<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ransomware protection: How do I find out what triggered the alert? in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Ransomware-protection-How-do-I-find-out-what-triggered-the-alert/m-p/452784#M43615</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sanaman_0-1716163356788.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/28281i5B7B26DE38D00E82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sanaman_0-1716163356788.png" alt="Sanaman_0-1716163356788.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You may see similar to above in "Volume -&amp;gt; Security", where you could see the suspected file type.&lt;/P&gt;</description>
    <pubDate>Mon, 20 May 2024 00:06:29 GMT</pubDate>
    <dc:creator>Sanaman</dc:creator>
    <dc:date>2024-05-20T00:06:29Z</dc:date>
    <item>
      <title>Ransomware protection: How do I find out what triggered the alert?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Ransomware-protection-How-do-I-find-out-what-triggered-the-alert/m-p/452767#M43613</link>
      <description>&lt;P&gt;Hello, we are testing ARW on test volume and get alerts like:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"callhome.arw.activity.seen [ALERT]&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Description: This message occurs when ransomware activity is detected. To protect the data, a Snapshot copy has been created, which can be used to restore the original data. If your system is configured to do so, it generates and transmits an AutoSupport (or "call home") message to NetApp technical support and to the configured destinations. Successful delivery of an AutoSupport message significantly improves problem determination and resolution."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now how do I find out what caused this alert?? I've checked system manager's vol-security page, AIQ and even went to activeiq.netapp.com to check the autosupport it sent as the sections are readable from there. Absolutely no information what caused this ALERT...we have on-prem BlueXp and it doesn't support ARW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So where can I see what happened and caused snapshot creation and autosupport?&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 11:45:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Ransomware-protection-How-do-I-find-out-what-triggered-the-alert/m-p/452767#M43613</guid>
      <dc:creator>Tava</dc:creator>
      <dc:date>2024-05-17T11:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware protection: How do I find out what triggered the alert?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Ransomware-protection-How-do-I-find-out-what-triggered-the-alert/m-p/452784#M43615</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sanaman_0-1716163356788.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/28281i5B7B26DE38D00E82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sanaman_0-1716163356788.png" alt="Sanaman_0-1716163356788.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You may see similar to above in "Volume -&amp;gt; Security", where you could see the suspected file type.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 00:06:29 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Ransomware-protection-How-do-I-find-out-what-triggered-the-alert/m-p/452784#M43615</guid>
      <dc:creator>Sanaman</dc:creator>
      <dc:date>2024-05-20T00:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware protection: How do I find out what triggered the alert?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Ransomware-protection-How-do-I-find-out-what-triggered-the-alert/m-p/452788#M43616</link>
      <description>&lt;P&gt;Yes like I said I've checked that page but it only lists the suspected file types, but does not tell me why the alert was sent.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 10:15:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Ransomware-protection-How-do-I-find-out-what-triggered-the-alert/m-p/452788#M43616</guid>
      <dc:creator>Tava</dc:creator>
      <dc:date>2024-05-20T10:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware protection: How do I find out what triggered the alert?</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Ransomware-protection-How-do-I-find-out-what-triggered-the-alert/m-p/453291#M43699</link>
      <description>&lt;P&gt;How to confirm the attack's details detected from ARP&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_to_confirm_the_attack's_details_detected_from_ARP" target="_blank"&gt;https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/How_to_confirm_the_attack's_details_detected_from_ARP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security anti-ransomware volume attack generate-report output&lt;/P&gt;&lt;P&gt;&lt;A href="https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/Security_anti-ransomware_volume_attack_generate-report_output" target="_blank"&gt;https://kb.netapp.com/on-prem/ontap/Ontap_OS/OS-KBs/Security_anti-ransomware_volume_attack_generate-report_output&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 20:55:45 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Ransomware-protection-How-do-I-find-out-what-triggered-the-alert/m-p/453291#M43699</guid>
      <dc:creator>ByronE</dc:creator>
      <dc:date>2024-06-18T20:55:45Z</dc:date>
    </item>
  </channel>
</rss>

