This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

WannaCry Alert

Has anyone created a WannaCry LEM alert. This threat might have subsided due to the Kill switch but I am thinking others are coming.

Based on a few blog posts I have read I created a rule that looks on our file server for the below files.

@Please_Read_Me@.txt

testonly.wnry

.wcry

.wncry

.wncryt

This is what I have so far, but I was interested in others feedback.

2017-05-15_10-57-52.jpg

Parents
  • What kind of setup do you have in your FIM connector to detect file name changes? I have not been able to get a combination that will detect file name changes for some reason yet.

    I think your rule would work based on that though for alerting purposes.

Reply
  • What kind of setup do you have in your FIM connector to detect file name changes? I have not been able to get a combination that will detect file name changes for some reason yet.

    I think your rule would work based on that though for alerting purposes.

Children
No Data