Ransomware staged and stopped in four minutes
An initial-access broker sold credentials to a regional bank’s VPN. The affiliate had 90 minutes inside the estate before deploying an encryptor. Sentinel correlated the impossible-travel sign-in, the LSASS access and the SMB spread into one incident, then executed containment within the agreed policy envelope.
- T+00:00Anomalous VPN sign-in from unassigned ASN, entity risk raised
- T+00:41LSASS memory access on finance workstation flagged critical
- T+01:22Lateral SMB enumeration across 14 hosts correlated to same entity
- T+04:11Playbook isolated 14 hosts, revoked sessions, blocked egress
- T+22:00Forensic report and regulator notification drafted from evidence timeline
- 4:11
- TIME TO CONTAINMENT
- 0
- SYSTEMS ENCRYPTED
- 0
- HOURS DOWNTIME