@LThibx - ah, ok; hmm...would think a folder at least would have been shown in there. I will say...investigation/forensics of these events are going to be a challenge at times. For me, it's a huge challenge because I don't use Guest Indexing, and thus no File System Analysis configuration for my Malware Detection. Inline scans have no info - just the event name, e.g. Encrypted Data (what data??), Ransomware Note (what note??), Onion Link (in what file/location??).
Does this particular server have a folder/directory you're aware of with a lot of zips? Do you have cleanup tasks for it? Those are just some of the things to think about when performing your event investigation strategies.
Does this particular server have a folder/directory you're aware of with a lot of zips? Do you have cleanup tasks for it? Those are just some of the things to think about when performing your event investigation strategies.
Statistics: Posted by coolsport00 — Feb 29, 2024 4:10 pm







