Skip to main content

Ransomware Detection Report

Provides information about detailed report for Ransomware Detection alert generated

What information does this report provide

The Ransomware Detection report provides audit-compliance details for every Ransomware Detection alert generated within a specified period.

How does the report help

You can leverage this report to get the following compliance insights for every Ransomware Detection alert generated.

  1. Quickly Spot Urgent Threats: Easily sort items by Detection Status to see the difference between confirmed attacks that need immediate action and minor warnings that just need a quick check.

  2. Understand What Happened: See exactly when an alert was triggered (Alert Generated On) and what type of suspicious activity occurred—such as unusual file name changes or ransom notes left on your system.

  3. Automate Status Updates: Use Manage Subscriptions to automatically email regular security summaries to management, IT leads, or auditors without having to manually export data every time.

To access the report

You need to be a Druva Cloud Administrator.

Go to Druva Cloud Platform Console Global Navigation > Reports > Cyber Resilience > Ransomware Detection Report.

Using the report


📝 Note:

By default, the period selected for the report is 30 days from the current date. For example, if today is March 31, 2024, the report displays data from March 1 to March 30, 2024.


The data in the reports is synced periodically. The report shows the Data last updated details.

The Ransomware Detection Report comprises the following information:

Field

Description

Detection On

The date and time when the Ransomware Detection was performed.

Resource Name

The name of the resource on which the detection was performed.

Resource Type

The type of resource on which the detection was performed. It can be either VMware, Azure VM, AWS Workloads- EC2 and EBS Volume.

Detection Status

The alert status after detection is complete. It can be either:

  • Encryption Detected if a ransomware attack is confirmed

  • Security Indicators if it is a potential ransomware attack

Ransomware Family

The ransomware family to which the detected alert belongs. For example, Akira, Anubis, and so on.

Alert Generated On

The date and timestamp of when the alert was generated.

Ransom Note

Total number of Ransom Note detected.

File Extension Changes

Total number of modified file extensions detected.

Ransomware File Extensions

Total number of File Extensions detected.

High Entropy Files

Total number of High Entropy files detected.

File Header Mismatch

Total number of File Header Mismatch detected.

MIME Mismatch

Total number of MIME mismatches detected.

Actions

To leverage the report, you can perform the following actions:

  • Manage Reports: Learn how to subscribe to reports, apply filters, email reports, and edit existing subscriptions.

  • Custom Report Creation: Learn how to customize, and manage your own reports.

Related Articles

Did this answer your question?