Ransomware-as-a-service (RaaS) has transformed how attacks scale. When Medusa transitioned to RaaS in early 2023, its attack volume surged from 300 victims over four years to more than 200 additional victims in just over a year. This acceleration results directly from affiliates and initial access brokers acting as a supply chain. Your team needs to disrupt that chain systematically at multiple points.
This playbook guides you in hardening the three entry vectors RaaS operators rely on: unpatched vulnerabilities, credential compromise, and remote access abuse. You'll build detection for initial access broker tactics, segment networks to contain lateral movement, and establish rapid patch deployment that outpaces exploit timelines.
What You Need Before Starting
Authority and Access:
- Administrative rights to patch management systems, network segmentation infrastructure, and endpoint detection platforms.
- Approval to modify firewall rules and disable legacy remote access protocols.
- Budget for vulnerability scanning tools if continuous monitoring isn't already in place.
Current State Documentation:
- Complete asset inventory, including software versions, firmware, and operating systems.
- Map of remote access points: VPN concentrators, RDP exposure, remote monitoring tools.
- List of privileged accounts and their authentication methods.
- Network diagram showing trust boundaries and lateral movement paths.
Team Coordination:
- IT operations lead for patch deployment windows.
- Network engineering for segmentation rule changes.
- Security operations for alert tuning and response procedures.
- Communications plan for user-facing changes to remote access.
Tools You'll Configure:
- Vulnerability scanner with API integration (Tenable, Qualys, or Rapid7).
- SIEM or log aggregation platform for detection rules.
- Network access control or firewall management console.
- Endpoint detection and response platform.
Step-by-Step Implementation
Week 1: Accelerate Vulnerability Management
RaaS groups exploit new vulnerabilities within 24 hours of announcements. Your patch cycle must match that speed for remotely exploitable flaws.
Day 1-2: Establish Critical Vulnerability Criteria
Define triggers for emergency patching. Use CISA's Known Exploited Vulnerabilities catalog as your baseline, adding:
- Any remotely exploitable vulnerability with a CVSS base score of 9.0 or higher.
- Vulnerabilities in remote access software (VPN, RDP gateways, remote monitoring tools).
- Authentication bypass or privilege escalation flaws in internet-facing systems.
Configure your vulnerability scanner to flag these automatically and send alerts to a dedicated Slack channel or email list.
Day 3-5: Build the 48-Hour Patch Pipeline
Streamline the process for critical vulnerabilities:
- Automated scan runs daily at 0600 local time.
- Alert triggers if a new critical vulnerability appears.
- IT operations receives notification with affected asset list by 0800.
- Patch testing begins immediately in a non-production environment.
- Production deployment starts within 48 hours of vendor patch release.
Document the approval chain for emergency patching. Organizations that patched CVE-2025-10035 Fortra GoAnywhere and CVE-2026-1731 BeyondTrust within 24-48 hours avoided exploitation. Those waiting for standard cycles became victims.
Day 6-7: Implement Compensating Controls
For systems that can't be patched immediately:
- Restrict network access using firewall rules (source IP allowlisting).
- Require VPN access before reaching vulnerable services.
- Enable enhanced logging on vulnerable systems.
- Schedule daily manual checks of access logs.
Week 2: Detect Initial Access Brokers
Initial access brokers sell network access to RaaS affiliates for $100 to $1 million, often gaining access weeks or months before an attack. Your detection needs to catch them during reconnaissance.
Day 8-10: Deploy Enumeration Detection Rules
Configure your SIEM to alert on:
- Advanced IP Scanner, SoftPerfect Network Scanner, or similar tools running on endpoints.
- PowerShell execution with Base64-encoded commands.
- WMI queries for system information from non-administrative accounts.
- Multiple failed authentication attempts followed by successful login.
- New scheduled tasks created outside business hours.
Create a playbook for security operations: when these alerts fire, check for lateral movement indicators within 15 minutes.
Day 11-12: Harden PowerShell Logging
Enable PowerShell script block logging on all Windows systems:
Group Policy > Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell
Enable "Turn on PowerShell Script Block Logging"
Configure transcript logging to a centralized location that attackers can't easily delete:
Group Policy > Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell
Enable "Turn on PowerShell Transcription"
Set output directory to \\secure-log-server\pslogs\%COMPUTERNAME%
Centralized logging prevents Medusa actors from deleting PowerShell command history to hide activities.
Day 13-14: Audit Remote Access Tools
Inventory all remote monitoring and management software: TeamViewer, AnyDesk, ConnectWise, Atera, and similar tools. For each:
- Document business justification.
- Verify it's on the latest version.
- Confirm it requires authentication.
- Check if it allows unattended access (disable if not needed).
- Review access logs for the past 90 days.
RaaS affiliates use legitimate remote access software to evade detection. Remove tools without a business need.
Week 3: Network Segmentation and Access Control
Lateral movement turns initial access into full compromise. Segmentation limits how far an attacker can move before detection.
Day 15-17: Map and Segment Critical Assets
Identify your crown jewels:
- Domain controllers and authentication servers.
- File servers containing sensitive data.
- Backup infrastructure.
- Financial systems and databases.
Create firewall rules that:
- Deny all traffic to these systems by default.
- Allowlist specific source IPs or subnets with business justification.
- Block RDP (TCP 3389) from workstation VLANs to server VLANs.
- Require jump hosts for administrative access.
Day 18-19: Filter Unknown Origins
Configure perimeter firewalls to block inbound connections to internal remote services unless they originate from known VPN concentrators. Specifically:
- Block TCP 3389 (RDP) from the internet.
- Block TCP 5900 (VNC) from the internet.
- Block TCP 22 (SSH) to Windows systems from untrusted networks.
- Review and disable any port forwarding rules older than 90 days.
Day 20-21: Implement Just-in-Time Access for Privileged Operations
Configure your Privileged Access Management system (or Active Directory if you don't have PAM) to:
- Require approval for domain admin group membership.
- Auto-expire elevated privileges after 4 hours.
- Log all privileged session activity.
- Alert when privileged accounts authenticate outside business hours.
Week 4: Backup Protection and Response Readiness
RaaS operators terminate backup processes and delete shadow copies before deploying ransomware. Your backups need to survive a compromised network.
Day 22-24: Air-Gap Backup Infrastructure
Separate backup systems from the production network:
- Use a dedicated backup VLAN with strict firewall rules.
- Require MFA for backup administrator access.
- Implement immutable backup retention (write-once-read-many storage).
- Test offline backup restoration monthly.
Configure backup software to alert if:
- Backup jobs fail three consecutive times.
- Shadow copies are deleted.
- Volume Shadow Copy Service (VSS) is disabled.
Day 25-27: Disable Vulnerable Drivers and Tools
Medusa actors use vulnerable or signed drivers to kill endpoint detection processes. Create application control policies that:
- Block known vulnerable drivers (maintain list from LOLDrivers project).
- Require approval for PsExec, PDQ Deploy, BigFix deployment outside IT operations subnet.
- Alert when process termination tools run on endpoints.
Day 28-30: Tabletop Exercise and Documentation
Run a 90-minute tabletop exercise simulating a RaaS attack:
- Initial access via unpatched VPN appliance.
- Lateral movement using legitimate remote access software.
- Data exfiltration via Rclone.
- Ransomware deployment via PsExec.
Document gaps identified during the exercise and assign remediation owners.
Validation: How to Verify It Works
Test Vulnerability Response Time: Subscribe to a test CVE announcement feed. When a new critical vulnerability drops, track time from announcement to:
- Detection in your environment (should be within 24 hours).
- Patch availability confirmation (vendor-dependent).
- Test deployment (should start within 24 hours of patch release).
- Production deployment (should complete within 48 hours for critical remotely exploitable flaws).
Verify Detection Rules: Use atomic red team tests or similar frameworks to simulate:
- Network scanning with Advanced IP Scanner.
- PowerShell-based enumeration.
- Unauthorized RDP sessions.
- Shadow copy deletion commands.
Confirm your SIEM generates alerts within 5 minutes.
Test Segmentation: From a standard user workstation, attempt to:
- RDP to a domain controller (should fail).
- Access backup server shares (should fail).
- Connect to database servers on management ports (should fail).
From a jump host with proper credentials, verify the same connections succeed.
Validate Backup Resilience: Simulate compromise by:
- Attempting to delete shadow copies from a test system.
- Trying to access backup storage from a non-backup-admin account.
- Verifying immutable backup retention prevents deletion.
Restore a test system from backup without network connectivity to production.
Maintenance and Ongoing Tasks
Daily:
- Review vulnerability scan results for new critical findings.
- Check SIEM alerts for enumeration activity.
- Verify backup job completion.
Weekly:
- Audit new remote access software installations.
- Review privileged account access logs.
- Update firewall rules based on legitimate business requests.
- Check for new vulnerable driver signatures.
Monthly:
- Test offline backup restoration.
- Review and update critical vulnerability criteria.
- Audit network segmentation rules for drift.
- Conduct mini-tabletop exercise with on-call team.
Quarterly:
- Full-scale ransomware tabletop exercise.
- Review initial access broker tactics from threat intelligence feeds.
- Audit all remote access points and business justifications.
- Update detection rules based on new RaaS TTPs.
The RaaS model turns ransomware into a scalable business with specialized roles. Your defenses need the same systematic approach: rapid vulnerability management disrupts exploit developers, access controls frustrate initial access brokers, and segmentation contains affiliates who make it through. Build these capabilities in sequence, validate each one, and maintain them as operational disciplines rather than one-time projects.





