| Best Practices for Recovery from the Malicious Erasure of Files |
|
Cyber criminals can damage their victim's computer systems and data by changing or deleting files, wiping hard drives, or erasing backups to hide some or all of their malicious activity and tradecraft. By wiping, or "zeroing out," the hard disk drives, which overwrites good data with zeroes or other characters, the criminals effectively erase or alter all existing data, greatly impeding restoration. This sort of criminal activity makes it difficult to determine whether criminals merely accessed the network, stole information, or altered network access and configurations files. Completing network restoration efforts and business damage assessments may be also hampered.
The US-CERT webpage at www.us-cert.gov hosts a wide range of tips, best practices, and threat information for business and home users. Read more: US-CERT Current Activity |