Skip to main content

Ransomware Dashboard

The Ransomware Dashboard for QRadar shows a list of suspected ransomware events.

Ransomware Dashboard for Netwrix Activity Monitor App for QRadar

The Ransomware dashboard contains the following cards:

  • Offenses – List of offenses that QRadar detects from the file activity data as potential ransomware attacks

  • Details of Ransomware Attack – Tabular format of all file activity events for the selected offense which occurred over the specified time interval

    • Only visible after clicking Search on an offense
    • See the Table Card Features topic for additional information.
  • Breakdown of File Types – Pie chart of the top eight file extensions of the affected files for the selected offense

    • Only visible after clicking Search on an offense

QRadar generates the offenses based on the Netwrix: Ransomware Detected rule that this application includes. To adjust this rule to better suit your organization’s needs, see the IBM QRadar Rule management article on how to modify rules.