ALT-2405 · Windows Event Log
Ransomware canary file modified on file server
Canary files on SRV-FILE-03 were renamed with the .lkd extension by svc_backup within 90 seconds.
criticalInvestigatingconfidence 60% · 1970-01-01 08:37:00Z · rule DET-0311 Canary File TamperLinked to INC-1043
Detection summary
Canary files on SRV-FILE-03 were renamed with the .lkd extension by svc_backup within 90 seconds.
- Affected host
- SRV-SQL-01
- Affected user
- m.tanaka
- Source IP
- 10.20.23.211
- Detection rule
- DET-0311 Canary File Tamper
- Log source
- Windows Event Log
- Assignee
- Unassigned
Recommended actions
- Isolate the file server immediately
- Disable the service account
- Trigger the ransomware playbook
Analyst decision
Triage checklist
- 1. Confirm the detection logic matched genuine activity.
- 2. Check user and asset context for expected behaviour.
- 3. Pivot on host, user, IP and hash in the Log Explorer.
- 4. Enrich IOCs with threat intelligence.
- 5. Set a verdict and record your reasoning.