Ransomware (v1.0.21)

This pack is used to identify, investigate, and contain ransomware attacks.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Forensics & Malware Analysis

Incident fields (10)

Layouts (1)

Playbooks (2)

Scripts (2)

README

When a ransomware attack is detected, for example by your endpoint protection service, this pack can help you better understand your position and exposure against the threat actor group by collecting the needed information from your environment, performing the required investigation steps, containing the incident, and visualizing the data with its custom Post Intrusion Ransomware layout.

What does this pack do?

The main features of the semi-automated Post Intrusion Ransomware Investigation playbook included in the pack are:

Integrations

Integrations required for this pack.