Skip to main content

Get Started with Ransomware Detection

Indicator-Driven, Multi-Stage Ransomware Detection

📝NOTE: The availability of this feature may be limited based on the license type, region, and other criteria. To enable this feature, contact support.

Overview

Ransomware Detection is a multi-stage detection framework that utilizes Machine Learning (ML) and pattern recognition to identify ransomware activity within backed up data.

It analyzes key ransomware indicators and behavioral patterns such as suspicious file extension changes, dropped artifacts, and encryption techniques to generate high-confidence, explainable alerts. This enables precise differentiation between legitimate operational activity and malicious behavior.

Key Benefits

  • Precision Detection: Get alerted only when it truly matters, high-confidence signals of real issues, with minimal noise and near-zero false positives.

  • Alert Prioritization: Clear severity mapping (warning and critical) based on the stage of detection.

  • Zero-Day Protection: It detects known, unknown, and new ransomware strains by identifying suspicious behavioral patterns.

  • Scalable Telemetry: Powered by field-driven data for continuous model refinement.

  • Minimize Business Impact: Identify the specific impact of an attack and locate exact restore points needed for a surgical and clean recovery.

  • Reduce Infrastructure Overhead: Fully managed SaaS platform with zero local software or hardware maintenance.

Access Path for Ransomware Detection

To access this feature, from the Druva Cloud Platform Console, go to the Global Navigation menu > Cyber Resiliency > Posture & Observability > Ransomware Detection. Click Ransomware Detection. You will be redirected to the Ransomware Detection dashboard page.

Here's a quick video tour that helps you get started with Ransomware Detection feature.

Set up

Ransomware Detection is designed as a plug-and-play capability, requiring no configuration. Once enabled, it begins to detect suspicious ransomware activity on your backed up data.

Supported workloads

  • VMware Virtual Machines

  • Azure Virtual Machines

  • AWS Workloads - EC2 and EBS Volume

What Druva License is required to use this feature?

Ransomware Detection feature is available with the Premium Security SKU.

How to enable this Ransomware Detection feature?

Contact your Account Manager or raise a case via Dru Assist to enable this feature.

What permissions are required to access Ransomware Detection?

You must have a Druva Cloud Administrator role to access Ransomware Detection feature.


📝Note: Druva Cloud Administrators have full authorization to perform Read, Write, Create, Delete, Edit, and Block actions. In contrast, the Druva Cloud Platform View-Only Administrator role provides strict view access, prohibiting any Create, Delete, Edit, or Block operations. For more information, see Role Based Access Control for Cyber Resiliency and Manage Druva Administrators.


How it Works: The Multi-Stage Framework

Ransomware Detection utilizes a layered defense strategy to correlate multiple signals before escalating an alert.

Stage

Category

Alert Title

Alert Severity

Stage 1

Pre-Ransom Checks

Suspicious Indicators

Warning

Stage 2

Ransom Impact

Encryption Detected

Critical

Stage 1: Potential Ransomware Detection of Ransomware Activity

During this stage, Druva uses proprietary enhanced Machine Learning (ML) models to continuously analyze backup snapshots for high-risk behavioral indicators, including mass renaming, ransom notes, and suspicious file extensions. If any high-risk indicators are detected, Druva generates a “Suspicious Indicators Found” notification via email to alert you to potential ransomware activity, automatically escalating the affected snapshot for forensic analysis.

Stage 2: Forensic Validation of Ransomware Activity

When Stage 1 flags a snapshot for potential ransomware activity, the system automatically initiates Stage 2 to conduct an in-depth forensic analysis and confirm active encryption. To ensure high accuracy, this confirmation relies on a robust, multi-layered process that evaluates multiple indicators of encryption and file tampering rather than a single signal. Once confirmed, an Encryption Detected alert is sent via email alongside supporting evidence to enable confident incident response.

Action: What should you do once you receive alerts for Ransomware Detection?

After investigating alerts, take appropriate action:

For Suspicious Indicators alert

  • Mark as Not Impacted if deemed as a false positive alert. This should be used in case of Stage 1 - Suspicious Indicators alert after a thorough investigation of the alert.

For Encryption Detected alert

  1. Declare ransomware impact: You can confidently declare a ransomware incident.

  2. Initiate containment via Manual Quarantine: Admins can manually isolate snapshots to prevent them from being used in any restore operations. Quarantined snapshots cannot be restored until you release them. If you confirm the snapshot is clean, see Manage Quarantined Snapshots to release it.

  3. Coordinate with Backup Admin: Share the incident context with your Backup Admin to begin recovery planning.


📝Note: Behavioral security tools watch for actions typical of ransomware such as rapidly modifying files, scrambling data (encryption), or renaming files in bulk. However, a false positive occurs when legitimate programs are flagged for doing these exact same things as part of their normal jobs.


Monitor Ransomware Detection

Next Step

Did this answer your question?