How to confirm the attack's details detected from ARP
Applies to
- ONTAP version 9.10.1 or later
- Anti-ransomware or Autonomous Ransomware Protection (ARP) or Anti_Ransomware or ARW
Description
If a never-seen-before file extension is detected, you can check the file extension, file path, data entropy, and detection parameters based on the information output to identify if the detection is false positive or not.
- security anti-ransomware volume attack-detection-parameters show
- security anti-ransomware volume attack generate-report
- security anti-ransomware volume workload-behavior show