Demo: Ransomware incident response
Nexa Logistics ยท Transport ยท 400 employees
๐ Free demo ยท No sign-upPhase 1 of 3
๐ 0/3
Phase 1 ยท Detection
Tuesday 08:47. You are a SOC analyst at Nexa Logistics, a transport company with 400 employees. The EDR fires a critical alert on the CFO's laptop: a powershell.exe child process of OUTLOOK.EXE runs a Base64-encoded command and, in the last 60 seconds, 312 files in the Documents folder have been renamed with the .lockx extension. The machine is still connected to the corporate VPN and the Finance share on the NAS is answering SMB requests from that host.
๐จEDR โ Critical alert #7741 ยท Ransomware behavior
08:47 HOST-FIN-CFO-03 (Madrid, user: j.sanchez)
Behavior: MASS FILE MODIFICATION
Parent process: OUTLOOK.EXE (PID 4892) โ powershell.exe -enc JABlAHgAaAAwAC4AegBpAHAA...
Files encrypted (last 60s): 312 | Extension created: .lockx
Ransom note: READ_ME_TO_RECOVER.txt in 9 directories
Active network destination: 10.10.20.15:445 (NAS-FINANCE, Accounting share)
Network state: VPN CONNECTED | Containment: NOT ENABLED
What is your first decision?