Hi
Does anyone have examples of how to use Splunk enterprise to investigate and contain ransomware?
I would like to detect it quickly - any recommendations?
Can you share any logs from real ransomware? or screenshots? I have alerts on some ransomware popular ports like 445 etc. I am just wondering what is like red frag, traffic pick etc? Many thanks
The Splunk Security Essentials app has many use cases for detecting behaviors indicative of ransomware.