Ransomware precursor detected and contained
An attacker had established persistence on a domain controller via a compromised service account and was staging Cobalt Strike for lateral movement. The activity was designed to blend with legitimate admin behaviour — no CVE was triggered, no malware signature matched.
buMDR’s offensive-informed behavioural rules flagged the credential usage pattern as anomalous within minutes. The host was isolated, the service account was suspended, and the full intrusion timeline was reconstructed before any ransomware payload was staged. The client was notified within 20 minutes of initial detection.