Skip to main content

Ransomware Detection Dashboard

Provides details about the Ransomware Detection dashboard

📝NOTE: The availability of this feature may be limited based on the license type, region, and other criteria. To enable this feature, contact support.

The Ransomware Detection dashboard provides a high-level summary and detailed granular views of ransomware activity across your monitored environments over a 30-day default lookback period (as indicated by showing data for the last 30 days).

Summary Tab

The Summary tab delivers an overview of environment health, detection metrics, threat distribution, and indicator breakdowns.

  • Resources Monitored: Total number of protected resources being tracked for ransomware behavior within the lookback window.

  • Healthy Resources: Displayed as a count and percentage green badge (For example: 4 Healthy Resources / 25%).

  • Impacted Resources: Displayed as a count and percentage red badge (For example: 12 Impacted Resources / 80%).

  • Last Updated On: Displays the exact system timestamp when the dashboard metrics were last refreshed (For example: Aug 07, 2026 08:00:36).

Ransomware Impact Widget

  • Impacted Resources Count: Aggregated total of resources affected by ransomware alerts.

  • Alerts Detected: Total count of individual alerts generated across all monitored workloads.

  • Attack Spread: The active date range spanning from the earliest detected alert to the most recent alert (For example: Jul 21 – Aug 13).

Alerts Distribution by Resource Type

A visual donut chart displaying the volume of alerts categorized by workload type:

  • VMware: Count of alerts identified on VMware virtual machines.

  • Azure Virtual Machine: Count of alerts identified on Azure VM instances.

Ransomware Activity Over Time

A chronological bar chart tracking daily alert volume across the 30-day period, allowing administrators to identify sudden spikes or sustained attack campaigns. Hover to view details.

Indicators Detected

Displays total alert counts associated with six primary behavioral and structural threat indicators:

  • Ransom Note: Detection of known or newly generated ransom note files (For example: 36/154 alerts).

  • Ransomware File Extensions: Identification of file extensions associated with ransomware strains (For example: 35/154 alerts).

  • File Extension Changes: Anomalous or bulk modification of file extensions across protected systems (For example: 84/154 alerts).

  • High Entropy Files: Detection of files exhibiting high randomness indicative of file encryption (For example: 14/154 alerts).

  • MIME Mismatch: Discrepancy between a file’s extension and its underlying binary MIME header (For example: 14/154 alerts).

  • File Header Mismatch: Structural file corruption or header modification matching encryption techniques (For example: 14/154 alerts).

Ransomware Family

A distribution list categorizing alerts by known threat families and signatures (For example: Akira, Anubis, Aurora, LockBit, Royal / BlackSuit, Unknown).

Impacted Resources Tab

The Impacted Resources tab lists all resources that have triggered Suspicious Indicators or Encryption Detected alerts.

  • Resource Name: Name of the affected virtual machine or workload.

  • Resource Type: Infrastructure platform (For example: VMware, Azure Virtual Machine).

  • Detection Status:

    • Encryption Detected (Red Badge): High-confidence detection indicating confirmed malicious encryption or activity.

    • Suspicious Indicators (Yellow Badge): Suspicious behavior requiring administrator review and validation.

  • Ransomware Family: Detected threat signatures associated with the workload, including overflow counters (For example: Anubis, Unknown +2).

  • Indicators Detected: List of specific indicator tags attached to the resource (For example: File Header Mismatch, Ransomware File Extensions +3).

  • First Detected On: Timestamp of the initial alert triggered for the resource.

Search, filters, and actions

  • Search Bar: Quickly locate workloads using Search by Resource Name.

  • Use the Filter icon, to search and filter the list based on Resource Type and Detection Status as per your requirement.

  • Selection Checkboxes: Select single or multiple resources to perform bulk actions.

  • Quarantine Button: Click Quarantine to immediately isolate selected resources.

  • Action Menu (...):

    • Mark Resource as Not Impacted: Select this option to mark false positives or investigated items, clearing the resource from active impact lists.

Resource Details View

Clicking any Resource Name opens a dedicated page providing deep-dive forensic details, environment metadata, and individual alert histories.

1. Resource Details

  • Resource Name: Full hostname or identifier.

  • Resource Type: Infrastructure workload platform.

  • Organization: Assigned Druva tenant organization (For example: Default Organization).

  • vCenters/ESXi Hosts [ For VMware only]: Associated management host or hypervisor address.

  • Subscription, Resource Group, and Region [For Azure Virtual Machines]

2. Detection Summary

Provides an aggregated snapshot of the threat state:

  • Status: Overall workload status (Encryption Detected or Suspicious Indicators).

  • Ransomware Family: Combined threat families identified on this specific workload.

  • Total Alerts: Total count of alert events recorded for the resource.

  • First Detected: Earliest timestamp of detection.

  • Last Detected: Most recent timestamp of detection.

  • Total Impacted Files: Aggregated total count of modified or encrypted files across all alerts (For example: 30K).

  • Summary Banner: Contextual text explaining the precise detection logic (For example: "Encryption detected on the resource based on the presence of encrypted files, entropy spikes, ransom notes, suspicious/randomized file extensions, and high-volume file modifications."

3. Recommended Actions

A collapsible guidance section providing step-by-step instructions to assist incident responders in investigating, containing, and recovering the resource safely.

Take action on this alert

Immediate containment and resolution workflows available directly from the console:

  • Download Logs: Download forensic log files to review specific detected indicators, impacted file paths, and modified file extensions.

  • Quarantine: Quarantine the impacted snapshot or resource to prevent the spread of ransomware to adjacent backup sets (snapshots) or production systems.

  • Mark as Not Impacted: Mark the alert or resource as not impacted if the alert is determined to be a false positive or has already been remediated.

Continue investigation and recovery

Broader investigative and recovery workflows across the Druva platform and external security ecosystem:

  • Threat Hunting: Navigate to Threat Hunting under Ransomware Recovery to search for Indicators of Compromise (IOCs) across all protected infrastructure.

  • Cyber Recovery: Navigate to Cyber Recovery tab to initiate clean-point-in-time recovery for impacted resources and restore data safely.

  • Verify in your security tools: Search your security monitoring systems using the alert's time and specific clues (like suspicious files or IP addresses). This helps you connect the dots to see what happened and figure out how far the issue spread.

Navigate from alert to affected resources to identify the last clean recovery point

  1. In the alert details, click the Impacted Resource link.

  2. The system opens the resource's restore view.

  3. Select the Cyber Recovery tab to view ransomware detection status for each recovery point.

  4. Identify the most recent snapshot that shows no warning icons.

  5. Select the checkbox next to the clean recovery point and click Restore. Monitor the restore job from the Jobs page. After the restore completes, verify the restored data is clean and functional.

4. Alert Details Breakdown

An expandable timeline list of individual alert instances recorded for the workload (For example: Aug 3 2026, 23:11):

  • Alert Status and Family: Status and specific threat family linked to that timestamp.

  • Total Impacted Files: Total file count affected specifically during that alert event.

  • Indicator Breakdown:

    • Counts per indicator type (Ransom Note, High Entropy Files, File Extension Changes, File Header Mismatch, Ransomware File Extensions, MIME Mismatch).

    • Specific detected file extension tags/chips (For example: .f2sw, .jwlj).

  • Download Logs: Located inside each individual alert card to allow administrators to export raw forensic logs for external SIEM or SOC analysis.

Download Logs for Suspicious Indicators

You can use the Download Logs option to download Suspicious Indicators reports for offline investigation and auditing purposes.

The data is downloaded in a compressed file format when you click the Download Logs option. Following is an example of the file naming convention of the downloaded file:

ResourceABC_SuspiciousIndicators_Sun-Aug-02-18-30-10-2026.zip

What information does the Suspicious Indicators download logs report contain?

The report includes the following information:

Field Name

Description

Example Value

Alert Status

Detection classification for this specific alert event.

Suspicious indicators

Resource Name

Full name or hostname of the affected workload.

realize-qa-vm-new

Resource Type

Cloud or virtualization environment type.

AzureVM

Ransomware Family

Identified threat family signatures associated with the alert.

Aurora, Akira

Alert Generated On

Date and time timestamp when the alert was triggered.

Aug 03 2026 10:30

Total Impacted Files

Total count of individual files identified as suspicious or compromised during this alert.

6015

Evidence Summary

Aggregate tally across detected indicators for quick triage.

50320 Ransomware File Extensions, 0 File Extension Changes, 14 Ransom Note

File Path

The absolute system or volume path of the impacted file

/5b618de7-3de2-4d29-9615-b61ae...

File Size (Bytes)

Exact size of the flagged file in bytes

420, 370

Modified Timestamp

System timestamp indicating when the file was last modified prior to or during the alert event

Aug 01 2026 09:34:27

Signals

The specific indicator trigger attached to the file.

Ransomware File Extensions, Ransom Note, File Header Mismatch, or High Entropy.

Download Logs for Encryption Detected

You can use the Download Logs option to download Encryption Detected reports for offline investigation and auditing purposes.

The data is downloaded in a compressed file format when you click the Download Logs option. Following is an example of the file naming convention of the downloaded file:

ResourceABC_EncryptionDetected_Sun-Aug-02-18-30-10-2026.zip

What information does the Encryption Detected download logs report contain?

The report includes the following information:

Field Name

Description

Example Value

Alert Status

Detection classification for this specific alert event.

Encryption Detected

Resource Name

Full name or hostname of the affected workload.

realize-qa-vm-new

Resource Type

Cloud or virtualization environment type.

AzureVM

Ransomware Family

Identified threat family signatures associated with the alert.

Aurora, Akira

Alert Generated On

Date and time timestamp when the alert was triggered.

Aug 03 2026 10:30

Total Impacted Files

Total count of individual files identified as suspicious or compromised during this alert.

6015

Evidence Summary

Aggregate tally across detected indicators for quick triage.

50320 Ransomware File Extensions, 0 File Extension Changes, 14 Ransom Note

File Path

The absolute system or volume path of the impacted file

/5b618de7-3de2-4d29-9615-b61ae...

File Size (Bytes)

Exact size of the flagged file in bytes

420, 370

Modified Timestamp

System timestamp indicating when the file was last modified prior to or during the alert event

Aug 01 2026 09:34:27

Signals

The specific indicator trigger attached to the file.

Ransomware File Extensions, Ransom Note, File Header Mismatch, or High Entropy.

Understand Ransomware Detection status in Cyber Restore tab of workloads (Recovery Intelligence)

Cyber Restore tab or the Recovery Intelligence is the dashboard view that displays backup snapshots and their security status. The Ransomware Detection banner is displayed on the Cyber Restore tab which shows the security status for each snapshot:

  • Suspicious indicators: Detected behavioral indicators. Snapshot may be compromised.

  • Encryption Detected: Validated ransomware encryption. Do not restore this snapshot.

  • Clean: No ransomware indicators detected. Safe for restore.

  • Not Scanned: Snapshot has not yet been scanned by Ransomware Detection.

Trends tab

On the Trends tab, the Recovery Points Data Trend section provides vital security insights over the last 30 days for Ransomware Detection alerts.

For more information, see,

Use the clean snapshot for restore.

Did this answer your question?