---
title: WatchPoint - Tip of the Week - Account Lockout Detection and Notification
description: Use Powershell to send email alerts about locked accounts in active directory. Simple detection-to-notification script for locked accounts in active directory.
image: https://blog.canauri.com/hubfs/Logo/watchpoint_css.png
---

- [319-383-0165](tel:+1.319-383-0165)

- [Free Tools](https://www.getcryptostopper.com/free-tools)
- [About](https://www.getcryptostopper.com/about)
- [Partners](https://www.getcryptostopper.com/partners)

[![CryptoStopper™](https://blog.canauri.com/hubfs/cryptostopper-logo.png)](https://www.getcryptostopper.com/)

- [CryptoStopper™](https://www.getcryptostopper.com/cryptostopper/)
- [For MSPs](https://www.getcryptostopper.com/cryptostopper-for-msps/)
- [Blog](https://blog.getcryptostopper.com/)

[Pricing](https://www.getcryptostopper.com/pricing)

# WatchPoint - Tip of the Week - Account Lockout Detection and Notification

 August 03, 2016 [Nathan Studebaker](https://blog.canauri.com/author/nathan-studebaker)

**![watchpoint_css.png](https://blog.canauri.com/hs-fs/hubfs/Logo/watchpoint_css.png?width=600&height=139&name=watchpoint_css.png)**

**Overview**

Network security has several moving parts. Of those parts, detection and notification are arguably the most important. Detection/notification are usually the first steps in any security strategy, and obviously, you cannot be notified of something you didn’t detect. Today’s Tip-of-the-Week is one article in a series that will help to bridge the gap between detection and notification.

This article focuses on active directory account lockout events and a detection-notification bridge. Lockout events can occur organically through users who have mistyped or forgotten a password, but they can also occur through [brute force attacks](https://www.owasp.org/index.php/Brute_force_attack) and [targeted attacks](http://searchsecurity.techtarget.com/feature/Targeted-Cyber-Attacks).

Regardless of their origin, we need to first detect that a lockout has occurred and then be notified of the event. Below are the steps to configure the detection-to-notification bridge using Powershell and Task Scheduler. \*This article assumes that the environment is already configured with an [account lockout policy](https://technet.microsoft.com/en-us/library/cc781491(v=ws.10).aspx) and with [failed logon auditing](https://technet.microsoft.com/en-us/library/dd277403.aspx). If not, please use the links provided.

Here are the steps:

1. Modify the Powershell script. Everything in **bold** will need to be modified to match your environment.

\*Tip - You’ll notice that we include a quote in the body of the email. We do this for security reasons. Instinctively we’re weary of any email attachment and the quote that’s been chosen lets us know that it’s legitimate. We even change the quote when we changes passwords. Use your own quote or an MD5 checksum, or none at all, it’s up to you. The script can be found below:

#######################Beginning of script#########################

#Declare a location for script. The email attachment will be created here

#Change this to match your environment

$location = "**C:\\support\\scripts**"

 

#Declare the email settings

$To = "**youremailaddress@yourcompany.com**"

$From = "**lockoutalert@yourcompany.com**"

$Body = "**Quote:Keep your friends close, but your enemies closer. Account lockout event detected**."

$Sub = "**Account Lockout Event**"

$CredUser = "**youremailaddress@yourcompany.com@**"

#Please note that the password is in clear text. In a future post, we’ll show you how to encrypt it.

$CredPass = "**yourpassword**" | ConvertTo-SecureString -AsPlainText -Force

$Credentials = New-Object System.Management.Automation.Pscredential -Argumentlist $CredUser,$CredPass

$Attachments = "$location\\**LockedEvents.csv**"

$SmtpServer = "**mail.yoursmptserver.com**"

$Port = "**25**"

 

#Checks for locked out accounts, event id 4740

#Checks the last 1 hours

$events = Get-WinEvent -FilterHashtable @{logname='security';id=4740;StartTime=(get-date).AddHours(-1.0)} | Select-Object -Property "TimeCreated",

@{label='UserAccount';expression={$\_.properties\[0\].value}},

@{label='RemoteComputerName';expression={$\_.properties\[1\].value}}

 

#Convert events to a number using measure object and select object

$eventcount = $events | Measure-Object | Select-Object -Property Count

 

#If more than one lockout is found, send email

If ($eventcount.count -ge 1) {

Send-MailMessage -To $To -From $From -Body $Body -Subject $Sub -Credential $Credentials -SmtpServer $smtpServer -Port $Port -Attachments $Attachments

}

 #Write to logfile

$events | Export-Csv $location\\LockedEvents.csv -Append

Exit

##########################End of script##########################

2. Save the script to the location that is specified via the $location variable.

3. Open task manager and select ‘Create New Task’. Give it a proper name and ensure that ‘Run whether user is logged on or not’ is selected and that ‘run with highest privileges’ is selected. Sensitive information has been removed from this graphic.

![scheduled_task_-_general_tab.jpg](https://blog.canauri.com/hs-fs/hubfs/tip_of_the_week/scheduled_task_-_general_tab.jpg?width=483&name=scheduled_task_-_general_tab.jpg)

4. Define the Triggers tab. Configure the ‘Repeat task every’ to a value that is less than your account lockout duration. For example, if the account lockout duration is 60 minutes, then configure the task for every 45 minutes.

![scheduled_task_trigger.jpg](https://blog.canauri.com/hs-fs/hubfs/tip_of_the_week/scheduled_task_trigger.jpg?width=485&name=scheduled_task_trigger.jpg)

5. Next is the Actions tab. Browse to the location of the script and then append the following to the ‘Program/script:’ section: powershell.exe –file

The entire string will look like this:

powershell.exe -file C:\\support\\scripts\\account\_lockout\_alert.ps1

![scheduled_task_actions_tab.jpg](https://blog.canauri.com/hs-fs/hubfs/tip_of_the_week/scheduled_task_actions_tab.jpg?width=628&height=160&name=scheduled_task_actions_tab.jpg)

6. The rest of the settings can be left at the default settings.

7. Click OK and enter the username and password of the user account. \*Note the user account will require ‘[run scheduled task/batch file permissions’](http://serverfault.com/questions/357726/permissions-for-scheduled-tasks-on-a-domain-controller). Sensitive information removed from screenshot.

![task_scheduler_credentials.jpg](https://blog.canauri.com/hs-fs/hubfs/tip_of_the_week/task_scheduler_credentials.jpg?width=338&height=268&name=task_scheduler_credentials.jpg)

8. Click yes at the next prompt.

![task_scheduler_prompt2.jpg](https://blog.canauri.com/hs-fs/hubfs/tip_of_the_week/task_scheduler_prompt2.jpg?width=487&height=110&name=task_scheduler_prompt2.jpg)

9. Next, you’ll need to purposefully lock an account from active directory. With an account locked out simply run the task and you’ll receive an email similar to this:

![account_lockout_email2.jpg](https://blog.canauri.com/hs-fs/hubfs/tip_of_the_week/account_lockout_email2.jpg?width=581&height=103&name=account_lockout_email2.jpg)

10.  And the attachment will look like this (sensitive information removed):

![email_attachment.jpg](https://blog.canauri.com/hs-fs/hubfs/tip_of_the_week/email_attachment.jpg?width=343&height=126&name=email_attachment.jpg)

That’s all there is to it. You now have a simple bridge between detection and notification of account lockout events. Stay tuned for next week’s tip, where we’ll build on this script and demonstrate how to block brute force attempts, once again using Powershell.

### Share this:

- [Tweet](https://twitter.com/share)

[Previous Post White House Releases Color-Coded Scale for Cybersecurity Threats](https://blog.canauri.com/white-house-releases-color-coded-scale-for-cybersecurity-threats) [Next Post CryptoStopper.io Demo – Isolate and Defeat TeslaCrypt Ransomware](https://blog.canauri.com/cryptostopper.io-demo-containing-and-defeating-teslacrypt-ransomware)

[![Entrepreneur Link](https://blog.canauri.com/hs-fs/hubfs/Watch_Point_Data_December2017_Theme/images/Feature-on-Entrepreneur.com_.png?width=300&height=300&name=Feature-on-Entrepreneur.com_.png)](https://www.entrepreneur.com/article/286698)

### Share

[![Share on Facebook](https://static.hubspot.com/final/img/common/icons/social/facebook-24x24.png)](http://www.facebook.com/share.php?u=https%3A%2F%2Fblog.canauri.com%2Fwatchpoint-tip-of-the-week-account-lockout-detection-and-notification%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on LinkedIn](https://static.hubspot.com/final/img/common/icons/social/linkedin-24x24.png)](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.canauri.com%2Fwatchpoint-tip-of-the-week-account-lockout-detection-and-notification%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on Twitter](https://static.hubspot.com/final/img/common/icons/social/twitter-24x24.png)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fblog.canauri.com%2Fwatchpoint-tip-of-the-week-account-lockout-detection-and-notification%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fblog.canauri.com%2Fwatchpoint-tip-of-the-week-account-lockout-detection-and-notification%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=WatchPoint%20-%20Tip%20of%20the%20Week%20-%20Account%20Lockout%20Detection%20and%20Notification) [![Share on Pinterest](https://static.hubspot.com/final/img/common/icons/social/pinterest-24x24.png)](http://pinterest.com/pin/create/button/?url=https%3A%2F%2Fblog.canauri.com%2Fwatchpoint-tip-of-the-week-account-lockout-detection-and-notification%3Futm_medium%3Dsocial%26utm_source%3Dpinterest&media=) [![Share on Email](https://static.hubspot.com/final/img/common/icons/social/email-24x24.png)](mailto:?subject=Check%20out%20https%3A%2F%2Fblog.canauri.com%2Fwatchpoint-tip-of-the-week-account-lockout-detection-and-notification%3Futm_medium%3Dsocial%26utm_source%3Demail%20&body=Check%20out%20https%3A%2F%2Fblog.canauri.com%2Fwatchpoint-tip-of-the-week-account-lockout-detection-and-notification%3Futm_medium%3Dsocial%26utm_source%3Demail)

### Subscribe to Email Updates

### Recent Posts

### Posts by Topic

- [Cyber Threats (164)](https://blog.canauri.com/topic/cyber-threats)
- [Ransomware (91)](https://blog.canauri.com/topic/ransomware)
- [Data Breach (68)](https://blog.canauri.com/topic/data-breach)
- [Business (49)](https://blog.canauri.com/topic/business)
- [Scams (19)](https://blog.canauri.com/topic/scams)
- [cybersecurity (14)](https://blog.canauri.com/topic/cybersecurity)
- [Cyber Attack (10)](https://blog.canauri.com/topic/cyber-attack)
- [Uncategorized (9)](https://blog.canauri.com/topic/uncategorized)
- [Breach (8)](https://blog.canauri.com/topic/breach)
- [Data (8)](https://blog.canauri.com/topic/data)
- [Phishing (7)](https://blog.canauri.com/topic/phishing)
- [cyber (5)](https://blog.canauri.com/topic/cyber)
- [decrypters (5)](https://blog.canauri.com/topic/decrypters)
- [security (5)](https://blog.canauri.com/topic/security)
- [Insider (4)](https://blog.canauri.com/topic/insider)
- [Ransomware Decrypters (4)](https://blog.canauri.com/topic/ransomware-decrypters)
- [cybercrime (4)](https://blog.canauri.com/topic/cybercrime)
- [managed service providers (4)](https://blog.canauri.com/topic/managed-service-providers)
- [ransom (4)](https://blog.canauri.com/topic/ransom)
- [ransomware ransom (4)](https://blog.canauri.com/topic/ransomware-ransom)
- [Banking Trojans (3)](https://blog.canauri.com/topic/banking-trojans)
- [Firewalls (3)](https://blog.canauri.com/topic/firewalls)
- [Press Release (3)](https://blog.canauri.com/topic/press-release)
- [Ransomware as a Service (3)](https://blog.canauri.com/topic/ransomware-as-a-service)
- [WannaCry (3)](https://blog.canauri.com/topic/wannacry)
- [Zero Day Vulnerability (3)](https://blog.canauri.com/topic/zero-day-vulnerability)
- [business email compromise (3)](https://blog.canauri.com/topic/business-email-compromise)
- [cyber security (3)](https://blog.canauri.com/topic/cyber-security)
- [decryptors (3)](https://blog.canauri.com/topic/decryptors)
- [ransomware attack (3)](https://blog.canauri.com/topic/ransomware-attack)
- [BlueKeep (2)](https://blog.canauri.com/topic/bluekeep)
- [CEO fraud (2)](https://blog.canauri.com/topic/ceo-fraud)
- [COVID-19 (2)](https://blog.canauri.com/topic/covid-19)
- [COVID-19 cybersecurity (2)](https://blog.canauri.com/topic/covid-19-cybersecurity)
- [Cyberattack (2)](https://blog.canauri.com/topic/cyberattack)
- [Fileless (2)](https://blog.canauri.com/topic/fileless)
- [Fileless Malware (2)](https://blog.canauri.com/topic/fileless-malware)
- [Fileless Ransomare (2)](https://blog.canauri.com/topic/fileless-ransomare)
- [Fortnite vulnerability (2)](https://blog.canauri.com/topic/fortnite-vulnerability)
- [MSPs (2)](https://blog.canauri.com/topic/msps)
- [Patch (2)](https://blog.canauri.com/topic/patch)
- [Small and Medium Enterprises Cybersecurity (2)](https://blog.canauri.com/topic/small-and-medium-enterprises-cybersecurity)
- [Spear Phishing (2)](https://blog.canauri.com/topic/spear-phishing)
- [WFH (2)](https://blog.canauri.com/topic/wfh)
- [Wi-Fi Connections (2)](https://blog.canauri.com/topic/wi-fi-connections)
- [Zero Day (2)](https://blog.canauri.com/topic/zero-day)
- [Zero Day Attacks (2)](https://blog.canauri.com/topic/zero-day-attacks)
- [bitcoin (2)](https://blog.canauri.com/topic/bitcoin)
- [bitcoins (2)](https://blog.canauri.com/topic/bitcoins)
- [cryptocurrency (2)](https://blog.canauri.com/topic/cryptocurrency)
- [cryptocurrency mining (2)](https://blog.canauri.com/topic/cryptocurrency-mining)
- [cryptojacking (2)](https://blog.canauri.com/topic/cryptojacking)
- [cyber attacks on hospitals (2)](https://blog.canauri.com/topic/cyber-attacks-on-hospitals)
- [cybersecurity jobs (2)](https://blog.canauri.com/topic/cybersecurity-jobs)
- [defray (2)](https://blog.canauri.com/topic/defray)
- [defray ransomware (2)](https://blog.canauri.com/topic/defray-ransomware)
- [fortnite (2)](https://blog.canauri.com/topic/fortnite)
- [gandcrab ransomware (2)](https://blog.canauri.com/topic/gandcrab-ransomware)
- [hacking (2)](https://blog.canauri.com/topic/hacking)
- [health (2)](https://blog.canauri.com/topic/health)
- [healthcare (2)](https://blog.canauri.com/topic/healthcare)
- [hospital cybersecurity (2)](https://blog.canauri.com/topic/hospital-cybersecurity)
- [mac malware (2)](https://blog.canauri.com/topic/mac-malware)
- [municipalities cyberattack (2)](https://blog.canauri.com/topic/municipalities-cyberattack)
- [municipalities ransomware (2)](https://blog.canauri.com/topic/municipalities-ransomware)
- [passwords (2)](https://blog.canauri.com/topic/passwords)
- [ransomware attacks (2)](https://blog.canauri.com/topic/ransomware-attacks)
- [ransomware normal (2)](https://blog.canauri.com/topic/ransomware-normal)
- [scareware (2)](https://blog.canauri.com/topic/scareware)
- [two-factor authentication (2)](https://blog.canauri.com/topic/two-factor-authentication)
- [2018 cybersecurity (1)](https://blog.canauri.com/topic/2018-cybersecurity)
- [2018 cybersecurity review (1)](https://blog.canauri.com/topic/2018-cybersecurity-review)
- [2019 cybersecurity predictions (1)](https://blog.canauri.com/topic/2019-cybersecurity-predictions)
- [2019 predictions (1)](https://blog.canauri.com/topic/2019-predictions)
- [2020 Cybersecurity Predictions (1)](https://blog.canauri.com/topic/2020-cybersecurity-predictions)
- [2FA (1)](https://blog.canauri.com/topic/2fa)
- [Arizona (1)](https://blog.canauri.com/topic/arizona)
- [Arizona beverages ransomware (1)](https://blog.canauri.com/topic/arizona-beverages-ransomware)
- [BEC (1)](https://blog.canauri.com/topic/bec)
- [BEC Attacks (1)](https://blog.canauri.com/topic/bec-attacks)
- [BitPaymer (1)](https://blog.canauri.com/topic/bitpaymer)
- [BlueKeep Exploit (1)](https://blog.canauri.com/topic/bluekeep-exploit)
- [BlueKeep Vulnerability (1)](https://blog.canauri.com/topic/bluekeep-vulnerability)
- [CISO (1)](https://blog.canauri.com/topic/ciso)
- [Chief Information Security Officer (1)](https://blog.canauri.com/topic/chief-information-security-officer)
- [Coronavirus (1)](https://blog.canauri.com/topic/coronavirus)
- [Coronavirus scams (1)](https://blog.canauri.com/topic/coronavirus-scams)
- [CryptoMix (1)](https://blog.canauri.com/topic/cryptomix)
- [Cyber Liability Insurance (1)](https://blog.canauri.com/topic/cyber-liability-insurance)
- [DLL (1)](https://blog.canauri.com/topic/dll)
- [DLL CryptoMix (1)](https://blog.canauri.com/topic/dll-cryptomix)
- [Data Leak (1)](https://blog.canauri.com/topic/data-leak)
- [Deepfakes (1)](https://blog.canauri.com/topic/deepfakes)
- [Dridex (1)](https://blog.canauri.com/topic/dridex)
- [ERP (1)](https://blog.canauri.com/topic/erp)
- [ERP Systems (1)](https://blog.canauri.com/topic/erp-systems)
- [Enterprise Resource Planning (1)](https://blog.canauri.com/topic/enterprise-resource-planning)
- [Exactis (1)](https://blog.canauri.com/topic/exactis)
- [FIFA (1)](https://blog.canauri.com/topic/fifa)
- [Fortnite ransomware (1)](https://blog.canauri.com/topic/fortnite-ransomware)
- [GandCrab (1)](https://blog.canauri.com/topic/gandcrab)
- [Google (1)](https://blog.canauri.com/topic/google)
- [Have I been pwned (1)](https://blog.canauri.com/topic/have-i-been-pwned)
- [Hospitals Ransomware (1)](https://blog.canauri.com/topic/hospitals-ransomware)
- [Kirk (1)](https://blog.canauri.com/topic/kirk)
- [Kirk Ransomware (1)](https://blog.canauri.com/topic/kirk-ransomware)
- [LockBit (1)](https://blog.canauri.com/topic/lockbit)
- [LockerGoga (1)](https://blog.canauri.com/topic/lockergoga)
- [LockerGoga Ransomware (1)](https://blog.canauri.com/topic/lockergoga-ransomware)
- [M&A (1)](https://blog.canauri.com/topic/ma)
- [Malware (1)](https://blog.canauri.com/topic/malware)
- [Marriott data breach (1)](https://blog.canauri.com/topic/marriott-data-breach)
- [NASA (1)](https://blog.canauri.com/topic/nasa)
- [NASA Data Breach (1)](https://blog.canauri.com/topic/nasa-data-breach)
- [NCSAM (1)](https://blog.canauri.com/topic/ncsam)
- [National Cyber Security Awareness Month (1)](https://blog.canauri.com/topic/national-cyber-security-awareness-month)
- [Norsk (1)](https://blog.canauri.com/topic/norsk)
- [Norsk Hydro (1)](https://blog.canauri.com/topic/norsk-hydro)
- [PGA (1)](https://blog.canauri.com/topic/pga)
- [Patch Tuesday (1)](https://blog.canauri.com/topic/patch-tuesday)
- [Petya (1)](https://blog.canauri.com/topic/petya)
- [Petya Ransomware (1)](https://blog.canauri.com/topic/petya-ransomware)
- [Quora data breach (1)](https://blog.canauri.com/topic/quora-data-breach)
- [RDP (1)](https://blog.canauri.com/topic/rdp)
- [Remote Desktop Protocol (1)](https://blog.canauri.com/topic/remote-desktop-protocol)
- [Remote workforce (1)](https://blog.canauri.com/topic/remote-workforce)
- [RobbinHood Ransomware (1)](https://blog.canauri.com/topic/robbinhood-ransomware)
- [Robbinhood (1)](https://blog.canauri.com/topic/robbinhood)
- [SEC (1)](https://blog.canauri.com/topic/sec)
- [SME (1)](https://blog.canauri.com/topic/sme)
- [SME Cybersecurity (1)](https://blog.canauri.com/topic/sme-cybersecurity)
- [SamSam (1)](https://blog.canauri.com/topic/samsam)
- [SamSam Ransomware (1)](https://blog.canauri.com/topic/samsam-ransomware)
- [Security Breach Notification Laws (1)](https://blog.canauri.com/topic/security-breach-notification-laws)
- [Small and Medium Enterprises (1)](https://blog.canauri.com/topic/small-and-medium-enterprises)
- [Sorebrect (1)](https://blog.canauri.com/topic/sorebrect)
- [Star Trek (1)](https://blog.canauri.com/topic/star-trek)
- [Syrk ransomware (1)](https://blog.canauri.com/topic/syrk-ransomware)
- [Target (1)](https://blog.canauri.com/topic/target)
- [Vidar (1)](https://blog.canauri.com/topic/vidar)
- [Vidar infostealer (1)](https://blog.canauri.com/topic/vidar-infostealer)
- [Vidar trojan (1)](https://blog.canauri.com/topic/vidar-trojan)
- [WCry (1)](https://blog.canauri.com/topic/wcry)
- [Wana Decryptor (1)](https://blog.canauri.com/topic/wana-decryptor)
- [WanaCry (1)](https://blog.canauri.com/topic/wanacry)
- [WanaDecryptor (1)](https://blog.canauri.com/topic/wanadecryptor)
- [WannaCry 2.0 (1)](https://blog.canauri.com/topic/wannacry-2-0)
- [World Cup (1)](https://blog.canauri.com/topic/world-cup)
- [Yahoo (1)](https://blog.canauri.com/topic/yahoo)
- [Yahoo Data Breach (1)](https://blog.canauri.com/topic/yahoo-data-breach)
- [anatova (1)](https://blog.canauri.com/topic/anatova)
- [anatova ransomware (1)](https://blog.canauri.com/topic/anatova-ransomware)
- [arizona beverages (1)](https://blog.canauri.com/topic/arizona-beverages)
- [atlanta (1)](https://blog.canauri.com/topic/atlanta)
- [automobile (1)](https://blog.canauri.com/topic/automobile)
- [automobile hacking (1)](https://blog.canauri.com/topic/automobile-hacking)
- [azorult trojan (1)](https://blog.canauri.com/topic/azorult-trojan)
- [banking trojan (1)](https://blog.canauri.com/topic/banking-trojan)
- [bentley (1)](https://blog.canauri.com/topic/bentley)
- [bitpaymer ransomware (1)](https://blog.canauri.com/topic/bitpaymer-ransomware)
- [blackmail (1)](https://blog.canauri.com/topic/blackmail)
- [budgeting (1)](https://blog.canauri.com/topic/budgeting)
- [capital one (1)](https://blog.canauri.com/topic/capital-one)
- [capital one data breach (1)](https://blog.canauri.com/topic/capital-one-data-breach)
- [car hacking (1)](https://blog.canauri.com/topic/car-hacking)
- [care (1)](https://blog.canauri.com/topic/care)
- [chicago tribune (1)](https://blog.canauri.com/topic/chicago-tribune)
- [collection (1)](https://blog.canauri.com/topic/collection)
- [collection 1 (1)](https://blog.canauri.com/topic/collection-1)
- [coronavirus cybersecurity (1)](https://blog.canauri.com/topic/coronavirus-cybersecurity)
- [coronavirus phishing (1)](https://blog.canauri.com/topic/coronavirus-phishing)
- [coronavirus ransomware (1)](https://blog.canauri.com/topic/coronavirus-ransomware)
- [crypto (1)](https://blog.canauri.com/topic/crypto)
- [crytocurrency hack (1)](https://blog.canauri.com/topic/crytocurrency-hack)
- [currency (1)](https://blog.canauri.com/topic/currency)
- [cyber insurance (1)](https://blog.canauri.com/topic/cyber-insurance)
- [cybersecurity budgeting (1)](https://blog.canauri.com/topic/cybersecurity-budgeting)
- [cybersecurity coronavirus (1)](https://blog.canauri.com/topic/cybersecurity-coronavirus)
- [cybersecurity predictions (1)](https://blog.canauri.com/topic/cybersecurity-predictions)
- [cybersecurity ventures (1)](https://blog.canauri.com/topic/cybersecurity-ventures)
- [cybersecurity working remotely (1)](https://blog.canauri.com/topic/cybersecurity-working-remotely)
- [dharma (1)](https://blog.canauri.com/topic/dharma)
- [dharma ransomware (1)](https://blog.canauri.com/topic/dharma-ransomware)
- [financial services (1)](https://blog.canauri.com/topic/financial-services)
- [financial services data breach (1)](https://blog.canauri.com/topic/financial-services-data-breach)
- [government cyberattack (1)](https://blog.canauri.com/topic/government-cyberattack)
- [holiday shopping (1)](https://blog.canauri.com/topic/holiday-shopping)
- [hospitals hit with ransomware (1)](https://blog.canauri.com/topic/hospitals-hit-with-ransomware)
- [iEncrypt (1)](https://blog.canauri.com/topic/iencrypt)
- [insider trading (1)](https://blog.canauri.com/topic/insider-trading)
- [insurance (1)](https://blog.canauri.com/topic/insurance)
- [laundering (1)](https://blog.canauri.com/topic/laundering)
- [leak (1)](https://blog.canauri.com/topic/leak)
- [los angeles times (1)](https://blog.canauri.com/topic/los-angeles-times)
- [man in the disk (1)](https://blog.canauri.com/topic/man-in-the-disk)
- [man in the disk attacks (1)](https://blog.canauri.com/topic/man-in-the-disk-attacks)
- [maritime cybersecurity (1)](https://blog.canauri.com/topic/maritime-cybersecurity)
- [maze ransomware (1)](https://blog.canauri.com/topic/maze-ransomware)
- [pensacola florida (1)](https://blog.canauri.com/topic/pensacola-florida)
- [phobos (1)](https://blog.canauri.com/topic/phobos)
- [phobos ransomware (1)](https://blog.canauri.com/topic/phobos-ransomware)
- [quarter 1 2019 ransomware (1)](https://blog.canauri.com/topic/quarter-1-2019-ransomware)
- [raccoon stealer (1)](https://blog.canauri.com/topic/raccoon-stealer)
- [ransomware data breaches (1)](https://blog.canauri.com/topic/ransomware-data-breaches)
- [ransomware defined (1)](https://blog.canauri.com/topic/ransomware-defined)
- [ransomware epidemic (1)](https://blog.canauri.com/topic/ransomware-epidemic)
- [ransomware hits municipalities (1)](https://blog.canauri.com/topic/ransomware-hits-municipalities)
- [ransomware statistics (1)](https://blog.canauri.com/topic/ransomware-statistics)
- [riviera beach ransomware attack (1)](https://blog.canauri.com/topic/riviera-beach-ransomware-attack)
- [ryuk (1)](https://blog.canauri.com/topic/ryuk)
- [ryuk ransomware (1)](https://blog.canauri.com/topic/ryuk-ransomware)
- [scammers (1)](https://blog.canauri.com/topic/scammers)
- [scams targeting holiday shoppers (1)](https://blog.canauri.com/topic/scams-targeting-holiday-shoppers)
- [securities and exchange commission (1)](https://blog.canauri.com/topic/securities-and-exchange-commission)
- [sextortion (1)](https://blog.canauri.com/topic/sextortion)
- [shipping industry (1)](https://blog.canauri.com/topic/shipping-industry)
- [snake ransomware (1)](https://blog.canauri.com/topic/snake-ransomware)
- [social engineering (1)](https://blog.canauri.com/topic/social-engineering)
- [southwire (1)](https://blog.canauri.com/topic/southwire)
- [stop paying the ransom (1)](https://blog.canauri.com/topic/stop-paying-the-ransom)
- [tips for working remotely (1)](https://blog.canauri.com/topic/tips-for-working-remotely)
- [tribune (1)](https://blog.canauri.com/topic/tribune)
- [ursnif (1)](https://blog.canauri.com/topic/ursnif)
- [wall street journal (1)](https://blog.canauri.com/topic/wall-street-journal)
- [what is ransomware (1)](https://blog.canauri.com/topic/what-is-ransomware)
- [working from home (1)](https://blog.canauri.com/topic/working-from-home)
- [working remotely (1)](https://blog.canauri.com/topic/working-remotely)

see all

##### Contact

[415 12th Ave SE, Suite 201 Cedar Rapids, IA 52401](https://www.google.com/maps/place/415+12th+Ave+SE+%23201,+Cedar+Rapids,+IA+52401/@41.9710436,-91.6582952,17z/data=!3m1!4b1!4m5!3m4!1s0x87e4f73f67891f6d:0x38f71e45a9fa7c1f!8m2!3d41.9710436!4d-91.6561065)

[319-383-0165](tel:319-383-0165)

[support@getcryptostopper.com](mailto:support@getcryptostopper.com)

<https://www.facebook.com/cryptostopper>

Facebook

<https://twitter.com/cryptostopper>

Twitter

<https://www.linkedin.com/company/cryptostopper>

Linkedin

<https://www.youtube.com/c/CryptoStopper>

YouTube

- Products 
    - [CryptoStopper™](https://www.getcryptostopper.com/cryptostopper/)
    - [Endpoint Security](https://www.getcryptostopper.com/tools/endpoint-security/)
- Free Tools 
    - [Ransomware Simulator](https://www.getcryptostopper.com/ransomware-simulator/)
    - [Network Tools](https://www.getcryptostopper.com/free-network-tools/)
    - [Ransomware Decryptors](https://www.getcryptostopper.com/ransomware-decryptors/)
- Company 
    - [About](https://www.getcryptostopper.com/about/)
    - [Careers](https://www.getcryptostopper.com/careers/)
    - [Contact](https://www.getcryptostopper.com/contact/)

© Copyright WatchPoint Data, All Rights Reserved   |   [Terms](https://www.getcryptostopper.com/terms)