Fsi Ransomware Detect

Provides design/assessment support for the detection/analysis aspect of ransomware countermeasures on AWS, for financial services organizations. Use when: (1) designing a detection/analysis posture from scratch, or (2) assessing an existing posture for gaps. Covers service impact detection (resource/service/synthetic/application monitoring), security attack detection (Amazon GuardDuty, third-party products), alert-triggered root-cause triage (manual checks) for external attacks, log-based analysis (Amazon Detective, SIEM on OpenSearch, infection checks), detection aggregation/delegated admin, and forensic vendor engagement prep. Activate on ransomware detection, service monitoring, attack detection, GuardDuty, or incident investigation mentions. Do NOT use for protection/backup, evidence preservation/forensics/isolation, on-prem detection, or unclear phase -- use fsi-ransomware-overview first. Target: FSI detection/analysis staff, incl. security/infra/DevOps and risk/compliance.

aws-samples 99868dc 10 files · 329.2 KB Updated

File contents

aws-samples/sample-fsi-reference-architecture-jp/tree/main/skills/fsi-ransomware-resilience/fsi-ransomware-detect commit 99868dc5dc

Frequently asked questions

npx skillmds@latest add aws-samples/fsi-ransomware-detect