Ransomware Behaviour Detected
Informational
False Positive
ALR-00210 · 2026-05-23T23:15:45Z
Description
File encryption behaviour detected on WS-PC-002. 142 files renamed with .locked extension in 30 seconds. Dark Web Monitor isolated endpoint.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
23:15:45
Event ingested by SOC365 Engine
23:15:47
EmilyAI triage started — correlation enrichment
23:15:51
EmilyAI confidence: 98% — escalated to human analyst
23:16:00
Alert assigned to analyst: EmilyAI (auto)
23:17:49
Investigation started — querying SIEM and threat intelligence
23:25:22
Containment action taken — endpoint isolated
23:31:01
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00326 | 9h ago | Ransomware Behaviour Detected | Low | False Positive | SRV-APP-01 |
| ALR-00130 | 11h ago | Ransomware Behaviour Detected | Medium | Escalated | WS-MAC-005 |
| ALR-00333 | 13h ago | Ransomware Behaviour Detected | High | Open | AP-WIFI-03 |
| ALR-00024 | 18h ago | Ransomware Behaviour Detected | Low | Escalated | WS-PC-004 |
| ALR-00338 | 1d ago | Shadow IT Discovery | Low | Resolved | WS-PC-002 |