Post-Incident Report — Stopping a RansomOp Before Ransomware

This write-up recounts the step-by-step progression of an actual attack in progress believed to be connected to UNC2447, a group associated with Five Hands Ransomware. 

Read the report to learn more about:

  • The timeline of activities observed. 
  • Attacker signatures and alert context. 
  • Initial detection by the NDR solution through to actual mitigation steps.

Request Free!