Skip to content

Commit

Permalink
Update rules/integrations/endpoint/impact_elastic_ransomware_detected…
Browse files Browse the repository at this point in the history
….toml

Co-authored-by: Terrance DeJesus <[email protected]>
  • Loading branch information
Samirbous and terrancedejesus authored Dec 18, 2024
1 parent 36e5e48 commit 72443d4
Showing 1 changed file with 0 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -44,8 +44,6 @@ Generally, our ransomware protection is tuned to have extremely low false positi
- Installers and backup software, which can make a large number of modifications to documents (especially during a restore operation).
- Encryption or system utilities which modify the system’s MBR may also trigger our MBR protection.
### Response and Remediation
- Immediate Isolation and Containment: Quickly disconnect affected systems from the network, including both wired and wireless connections, to prevent the ransomware from spreading. This includes disabling network cards and removing network cables if necessary, while keeping the systems powered on for forensic purposes.
Expand Down

0 comments on commit 72443d4

Please sign in to comment.