Estimated reading time: 5 minutes
Every MSP has a client who came close. A threat that almost became a call you didn’t want to make at 2 a.m. On June 10, 2026, Cyflare’s SOC ransomware response stopped one of those scenarios before it could turn. A compromised VPN account, lateral movement toward a domain controller, and Impacket tooling in the environment. It’s a well-known pre-ransomware setup, and it was moving fast.
It didn’t get far.
What happened
On June 10, Cyflare’s SOC flagged suspicious lateral movement originating from a compromised SonicWall VPN user account. The activity was targeting the customer’s domain controller.
Almost immediately, analysts found more indicators tied to Impacket, a toolset threat actors use to steal credentials and spread through Windows environments. Analysts pulled telemetry from SentinelOne EDR and Cyflare’s XDR platform and confirmed the threat before taking any action.
The SOC isolated the affected endpoint within 10 minutes of the first sign of malicious activity.
Why the attacker was targeting the domain controller
This is worth pausing on, because it reframes what a 10-minute response actually means.
A domain controller is one of the highest-value targets in any Windows environment. An attacker who compromises it can push ransomware payloads to every joined endpoint in the organization. We’re not talking about one infected machine. We’re talking about an organization-wide encryption event that can unfold faster than most IT teams can respond.
According to the Guardz 2026 Ransomware Report, there were more than 6,600 ransomware attacks in 2025, up 52% year over year. MSPs and their clients are squarely in that target set.
Impacket keeps showing up in this part of the attack chain because it works. Threat actors use it to steal credentials and move through a network quickly. So when analysts see it pointed at a domain controller, the intent isn’t unclear. The attacker was setting up for something much bigger.
Thirty additional minutes of dwell time in this environment would have changed the outcome entirely. Ten minutes didn’t give them the chance.
How the SOC ransomware response unfolded
Here’s the sequence:
- Detection: Cyflare’s SOC identified unusual activity from a compromised SonicWall VPN user account moving laterally toward the customer’s domain controller. The activity matched classic pre-ransomware staging behavior.
- Correlation: Analysts confirmed Impacket indicators and checked telemetry from both SentinelOne EDR and the XDR platform to verify the threat. They had the full picture before initiating containment.
- T+10 minutes: The SOC isolated the affected endpoint, cutting off the attacker’s path through the environment immediately.
- Remediation: Next, the SOC worked directly with the customer, recommended suspending VPN access, and helped complete organization-wide credential rotation to close the attacker’s foothold before restoring anything.
This is what a fast SOC ransomware response looks like in practice, and it’s what Cyflare’s Managed SOC Services are built to deliver. A complete response cycle that gets your client through the incident, not just notified of it.
The outcomes
Threat activity detected in real time across the environment.
Affected endpoint isolated within 10 minutes of first malicious activity.
Lateral movement contained before domain controller compromise.
Customer guidance provided immediately following containment.
Organization-wide credential rotation completed before further compromise occurred.
What this means for your clients
Detection alone isn’t a security strategy. The gap between identifying a threat and acting on it is where attackers do their real work. A SOC that sees everything but moves slowly is just an expensive alerting system.
What made this response work was context. Cross-platform telemetry gave analysts the full picture before they moved. As a result, there was no second-guessing and no waiting on a ticket queue. Just a confirmed threat, a clean isolation, and a client that came through without damage.
This is the case for layered detection. Managed EDR covers the endpoint. Managed XDR extends that visibility across cloud, identity, network, and email, so analysts always have the full picture when it counts.
IBM’s 2025 Cost of a Data Breach report found the average US breach costs $10.22 million, the highest of any country. For your clients, the math isn’t abstract. A 10-minute containment window is the difference between a managed incident and a business-disrupting one.
If you want to see how our SOC ransomware response model applies to your book of business, we’re happy to walk through it.
Frequently Asked Questions
What is Impacket and why does it matter in a ransomware investigation?
Impacket is an open-source collection of Python scripts designed for low-level Windows protocol manipulation. Threat actors use it to abuse credentials and move laterally through an environment. Seeing it near a domain controller is a strong signal that an attacker is staging for broader compromise, including pushing ransomware to every connected device.
How did Cyflare detect this so quickly?
Layered detection across SentinelOne EDR and our XDR platform let analysts correlate activity from multiple telemetry sources simultaneously. That cross-platform visibility cut out the investigation delay. When context is complete, containment decisions are fast and confident.
What happens after the endpoint is isolated?
Containment is the first action, not the last. Once the endpoint was isolated, the SOC engaged directly with the customer to suspend VPN access and support organization-wide credential rotation, ensuring the attacker’s access path was fully closed before anything was restored.
Does Cyflare work with any EDR or only SentinelOne?
Cyflare’s model is bring your own tools. We work across a wide range of EDR platforms so your clients don’t have to rip and replace what’s already deployed. The SOC runs the same playbook regardless of which EDR is in the environment. You can learn more about how that works on our Managed EDR Services page.
How does a partner know their clients are covered for something like this?
The best way to find out is to walk through it together. We’ll map your current client stack against the coverage model and show you exactly where the gaps are. Book a working session, and we’ll run the numbers with you.

