A." 
<raking () NSU EDU>
Reply-To: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU>
Date: Thursday, October 3, 2019 at 2:15 PM
To: "SECURITY () LISTSERV EDUCAUSE EDU" <SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Me too, please.

Ronald King
Chief Information Security Officer

Office of Information Technology
(757) 823-2916 (Office)
raking () nsu edu<mailto:raking () nsu edu>
https://nam04.safelinks.protection.outlook.com/?url=www.nsu.edu&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&amp;sdata=zvWV4gSCWZLNH%2BNTe7fFSf4wnd%2FV5VrG2XbkEICT8fA%3D&amp;reserved=0<https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.nsu.edu%2F&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&amp;sdata=yCLniq9ODdAcXLfwKtNYt3tkirvjv%2BX5%2FME5VAUtaBs%3D&amp;reserved=0>
@NSUCISO (Twitter)
[NSU_logo_horiz_tag_4c - Smaller]

From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Joey Rego
Sent: Thursday, October 3, 2019 5:13 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Ransomware Playbook

I am interested as well.  Thank you.

Joey Rego
Associate Director of Information Security
Information Technology
Lynn University
3601 N Military Trail
Boca Raton, FL 33462
561-237-7982
https://nam04.safelinks.protection.outlook.com/?url=www.lynn.edu&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&amp;sdata=TKd1naxIMi2Q3LKFUkiO51qptR4fDTxBgsnqKcIoN8A%3D&amp;reserved=0<https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.lynn.edu&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&amp;sdata=aJLexFMdfDvBGhfOGjUBRXl9pkzrGIu1fiYxusU%2Fjp0%3D&amp;reserved=0>
________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> on behalf of John Ramsey <jramsey () STUDENTCLEARINGHOUSE ORG<mailto:jramsey () STUDENTCLEARINGHOUSE 
ORG>>
Sent: Thursday, October 3, 2019 4:50:20 PM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE 
EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: Re: [SECURITY] Ransomware Playbook

I have one and am happy to share!
Sent from my Verizon, Samsung Galaxy smartphone
Get Outlook for 
Android<https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__aka.ms_ghei36%26d%3DDwMFAg%26c%3DtSGu_Pc6mPnB6zIYTZr3Sw%26r%3DPTnT2JXctjp4MTPziGqcrg%26m%3DSynK17bceWMbt_dooTOo-leAVssO48qPL8MzLnn_EXI%26s%3DwPjf0flvlyR164RzC6qod76IJztI6nHPHP-lEfY7Df4%26e&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&amp;sdata=k6trSr4941meB5%2B4q2HqMJO0nIEATQcuzh6EkMXQqrU%3D&amp;reserved=0=>

________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> on behalf of Kip Bates <kbates () HOUSING UCSB EDU<mailto:kbates () HOUSING UCSB EDU>>
Sent: Thursday, October 3, 2019 4:34:08 PM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE 
EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: [SECURITY] Ransomware Playbook

Colleagues:

I am hoping that I can find someone or someplace that has made an effort to develop a Ransomware Response playbook that 
they would not mind sharing. I understand all the preparation that needs to occur prior to an attack but I am looking 
for something that we can provide users, help desk folks, technicians and such on what actions to take if (when) they 
experience a ransomware attack. I have found a few on the web and I was wondering if someone has adapted one of these 
for their institution or have developed one that they think is particularly good.

Feel free to comment here or off-list.


Kip Bates
Associate Chief Information Security Officer
University of California, Santa Barbara


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&amp;sdata=oOdAdwrZnrdKrmmdGh85We8fU3D%2FpQWDpuH9J%2FsYGec%3D&amp;reserved=0<https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nam01.safelinks.protection.outlook.com_-3Furl-3Dhttps-253A-252F-252Fwww.educause.edu-252Fcommunity-26data-3D02-257C01-257Cjramsey-2540studentclearinghouse.org-257Ceeb9effb345442318b0a08d748429912-257C8cc02fea054043a688b6069d3eac0119-257C0-257C1-257C637057323178918904-26sdata-3DjUWrk2Wt4Gr-252BBW9ZZXxvxCnl0II1IpaYOvaKgjB5XWY-253D-26reserved-3D0%26d%3DDwMFAg%26c%3DtSGu_Pc6mPnB6zIYTZr3Sw%26r%3DPTnT2JXctjp4MTPziGqcrg%26m%3DSynK17bceWMbt_dooTOo-leAVssO48qPL8MzLnn_EXI%26s%3DwRiqkwHXt6Jf5tWQ1QiT68gVcu1m5m3M9X1VAYqNvJ4%26e&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&amp;sdata=8ErlWkCHZ6X66%2BBAFuhNJUe%2F8W0JxBveBqZpuOTaXmg%3D&amp;reserved=0=>

=======================================================

This message has been analyzed by Deep Discovery Email Inspector.

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&amp;sdata=oOdAdwrZnrdKrmmdGh85We8fU3D%2FpQWDpuH9J%2FsYGec%3D&amp;reserved=0<https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwMFAg%26c%3DtSGu_Pc6mPnB6zIYTZr3Sw%26r%3DPTnT2JXctjp4MTPziGqcrg%26m%3DSynK17bceWMbt_dooTOo-leAVssO48qPL8MzLnn_EXI%26s%3DfKkuKv3i6k7W-LRIBSa1iIePP8_8E9PyJhCtYBo-r1U%26e&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&amp;sdata=xxjgW3CPXzsl176%2B88wOmlX6dv4Hfrq2Qqaw5asbFGo%3D&amp;reserved=0=>

This email is intended for the designated recipient only, and may be confidential, non-public, proprietary, protected 
by the attorney/client or other privilege. Unauthorized reading, distribution, copying or other use of this 
communication is prohibited and may be unlawful. Receipt by anyone other than the intended recipients should not be 
deemed a waiver of any privilege or protection. If you are not the intended recipient or if you believe that you have 
received this email in error, please notify the sender immediately and delete all copies from your computer system 
without reading, saving, or using it in any manner. Although it has been checked for viruses and other malicious 
software, malware, we do not warrant, represent or guarantee in any way that this communication is free of malware or 
potentially damaging defects. All liability for any actual or alleged loss, damage, or injury arising out of or 
resulting in any way from the receipt, opening or use of this email is expressly disclaimed.

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&amp;sdata=oOdAdwrZnrdKrmmdGh85We8fU3D%2FpQWDpuH9J%2FsYGec%3D&amp;reserved=0

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&amp;sdata=oOdAdwrZnrdKrmmdGh85We8fU3D%2FpQWDpuH9J%2FsYGec%3D&amp;reserved=0

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2F&amp;data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&amp;sdata=ybapxTSl0jrRTyUZaNDzhRUFg3hpfnQabRsFyT%2F2B%2Fk%3D&amp;reserved=0

------------------------------

End of SECURITY Digest - 3 Oct 2019 (#2019-192)
***********************************************

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Current thread: