
None of those incidents were triggered by alerts from SOC or all of them were triggered by the ransomware or the whatever Yeah it's none of these were ransomware attacks. It was more of a sophisticated actor. It's different. In some cases, it can be that the company is doing some hardening and then, you know, they start hitting that hardening and they're like, "Oh, that's weird. This EPC shouldn't block bunch of whatever, right?" Um in other cases, it's they like national intelligence services that reach out to the customer and says that you need to check on this specific host name and they're like, "How did they know the host name?" Uh so, that's kind of common as well.