eSentire 24-7 SOC Cyber Analysts in Action
Cyber threats don't operate on a schedule, and businesses need security that works around the clock. Without continuous monitoring and expert-led threat response, organizations are left vulnerable to attacks that can cause financial and reputational damage. The eSentire 24/7 SOC Cyber Analysts in Action video provides an inside look at how eSentire's elite cybersecurity experts detect, investigate, and contain threats in real time. Watch the video now to see how a dedicated SOC team protects businesses from evolving threats. For a personalized security consultation, contact Computer SuperCenter today.
How was the ransomware attack initially detected?
The ransomware attack was first detected by the Managed Detection and Response (MDR) for endpoint using a detection rule that had been deployed several months earlier. This rule specifically looked for the BestCrypt utility being copied onto machines in a suspicious manner, which indicated the activity of a known ransomware actor.
What actions were taken during the incident response?
Once the attack was confirmed, the incident was escalated to the incident handling team. They quickly scoped the intrusion, identifying the adversary's activity across more than 250 workstations and servers. The team blocked the BestCrypt executable across all endpoints and isolated impacted systems to maintain connectivity while denying the attacker access. They also communicated with the customer to keep them informed throughout the process.
How did the team manage the BitLocker encryption issue?
The team discovered that the attackers had configured BitLocker in a way that would complicate recovery after a restart. However, they managed to cancel the restart command that would have initiated the encryption, effectively reversing the BitLocker encryption process. This timely intervention allowed them to prevent significant data loss across the impacted hosts.
eSentire 24-7 SOC Cyber Analysts in Action
published by Computer SuperCenter
Wouldn't it be relief to know you had your very own IT Department? Well that's why we are here: You can trust us. When you have an emergency, or simply need technology advice, you can trust us. Who do you turn to when your computer is down, your data is at risk, or if you finally want a regular, day-to-day service relationship? We are waiting, ready for you, whenever you need us, or on a subscribed, monthly basis. You can count on us every day, in every way.
Yes, you can trust Computer SuperCenter. We've stood the test of time, since 1984, to be specific! There is no higher rated Microsoft or Apple solution provider. Check out our Google and A+ Better Business Bureau Ratings...Then give us a call today - Doing business with us is the safe choice.
Your business can only thrive if the technology you’ve invested in runs at peak performance, every minute of every day. When you choose Computer SuperCenter as your Managed Services Provider (MSP), you’re choosing a partner with the in-house capability to proactively maintain, upgrade, continuously monitor, and intelligently evolve your systems.
In the face of tightened security, Computer SuperCenter delivers protection, disaster recovery and data privacy services to counter the proliferation of network and data breaches.
You can accomplish more than ever using the right collaboration and productivity platform. We are among the most experienced of Microsoft Solution Providers advising and deploying Microsoft Office 365 and Microsoft Azure Cloud Solutions. As a matter of fact, we won the Microsoft award as Top Cloud Solution Provider in the Metro-New York Area.