INC-1043 · owner A. Pratama
Ransomware staging detected on SRV-FILE-03
Canary files were encrypted and shadow copies deleted on the primary file server using a compromised backup service account.
criticalEradicationSLA 1h response · breached by 12mcollaborators: S. Hartono, You
Evidence panel
Pivotable entities
MITRE ATT&CK
T1486T1490
Attack timeline
Build the sequence of the intrusion
- 07:44
vssadmin delete shadows
Shadow copies removed
- 07:45
Mass rename
1,204 files renamed to .lkd
- 07:47
Ransom note
README_RESTORE.txt written
Linked alerts
Containment actions
- File server isolated
- svc_backup disabled
- Backup integrity verified offline
Recommendations
- Move backup service to a gMSA
- Deny interactive logon for service accounts
- Test restore procedure quarterly
Case tasks
- Identify initial access vectorS. Hartono
- Rebuild file server from clean imageA. Pratama
Investigation notes
Audit trail
- System · Incident auto-created from critical alert ALT-24051970-01-01 07:45:00Z