ActionAlerts

Click here to go back to the stages screen

Click here to show all alerts

Run a hunt on this event to dive into packet level data

View Full Event to see Contextual information

This is the ALERTS Pane. Within this view, you’re presented with the alerts relevant to your investigation.

In this instance, we’re viewing the Action alerts

Persistence and Expansion is critical to any successful ransomware campaign, and with that criticality, comes an opportunity for defenders to identify that increase in network load, increased use of encrypted traffic, increased number of anomalous file downloads, and lateral movement activities indicative of internal enterprise spread.

Here we have a Extreme Rates alert highlighted for triage

This pane also allows an analyst to see if any other analysts have previously seen, triaged, or commented on any given alert indicator, as depicted by the green circle with three dots