Supply Chain Attack: Fighting back against REvil ransomware | #ransomware | #cybercrime


A leading provider of dental insurance had two MDR partners at the time of the Kaseya attack. In addition to Red Canary MDR, they also used a legacy, SIEM-based MDR provider that enabled them to comply with industry regulations through the 24×7 monitoring and retention of all logs.

But while they had duplicative MDR providers, only Red Canary alerted them to the attack on that Fourth of July weekend, resulting in little to no business impact.

Red Canary observed and detected a slew of suspicious behaviors and alerted on that activity right away, empowering the dental insurance provider to understand the full story on Kaseya and mitigate the threat before any ransomware was detonated or endpoints encrypted.

If not for Red Canary, this leading dental insurance provider would have been blind to the attack. Other security providers, such as their legacy MDR, generally look at events and attempt to correlate them. On the contrary, they explained, “Red Canary focuses on behavioral analytics, which are essential in the modern landscape, not just IOCs or alerts.”

To date, every incident alert they’ve received—and every detection that has turned into an actual incident—has come from Red Canary, not their legacy MDR provider. Consequently, they are hoping to drop their legacy MDR provider altogether and use Red Canary exclusively.



Click Here For The Original Source.

——————————————————–

..........

.

.