Overview
Leveraging EDR to Combat Advanced Malware Threats in HealthcareRedscan |
Cybersecurity & Privacy - Intrusion Detection Cybersecurity & Privacy - Malware Protection | |
Healthcare & Hospitals National Security & Defense | |
Intrusion Detection Systems Tamper Detection | |
Cybersecurity Services Training | |
Operational Impact
The incident response capabilities of Redscan’s Managed Endpoint Detection and Response service proved crucial in quickly identifying and responding to the malware attack. The service's Proactive Intrusion Detection System (IDS) and Security Information and Event Management (SIEM) monitoring helped identify the attack, while Carbon Black’s Response solution enhanced event visibility, threat hunting, and incident response. The Redscan team was able to quickly isolate all infected hosts from the network, preventing additional infections. The team also conducted a detailed digital forensics investigation to understand the kill chain of the attack. Following the incident, the Redscan team prepared a detailed report for the client, including a full event timeline and a list of recommendations to help mitigate the risk of future attacks. | |
Quantitative Benefit
Quick identification and response to the malware attack, minimizing operational disruption | |
Successful isolation and cleaning of all infected machines | |
No evidence of data loss despite the malware's attempt to conduct an internal network IP scan | |