Ransomware-ReconAlerts

Click here to go back to the stages screen

Run HUNT to show the
Full packet details

View Full Event to see
Contextual information

Click here to show all alerts

This is the ALERTS Pane. Within this view, you’re presented with the alerts relevant to your investigation.

In this instance, we’re viewing the RECON alerts

RECON is typically the first stage of any malware or ransomware campaign, and is often creates more noise on within the network than an analyst can handle, so these types of activities are most often ignored.

IronDefense helps prioritize the noisy RECON alerting to assist in reducing that noise, allowing you to focus on what truly matters most.

This pane also allows an analyst to see if any other analysts have previously seen, triaged, or commented on any given alert indicator, as depicted by the green circle with three dots