Threat Response, Lockout and Snapshots
Overview
When Ransomware Defender raises a security event at Major or Critical severity, the system responds in two coordinated ways: it locks out the affected user's access, and it takes protective snapshots of the data that was accessible to them. This section covers both halves of that response in detail.
See also
- Threat Detection and Severity Settings — Detector types, severity levels, and enforcement modes.
- Detection Controls and False Positive Management — Tuning detection and managing false positives.
- Threat Detection — Features — Full event lifecycle and triage workflow.