Ziften
11 Case Studies
A Ziften Case Study
A Fortune 100 CRM Software Service Provider faced a ransomware infection on a shared machine in a remote office, with incident response starting from only a user name and username and no antivirus or IDS alert. The team needed to quickly identify the infected system and the source before the malware spread, using Ziften Endpoint Visibility.
Using Ziften, the incident response team traced user activity, identified the last machine used, and drilled into recent binaries to find a suspicious file whose hash matched a malicious TeslaCrypt variant on a threat feed. Ziften enabled them to pinpoint the infected machine within minutes, isolate it, preserve the image for forensics, and stop the spread before broader damage occurred.