Detection before the first file is encrypted
Backup and shadow-copy destruction almost always precedes encryption. Acting on that step is the difference between an incident and an outage.
Detect and stop ransomware behavior, not just signatures.
Ransomware that has been recompiled has no useful signature. What it cannot hide is its behaviour: mass file rewriting, shadow-copy destruction and ransom notes.

What is at stake
This is the scenario the board already knows the name of, and the window between first encryption and unrecoverable loss is measured in minutes.
Backup and shadow-copy destruction almost always precedes encryption. Acting on that step is the difference between an incident and an outage.
Ransomware operations target recoverability first because it determines whether you have a choice. Protecting that is what preserves the option not to pay.
Families repack constantly and increasingly use legitimate signed tooling. A control that only recognises known samples is a control that works until it matters.
Who carries this
Formally the SOC; in practice this is the module executives ask about by name, and the one most likely to appear in a cyber-insurance questionnaire.
The problem
Ransomware is the threat class where signature-based detection fails most completely, and for a structural reason rather than a quality one. Signatures identify known samples. Ransomware operations repack constantly, affiliates customise builds per campaign, and an increasing share of incidents are carried out with legitimate signed tooling that no signature should ever flag.
Meanwhile the behaviour is remarkably consistent. Destroy the recovery path, then encrypt at volume, then leave a note. That sequence has been stable for years across families that share no code at all, because it is dictated by the economics rather than the implementation.
The other constraint is time. Encryption at scale is fast. A detection that depends on analysis elsewhere, or on a human reading an alert, arrives after the thing it was meant to prevent. Which is why the detector and the response both run on the agent.
The best moment to detect ransomware is before the first file is encrypted — when the backups are being deleted.
Capabilities
A dedicated detector using canary files, mass file-rewrite patterns, ransom-note recognition and shadow-copy or backup destruction — the signals that hold regardless of the sample.
Detection is wired to automated isolation and response, so the window between "encryption started" and "host contained" is measured in seconds.
Built into the Linux, Windows and RPM/PKG agents, with reboot survival proven.
How it fits the platform
Ransomware is also a correlation family in its own right: multiple impact techniques inside a short window assemble into a single incident, which is what triggers response rather than a stream of individual file alerts.
The signals
They fire at different points in the attack, which is the reason for running all four rather than the most reliable one.
| Signal | What it reads | Why it works |
|---|---|---|
| Canary files | Files placed specifically to be encrypted | A file nothing legitimate should ever touch is modified. Near-zero false positive rate, and it fires early because encryption routines work through directories indiscriminately. |
| Mass file rewrite | Volume and rate of modification | Encryption at scale looks unlike anything a user does. The shape of the activity gives it away regardless of which binary is performing it. |
| Ransom-note patterns | The files the attacker leaves behind | Ransomware announces itself. Detecting the announcement is late but unambiguous, and it confirms what the earlier signals suggested. |
| Shadow-copy and backup destruction | Attempts to remove the recovery path | Deleting volume shadow copies or backup catalogues is a near-universal precursor. It is also the single best early warning available, because it happens before encryption starts. |
How it works
A ransomware-specific detector runs against the four behavioural signals rather than against a list of known samples. What it looks for is what ransomware does, which does not change between families.
Ransomware is a correlation family in its own right: multiple impact techniques inside a short window assemble into a single incident. This is what triggers response — not a stream of individual file-modification alerts that would arrive too fast to read.
Automated isolation and the tiered response engine contain the host. Because the trigger is a correlated incident rather than a single alert, this is a case where unattended containment is defensible.
Protection is built into the Linux, Windows and RPM/PKG agents themselves, so it operates on the endpoint rather than depending on a round trip. Reboot survival is proven.
Why behaviour
Each of these is routine in current ransomware operations, and each defeats sample-based detection entirely.
Terms
A decoy file placed where encryption will reach it, which nothing legitimate reads or writes. Touching it is almost definitionally an alert.
Removal of the operating system snapshots that would otherwise allow local recovery. Almost every serious ransomware operation does this first, which makes it the earliest reliable signal available.
Protection built into the agent that acts on the endpoint itself. Local action matters here specifically because the encryption window is short.
The ATT&CK tactic covering actions that damage availability or integrity. Several of them firing together in a short window is the platform's ransomware incident definition.
Background
Plain explainers on the underlying ideas, written for someone evaluating rather than buying.
Questions
No. Detection is behavioural — canary files, mass file-rewrite patterns, ransom-note recognition and shadow-copy or backup destruction. Those signals hold regardless of the sample, which matters because a recompiled payload has no useful signature.
Detection is wired to automated isolation and response, and ransomware is a correlation family in its own right: multiple impact techniques inside a short window assemble into one incident, which is what triggers response rather than a stream of individual file alerts.
No, and nothing does. Offline or immutable copies with tested restores remain the control that decides the recovery outcome. Modern ransomware also steals data before encrypting, so backups resolve availability and not disclosure.
Works with
Every module runs in the same self-hosted stack and shares the same telemetry, severity model and response engine.
Deep endpoint visibility and on-box response, from a lightweight native agent.
ExploreRespond in seconds, with guardrails.
ExploreTurn raw events into severity-graded, ATT&CK-mapped alerts — then connect them into real attacks.
ExploreWe will walk through the console, the deployment model and what it takes to stand it up in your environment.