SOC 2 Readiness
24/7 Security Monitoring
Canadian-Based SOC
GuardsArm Platform · Respond

Ransomware Protection

Detect and stop ransomware behavior, not just signatures.

Ransomware that has been recompiled has no useful signature. What it cannot hide is its behaviour: mass file rewriting, shadow-copy destruction and ransom notes.

  • Canary files
  • Shadow-copy monitoring
  • Automated isolation
Behavioural ransomware signals — a touched canary file, mass file rewriting and shadow-copy deletion — converging into one incident that triggers host isolation

What is at stake

This is the scenario the board already knows the name of, and the window between first encryption and unrecoverable loss is measured in minutes.

Detection before the first file is encrypted

Backup and shadow-copy destruction almost always precedes encryption. Acting on that step is the difference between an incident and an outage.

The recovery path is defended, not just the data

Ransomware operations target recoverability first because it determines whether you have a choice. Protecting that is what preserves the option not to pay.

Behavioural detection that does not depend on having seen the sample

Families repack constantly and increasingly use legitimate signed tooling. A control that only recognises known samples is a control that works until it matters.

Who carries this

Formally the SOC; in practice this is the module executives ask about by name, and the one most likely to appear in a cyber-insurance questionnaire.

The problem

You cannot have a signature for a sample nobody has seen

Ransomware is the threat class where signature-based detection fails most completely, and for a structural reason rather than a quality one. Signatures identify known samples. Ransomware operations repack constantly, affiliates customise builds per campaign, and an increasing share of incidents are carried out with legitimate signed tooling that no signature should ever flag.

Meanwhile the behaviour is remarkably consistent. Destroy the recovery path, then encrypt at volume, then leave a note. That sequence has been stable for years across families that share no code at all, because it is dictated by the economics rather than the implementation.

The other constraint is time. Encryption at scale is fast. A detection that depends on analysis elsewhere, or on a human reading an alert, arrives after the thing it was meant to prevent. Which is why the detector and the response both run on the agent.

The best moment to detect ransomware is before the first file is encrypted — when the backups are being deleted.

Capabilities

What ransomware protection does

Behavioural ransomware detection

A dedicated detector using canary files, mass file-rewrite patterns, ransom-note recognition and shadow-copy or backup destruction — the signals that hold regardless of the sample.

Layered automated response

Detection is wired to automated isolation and response, so the window between "encryption started" and "host contained" is measured in seconds.

Guard-and-restore on the agent

Built into the Linux, Windows and RPM/PKG agents, with reboot survival proven.

How it fits the platform

Ransomware is also a correlation family in its own right: multiple impact techniques inside a short window assemble into a single incident, which is what triggers response rather than a stream of individual file alerts.

The signals

Four behaviours, and what each one buys you

They fire at different points in the attack, which is the reason for running all four rather than the most reliable one.

SignalWhat it readsWhy it works
Canary filesFiles placed specifically to be encryptedA file nothing legitimate should ever touch is modified. Near-zero false positive rate, and it fires early because encryption routines work through directories indiscriminately.
Mass file rewriteVolume and rate of modificationEncryption at scale looks unlike anything a user does. The shape of the activity gives it away regardless of which binary is performing it.
Ransom-note patternsThe files the attacker leaves behindRansomware announces itself. Detecting the announcement is late but unambiguous, and it confirms what the earlier signals suggested.
Shadow-copy and backup destructionAttempts to remove the recovery pathDeleting volume shadow copies or backup catalogues is a near-universal precursor. It is also the single best early warning available, because it happens before encryption starts.

How it works

From the first signal to a contained host

  1. The dedicated detector watches behaviour

    A ransomware-specific detector runs against the four behavioural signals rather than against a list of known samples. What it looks for is what ransomware does, which does not change between families.

  2. Impact techniques correlate into one incident

    Ransomware is a correlation family in its own right: multiple impact techniques inside a short window assemble into a single incident. This is what triggers response — not a stream of individual file-modification alerts that would arrive too fast to read.

  3. Layered response fires

    Automated isolation and the tiered response engine contain the host. Because the trigger is a correlated incident rather than a single alert, this is a case where unattended containment is defensible.

  4. Guard-and-restore runs on the agent

    Protection is built into the Linux, Windows and RPM/PKG agents themselves, so it operates on the endpoint rather than depending on a round trip. Reboot survival is proven.

Why behaviour

Four cases a signature cannot cover

Each of these is routine in current ransomware operations, and each defeats sample-based detection entirely.

  • A ransomware family nobody has seen beforeInvisible to signature matching by definition. Behaviourally identical to every family that came before it.
  • A repacked variant of a known familyA new hash, so a new signature is needed. The encryption behaviour is unchanged.
  • Encryption performed by a legitimate signed utilityNo malicious binary to find at all. The behaviour is the only thing there is to detect.
  • Shadow copies deleted before anything is encryptedCaught before the damage begins — a window signatures do not have access to, because nothing malicious has run yet.

Terms

The vocabulary, briefly

Canary file

A decoy file placed where encryption will reach it, which nothing legitimate reads or writes. Touching it is almost definitionally an alert.

Shadow copy destruction

Removal of the operating system snapshots that would otherwise allow local recovery. Almost every serious ransomware operation does this first, which makes it the earliest reliable signal available.

Guard-and-restore

Protection built into the agent that acts on the endpoint itself. Local action matters here specifically because the encryption window is short.

Impact technique

The ATT&CK tactic covering actions that damage availability or integrity. Several of them firing together in a short window is the platform's ransomware incident definition.

Background

Understand the concept first

Plain explainers on the underlying ideas, written for someone evaluating rather than buying.

Questions

Common questions

Does it rely on knowing the ransomware family?

No. Detection is behavioural — canary files, mass file-rewrite patterns, ransom-note recognition and shadow-copy or backup destruction. Those signals hold regardless of the sample, which matters because a recompiled payload has no useful signature.

How fast is containment?

Detection is wired to automated isolation and response, and ransomware is a correlation family in its own right: multiple impact techniques inside a short window assemble into one incident, which is what triggers response rather than a stream of individual file alerts.

Does this replace backups?

No, and nothing does. Offline or immutable copies with tested restores remain the control that decides the recovery outcome. Modern ransomware also steals data before encrypting, so backups resolve availability and not disclosure.

See Ransomware Protection running on your own infrastructure

We will walk through the console, the deployment model and what it takes to stand it up in your environment.