Ryuk Test Files Detected
The search looks for files that contain the key word Ryuk under any folder in the C drive, which is consistent with Ryuk propagation.
Ryuk Test Files Detected Help
You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint Filesystem data-model object. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data.
Open in Search