Ransomware Dashboard
The Ransomware Dashboard for QRadar shows a list of suspected ransomware events.

The Ransomware dashboard contains the following cards:
-
Offenses – List of offenses that QRadar detects from the file activity data as potential ransomware attacks
- See the Table Card Features topic for additional information.
-
Details of Ransomware Attack – Tabular format of all file activity events for the selected offense which occurred over the specified time interval
- Only visible after clicking Search on an offense
- See the Table Card Features topic for additional information.
-
Breakdown of File Types – Pie chart of the top eight file extensions of the affected files for the selected offense
- Only visible after clicking Search on an offense
QRadar generates the offenses based on the Netwrix: Ransomware Detected rule that this application includes. To adjust this rule to better suit your organization’s needs, see the IBM QRadar Rule management article on how to modify rules.