Identifying the suspect files
New critical alerts may appear after a policy job runs, and, during the post-processing phase,
analyzed by anomaly scan software. When a new alert is listed in
the New Alerts table, it displays the number of infected hosts, the policy
name used for the anomaly scan software analysis job, the status,
the type of alert, and the severity.
Note: At this time, only Critical alerts with a
Pending status are displayed in the New Alerts table.
To see more detail on the critical alert, select it in the New Alerts table. The details are displayed just below the table with the Clear button, which is used to stop the alert reporting once the files have been restored to a clean condition.
From the alert details, you learn the policy name, which is the identifier of the anomaly scan software analysis job, along with the type of encryption or infection method used by the ransomware, and the MAC address of the anomaly scan software server. The next step is remediation of the suspect files.