# Muse.Ment Incident Response

Muse.Ment is a subsidiary of **circ.us** focused on running fun amusement parks.

An incident occurred yesterday in which the park was unable to function. Rides and other components of the park were stuck in place or unable to start. Employees also noticed issues opening programs and accessing workplace files. At that time, the IT team discovered that files appeared encrypted and ransomware was present on each system.

A copy of the ransomware was captured as well.  
Captures are provided using open-source tools.

---

## Environment Overview

Each system is organized into a root directory named after its **IP address**.

> **Note:** This may or may not be relevant.

Each directory will contain either:
- A single `.raw` file, or
- Several `.zip` files

---


## Windows Host Captures

Windows hosts were captured using the following tools:

- https://github.com/forensicanalysis/artifactcollector  
- https://github.com/orlikoski/CyLR

### Capture Details

- `%hostname%.zip`  
  - Can be used in **log2timeline** and **TimeSketch**

- `%hostname-%date%.zip`  
  - Contains logs and organized artifacts from **ArtifactCollector**

---

## Additional Artifacts

- A **memory dump** may be provided on some hosts (may or may not be relevant)
- Some systems may include a **raw disk dump**, noted by the `.raw` extension

---

## Important Note

**You do NOT have the passwords to these systems. Do not attempt to log in.**  
That is not what Incident Response is about.

---

**Good luck!**



