New automated response action for Shield Ransomware Activity alert
Along with the release of Ransomware Activity: Automated Remediation in Box Shield Pro, the rule_response_action parameter is now returned for the Ransomware Activity alert event.
Previously, rule_response_action was always null for Ransomware Activity alerts. It now returns a terminate_sessions field that reflects whether Box Shield automatically terminated the target user's sessions when the alert was created.
The value depends on the Terminate Target User Sessions rule setting in the Admin Console, which is off by default.
- If enabled,
terminate_sessions is true when the alert is triggered.
- If disabled,
terminate_sessions is false when the alert is triggered.
For all other Shield alerts (Anomalous Download, Malicious Content, Suspicious Session), the rule_response_action parameter remains null.
For additional information, see the Shield Alert Events guide.
Where to get support
Should you have any issues or need further guidance, please post a request to our developer forum for any help needed.