JELAJAH SOC
YO

INC-1043 · owner A. Pratama

Ransomware staging detected on SRV-FILE-03

Canary files were encrypted and shadow copies deleted on the primary file server using a compromised backup service account.

All incidents
criticalEradicationSLA 1h response · breached by 12mcollaborators: S. Hartono, You

Evidence panel

Pivotable entities

MITRE ATT&CK

T1486T1490

Attack timeline

Build the sequence of the intrusion

  1. 07:44

    vssadmin delete shadows

    Shadow copies removed

  2. 07:45

    Mass rename

    1,204 files renamed to .lkd

  3. 07:47

    Ransom note

    README_RESTORE.txt written

Linked alerts

Containment actions

  • File server isolated
  • svc_backup disabled
  • Backup integrity verified offline

Recommendations

  • Move backup service to a gMSA
  • Deny interactive logon for service accounts
  • Test restore procedure quarterly

Case tasks

  • Identify initial access vectorS. Hartono
  • Rebuild file server from clean imageA. Pratama

Investigation notes

    Audit trail

    • System · Incident auto-created from critical alert ALT-24051970-01-01 07:45:00Z