Got a virus or "malicious activity" warning? Do this immediately
IT Processes · 1 views
Our laptops run endpoint protection (CrowdStrike Falcon) that detects and usually blocks threats automatically. If you see a threat popup on your laptop, or IT contacts you about an alert from your machine:
1. Do not panic, and do not ignore it. In most cases the threat was already blocked/quarantined — but IT still verifies each alert (a security incident is opened automatically).
2. Disconnect from the network if the warning says the threat is active: turn off Wi-Fi / unplug the cable. Do NOT shut the laptop down unless IT asks — evidence is lost on shutdown.
3. Stop and think about what you just did: opened an email attachment? Plugged in a USB drive? Downloaded a "free" tool or crack? Tell IT exactly this — it speeds up containment and there is no penalty for honesty.
4. Change your passwords from ANOTHER device (phone) if you typed any password around the time of the alert — start with your Iksula Gmail.
5. Cooperate with the remote session. IT will connect, review the quarantine, run a full scan, and clear the incident. You will be told when the machine is safe to use normally.
PREVENTION: never install software yourself (see the software article), be suspicious of email attachments you did not expect — even from known senders — and report suspicious emails to [email protected] instead of clicking links in them.
Still stuck? Email [email protected] or raise a ticket from the Help Center — include your asset tag (sticker on the laptop) and a screenshot if possible.
1. Do not panic, and do not ignore it. In most cases the threat was already blocked/quarantined — but IT still verifies each alert (a security incident is opened automatically).
2. Disconnect from the network if the warning says the threat is active: turn off Wi-Fi / unplug the cable. Do NOT shut the laptop down unless IT asks — evidence is lost on shutdown.
3. Stop and think about what you just did: opened an email attachment? Plugged in a USB drive? Downloaded a "free" tool or crack? Tell IT exactly this — it speeds up containment and there is no penalty for honesty.
4. Change your passwords from ANOTHER device (phone) if you typed any password around the time of the alert — start with your Iksula Gmail.
5. Cooperate with the remote session. IT will connect, review the quarantine, run a full scan, and clear the incident. You will be told when the machine is safe to use normally.
PREVENTION: never install software yourself (see the software article), be suspicious of email attachments you did not expect — even from known senders — and report suspicious emails to [email protected] instead of clicking links in them.
Still stuck? Email [email protected] or raise a ticket from the Help Center — include your asset tag (sticker on the laptop) and a screenshot if possible.
securityvirusmalwarecrowdstrikephishingalert
