User Profile
DanAlexander
Copper Contributor
Joined 4 years ago
User Widgets
Recent Discussions
Re: Ransomware alert
AmolShelar,unfortunately, I do not have granular visibility on the endpoint' active processes and cannot inspect if there are any suspicious remote connections attempts. Can you please, based on your experience suggest a questionnaire for the technical Team to address potential adversaries on the endpoint? Your help is much appreciated!1.7KViews0likes0CommentsRe: Ransomware alert
Thanks for the reply. All checks were made and all looks good. However, I would like to understand if there is something else that caused the PGHook to be listed in the timeline as the main contributor to the alert? For example bad WMI image load, DLL sharing issues etc.?1.7KViews0likes2CommentsRansomware alert
Morning community, I have a question and I hope I am in the right place. We use M365 Defender as a SIEM solution and a Ransome alert came recently. In the timeline, there were more than 10 instances of taskkill involved. As far as I am informed the tool is set up to trigger an alert on several taskkill execution events. However, there was a PGHook.dll clipped/involved in the mix and has a direct link to the Ransomware in the timeline. My question is: Would the PGHook.dll had assisted in creating the alert or did the M365 defender pick up only on the number of taskkill events? Thank you in advance. Dan1.8KViews0likes5Comments
Groups
Recent Blog Articles
No content to show