Was Petya (2016) the first widely observed ransomware to overwrite the MBR and run its locker during boot, or is there an earlier sample I should cite? From a containment standpoint, my bet was on isolating hosts and restoring from offline backups rather than attempting live recovery — curious if anyone had better luck with other controls.