Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →If ransomware is changing SharePoint files through a synced computer or mapped drive, stop OneDrive sync or disconnect the mapped drive immediately. Then investigate both the Microsoft 365 activity and the endpoint or account that made the changes. Restore files only after the attack is contained and you have selected a known-clean recovery point.
What to do first during a suspected SharePoint ransomware attack
- Stop the path carrying changes to SharePoint. Stop OneDrive sync on affected computers or disconnect a mapped drive to the SharePoint library. This limits further changes in the local-device sync pattern Microsoft describes; it does not, by itself, stop an attacker who has direct access to Microsoft 365.
- Set up secure incident communications. Coordinate with your incident response team over a channel you believe is safe. Prioritize containment while the investigation proceeds.
- Preserve evidence and record the incident. Avoid wiping or rebuilding potentially compromised systems before responders can preserve them for analysis. Start a timeline, record affected SharePoint site collection URLs, and note the last time the files were known to be clean.
- Assess credentials and backups. Identify potentially compromised credentials for reset, and consider disconnecting online backups until the attack is contained. Do not assume that restoring files will remove an infected endpoint or attacker access.
If activity is ongoing, the incident affects multiple sites, or there are signs of compromised identity or administrative control, involve qualified incident-response help. A file restore is not a substitute for investigating and containing a wider compromise.
How to tell whether a SharePoint library may be affected
Microsoft identifies these as signs of ransomware in a SharePoint library. Treat them as indicators to investigate, not as proof on their own of what happened or how far the incident reached.
- Many files have the same Modified By timestamp.
- Files fail to open or appear corrupted.
- Ransom instructions appear in directories.
- Files have been renamed or have an extension appended.
Record which libraries and users are affected, then look for the endpoints and accounts associated with their changes. Also check whether suspicious access is continuing. A visible file pattern alone cannot establish whether an attacker accessed other content or gained control of an account.
Recommended Free Tools
#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
How to investigate file and account activity
Review Microsoft 365 audit records
Use Microsoft 365 audit records to reconstruct SharePoint and OneDrive activity around the incident. Relevant recorded activity can include file modifications, renames, uploads, downloads, malware detections, recycle events, and restore events. Audit logging is on by default for Microsoft 365 organizations, but confirm that logging is available for your tenant and check its retention before relying on the records.
Correlate cloud events with the source
Compare the file-event timeline with endpoint, identity, network, and security logs. The goal is to identify which device or account wrote the changes and whether that device or account is still being used. Preserve compromised systems for analysis where possible rather than treating the SharePoint activity log as the whole incident record.
Rank #2
- Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Determine whether the incident extends beyond documents
Assess the scope of affected sites, users, endpoints, and accounts. Identify business applications that are unavailable and whether tested backups exist. If logs or account activity suggest compromised identity or administrative control, determine whether compromise recovery is needed to remove the attacker’s control—not merely recovery of changed files.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Which SharePoint recovery option fits the damage?
Choose the narrowest option that can restore a known-clean state. Microsoft documents the following recovery paths; availability depends on what versions, recycle-bin items, or backup restore points remain in your tenant.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Quick Recap
Best Value
- [Upgraded Version] - This external hard drive features a mirrored logo stripe combined with a striped anti-slip design, and the rounded corners of the casing make it easier to grip. The stripes also have a heat dissipation function, ensuring stable and fast data transfer.
- 【Ultra-thin and quiet】 - The motherboard adopts JMicron 578 noise-free solution, giving you a quiet working environment. Lightweight and portable size designed to fit in your pocket for easy portability.
- 【Ultra-Fast Data Transfers】 - Pairing this external hard drive with JMicron 578 solution USB 3.0 and USB 2.0 interfaces enables blazing-fast data transfer. It boasts theoretical read speeds of up to 125MB/s and write speeds of up to 103MB/s.
- 【Plug and Play】 - With no software to install, just plug it in and the drive is ready to use.The hard disk chip is wrapped with an aluminum anti-interference layer to increase heat dissipation and protect data.
- 【What You Get】 - 1 x Portable Hard Drive, 1 x USB 3.0 Cable, 1 x User Manual, Gift-type shell packaging ,Three-year manufacturer's warranty and free technical support services.
Rank #4
- Easily store and access 4TB of content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Rank #3
- Easily store and access 1TB to content on the go with the Seagate Portable Drive, a USB external hard drive.Specific uses: Personal
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop. Reformatting may be required for Mac
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
| Recovery option | Best fit | Scope and limits |
|---|---|---|
| Previous file version | Damage is limited to particular files and an earlier clean version is available. | SharePoint version history lets a user view and restore an earlier file version. It will not address attacker access or establish that other files are clean. |
| Document library restore (Files Restore) | Changes affect many files in a library and a point before the malicious changes is available. | Microsoft says Files Restore can move a document library to a point in the previous 30 days. It relies on file versions, so reduced version retention can limit recovery. |
| SharePoint recycle bin | Files or other items were deleted. | Deleted items may be restored from the SharePoint recycle bin or site collection recycle bin. Microsoft documents 93 days of retention from deletion in the original location. |
| Microsoft 365 Backup | A suitable backup restore point exists and recovery needs to cover a site or selected files or folders. | Microsoft documents full SharePoint site and granular file or folder restores. Restore-point cadence varies by restore type and age; check the available points and choose a healthy destination, which may be the original or a new location. Do not assume Backup was enabled or that a suitable point exists. |
| Microsoft Support | Content cannot be restored from the site collection recycle bin. | Microsoft says to contact support within 14 days after content is removed from the site collection recycle bin, and provide the affected site URLs and last known clean modification time. This is a request window, not a guarantee of recovery. |
Compare clean-point age, scope, and disruption
Before choosing, answer these questions:
- How old is the last known healthy state? Use a point that predates the malicious changes, not simply the newest restore point.
- How much content is affected? A file-level restore may be enough for isolated damage; a library or site restore may be more appropriate for broader changes.
- How granular is the restore? Confirm whether you can select individual files or folders, or whether the recovery replaces a larger unit.
- Where will restored content go? Check whether the option replaces existing content or allows a new destination, and account for disruption to users.
- Are the needed versions or restore points still available? Version limits, retention, and backup cadence can affect what can be recovered.
How to restore safely and verify the result
- Contain the attack before returning content to normal use. Remove the ransomware payload, reset known-compromised credentials, and verify that unauthorized access to Microsoft 365 has been addressed. Microsoft’s ransomware guidance conditions restoration from offline backups on malware removal and verification that unauthorized tenant access is no longer present.
- Select a known-clean restore point. Use the incident timeline and file activity to choose a point from before malicious changes began. If you cannot establish a clean point, pause and get incident-response guidance rather than restoring an arbitrary snapshot.
- Use the recovery path that matches the affected scope. Restore only the needed files when damage is isolated; use a library or site recovery when the evidence supports that broader scope. For Microsoft 365 Backup, decide whether the original or a new location is appropriate.
- Validate before reopening normal access. Check restored files for integrity, confirm site access behaves as expected, and test business-critical workflows.
- Monitor for renewed suspicious changes. Continue reviewing activity after restoration so that a returning pattern of unauthorized changes is detected.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

