公式動画ピックアップ
AAPL
ADBE
ADSK
AIG
AMGN
AMZN
BABA
BAC
BL
BOX
C
CHGG
CLDR
COKE
COUP
CRM
CROX
DDOG
DELL
DIS
DOCU
DOMO
ESTC
F
FIVN
GILD
GRUB
GS
GSK
H
HD
HON
HPE
HSBC
IBM
INST
INTC
INTU
IRBT
JCOM
JNJ
JPM
LLY
LMT
M
MA
MCD
MDB
MGM
MMM
MSFT
MSI
NCR
NEM
NEWR
NFLX
NKE
NOW
NTNX
NVDA
NYT
OKTA
ORCL
PD
PG
PLAN
PS
RHT
RNG
SAP
SBUX
SHOP
SMAR
SPLK
SQ
TDOC
TEAM
TSLA
TWOU
TWTR
TXN
UA
UAL
UL
UTX
V
VEEV
VZ
WDAY
WFC
WK
WMT
WORK
YELP
ZEN
ZM
ZS
ZUO
公式動画&関連する動画 [Detect, contain, and recover from a ransomware event with Box Shield Pro]
Ransomware does not always attack from the outside. Sometimes it comes in through a compromised endpoint device that quietly syncs corrupted files to the cloud before anyone knows something is wrong. Most enterprises assume their cloud content is safe. Box Shield Pro's Ransomware Activity Detection is built for exactly the scenario where it is not.
In this demo, we walk through how Box Shield Pro detects, contains, and recovers from a ransomware event triggered by a compromised endpoint device, in under fifteen minutes.
The scenario: an intern plugs an infected thumb drive into a work laptop, accidentally infecting it with ransomware. The device begins overwriting Box content with encrypted versions synced from the compromised endpoint. Within fifteen minutes, the admin receives an email alert with the time, user, and files involved. From the Shield dashboard, the admin can see every detail of the incident, terminate the user session immediately to cut off access and prevent further files from being affected, and restore all affected files to their last known good state with a single click using the Recover Content tool.
The demo also covers a new update to ransomware detection: the Terminate Target User Session toggle. When enabled, the compromised user's session is terminated automatically the moment ransomware activity is detected, without waiting for a human to act. In a world where time to remediation is the deciding factor between a minor incident and a major disaster, that automation is critical.
Box Shield Pro moves content protection beyond the cloud to the endpoint layer, where the real ransomware vectors live. Detection in minutes. Containment with one click. Recovery to the last known good state automatically.
FAQs:
Q: How does ransomware reach Box content if Box is immune to ransomware as a platform?
A: While Box as a cloud platform is immune to ransomware, a compromised endpoint device connected to Box Drive can sync corrupted, encrypted versions of files to Box before the attack is detected. Box Shield Pro's Ransomware Activity Detection is designed to catch and stop this specific vector.
Q: How quickly does Box Shield Pro detect a ransomware event?
A: In this demo, the admin receives an alert within fifteen minutes of the ransomware event. The alert includes the time, user, and every file that was compromised.
Q: What can an admin do once a ransomware alert fires?
A: From the Shield dashboard, admins can see the full details of the incident, terminate the compromised user's session immediately to prevent further files from being affected, and restore all affected files to their last known good state using the Recover Content tool.
Q: What is the Terminate Target User Session toggle?
A: This is a new update to ransomware detection in Box Shield Pro. When enabled, the compromised user's session is terminated automatically the moment ransomware activity is detected, without requiring a human to manually intervene. This accelerates time to remediation significantly.
Q: What does the content recovery tool do?
A: The Recover Content tool allows admins to restore all files affected by a ransomware event to their last known good state. The recovery is automatically scoped to the time frame of the detected incident, making it fast and precise.
Q: Does Box Shield Pro work with Box Drive?
A: Yes. Box Shield Pro's Ransomware Activity Detection is specifically designed to protect against the endpoint vector, where a compromised device connected to Box Drive syncs corrupted content to the cloud. The protection extends beyond the cloud platform to cover this real-world attack scenario.
87
2