PUBLISHED CUSTOMER CASE STUDY · 2022

An investigation stopped ransomware before activation.

A global manufacturer with more than 5,000 employees and over $1 billion in annual revenue faced an advanced intrusion.

The signal behind the case

A domain-controller log-clearing event revealed an intrusion that had progressed through the network.

Reconstructing the attack

The investigation traced entry through an unrestricted internet-facing RDS server, followed by lateral movement, privileged-credential harvesting and domain-controller access. Threat intelligence connected the attacker to ransomware activity.

Containing the threat

CYREBRO’s DFIR team found the deployed ransomware before execution, removed the attacker and performed incident response from scoping through recovery. Threat hunting examined residual activity and attempts to regain access.

The work concluded with an incident report and recommendations to improve security hygiene. Existing telemetry collection supported a rapid investigation.