Demo: Ransomware incident response

Nexa Logistics ยท Transport ยท 400 employees
๐Ÿ†“ Free demo ยท No sign-up
Phase 1 of 3
๐Ÿ† 0/3
Phase 1 ยท Detection
Tuesday 08:47. You are a SOC analyst at Nexa Logistics, a transport company with 400 employees. The EDR fires a critical alert on the CFO's laptop: a powershell.exe child process of OUTLOOK.EXE runs a Base64-encoded command and, in the last 60 seconds, 312 files in the Documents folder have been renamed with the .lockx extension. The machine is still connected to the corporate VPN and the Finance share on the NAS is answering SMB requests from that host.
๐ŸšจEDR โ€” Critical alert #7741 ยท Ransomware behavior
08:47 HOST-FIN-CFO-03 (Madrid, user: j.sanchez) Behavior: MASS FILE MODIFICATION Parent process: OUTLOOK.EXE (PID 4892) โ†’ powershell.exe -enc JABlAHgAaAAwAC4AegBpAHAA... Files encrypted (last 60s): 312 | Extension created: .lockx Ransom note: READ_ME_TO_RECOVER.txt in 9 directories Active network destination: 10.10.20.15:445 (NAS-FINANCE, Accounting share) Network state: VPN CONNECTED | Containment: NOT ENABLED
What is your first decision?