Ransomware Behaviour Detected
Medium
Escalated
ALR-00239 · 2026-04-11T12:17:14Z
Description
File encryption behaviour detected on SRV-WEB-01. 142 files renamed with .locked extension in 30 seconds. Dark Web Monitor isolated endpoint.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
12:17:14
Event ingested by SOC365 Engine
12:17:17
EmilyAI triage started — correlation enrichment
12:17:24
EmilyAI confidence: 96% — escalated to human analyst
12:17:49
Alert assigned to analyst: James Okonkwo
12:18:41
Investigation started — querying SIEM and threat intelligence
12:23:49
Containment action taken — endpoint isolated
12:36:08
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00243 | 38m ago | Unauthorised USB Device | Medium | Resolved | SRV-WEB-01 |
| ALR-00415 | 3h ago | Ransomware Behaviour Detected | Medium | Escalated | AP-WIFI-03 |
| ALR-00053 | 3h ago | Ransomware Behaviour Detected | Medium | False Positive | SRV-BACKUP-01 |
| ALR-00134 | 5h ago | Ransomware Behaviour Detected | Informational | Resolved | WS-PC-003 |
| ALR-00140 | 11h ago | DecoyPulse Honeypot Triggered | Informational | Resolved | SRV-WEB-01 |