An operator got in through a phished invoice attachment and began staging encryption across the Windows file servers. The antivirus running on site reported nothing at all.
A custom KQL detection picked up the abnormal write volume across the SMB shares in ninety seconds. The SOAR playbook then isolated the host, suspended the account and started paging the incident response team.
Fourteen files out of twenty four thousand were encrypted before it stopped, and everything was restored from snapshot within two hours.