Ransomware Behaviour Detected
High
Open
ALR-00002 · 2026-05-21T09:25:43Z
Description
File encryption behaviour detected on FW-EDGE-01. 142 files renamed with .locked extension in 30 seconds. Endpoint Agent isolated endpoint.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
09:25:43
Event ingested by SOC365 Engine
09:25:47
EmilyAI triage started — correlation enrichment
09:25:51
EmilyAI confidence: 92% — escalated to human analyst
09:26:07
Alert assigned to analyst: James Okonkwo
09:27:58
Investigation started — querying SIEM and threat intelligence
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00224 | 33m ago | Anomalous DNS Query | Informational | Resolved | FW-EDGE-01 |
| ALR-00426 | 6h ago | Unusual Outbound Traffic | Low | Investigating | FW-EDGE-01 |
| ALR-00010 | 15h ago | Ransomware Behaviour Detected | Medium | False Positive | WS-PC-002 |
| ALR-00012 | 22h ago | Ransomware Behaviour Detected | Medium | Open | WS-PC-004 |
| ALR-00375 | 1d ago | Suspicious PowerShell Execution | Informational | False Positive | FW-EDGE-01 |