You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: content/guides/events/event-triggers/shield-alert-events.md
+71Lines changed: 71 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -27,6 +27,7 @@ The possible alerts produced by Shield are for:
27
27
2. Suspicious sessions
28
28
3. Anomalous downloads
29
29
4. Malicious content
30
+
5. Ransomware activity (part of Shield Pro)
30
31
31
32
All Shield threat detection alert events are produced within the
32
33
[enterprise event][events] stream. These events follow the
@@ -339,6 +340,76 @@ The `additional_details` payload will provide the following details:
339
340
}
340
341
```
341
342
343
+
### Ransomware activity alert
344
+
345
+
<!--alex ignore-->
346
+
347
+
A ransomware activity alert is produced when Box Shield identifies suspicious file extensions that may be indicative of a ransomware attack. It can be identified by the Ransomware Activity value within `additional_details.shield_alert.rule_category`.
348
+
349
+
The `additional_details` payload will provide the following details:
0 commit comments