Ransomware is rarely a single signature. In practice it shows up as a suspicious process, a burst of file changes and an attempt to wreck your recovery points. On the endpoint the aim is to cut the attack short early and, wherever possible, leave a way to bring the files back.

In the Kalkhan Anti-Virus package the ransomware chain is not sold as a separate license: honeypot traps, native process intervention, VSS Rollback and Shelter (an encrypted safe room) all belong to the same Windows endpoint product. Instead of lab scores, this article sums up the framework that holds up in the field.

Paying the ransom is not a solution. First the behavior has to be stopped; backups and a recovery path come next.

What to watch on the endpoint

  • Rapid encryption behavior and any contact with decoy (honeypot) files
  • Shadow copies and VSS restore points kept intact
  • A safe room (Shelter) for critical files, plus a recovery center
  • Tracking what was blocked through the Event Center
  • User awareness: suspicious attachments and remote desktop access

Product context

For the technical detail, see the ransomware protection page and the Kalkhan Anti-Virus product. If an incident has already happened, use the ransomware response form or our contact line.

Related reading: defending against ransomware, watch out for phishing.