📝NOTE: The availability of this feature may be limited based on the license type, region, and other criteria. To enable this feature, contact support.
The Ransomware Detection dashboard provides a high-level summary and detailed granular views of ransomware activity across your monitored environments over a 30-day default lookback period (as indicated by showing data for the last 30 days).
Summary Tab
The Summary tab delivers an overview of environment health, detection metrics, threat distribution, and indicator breakdowns.
Resources Monitored: Total number of protected resources being tracked for ransomware behavior within the lookback window.
Healthy Resources: Displayed as a count and percentage green badge (For example: 4 Healthy Resources / 25%).
Impacted Resources: Displayed as a count and percentage red badge (For example: 12 Impacted Resources / 80%).
Last Updated On: Displays the exact system timestamp when the dashboard metrics were last refreshed (For example: Aug 07, 2026 08:00:36).
Ransomware Impact Widget
Impacted Resources Count: Aggregated total of resources affected by ransomware alerts.
Alerts Detected: Total count of individual alerts generated across all monitored workloads.
Attack Spread: The active date range spanning from the earliest detected alert to the most recent alert (For example: Jul 21 – Aug 13).
Alerts Distribution by Resource Type
A visual donut chart displaying the volume of alerts categorized by workload type:
VMware: Count of alerts identified on VMware virtual machines.
Azure Virtual Machine: Count of alerts identified on Azure VM instances.
Ransomware Activity Over Time
A chronological bar chart tracking daily alert volume across the 30-day period, allowing administrators to identify sudden spikes or sustained attack campaigns. Hover to view details.
Indicators Detected
Displays total alert counts associated with six primary behavioral and structural threat indicators:
Ransom Note: Detection of known or newly generated ransom note files (For example: 36/154 alerts).
Ransomware File Extensions: Identification of file extensions associated with ransomware strains (For example: 35/154 alerts).
File Extension Changes: Anomalous or bulk modification of file extensions across protected systems (For example: 84/154 alerts).
High Entropy Files: Detection of files exhibiting high randomness indicative of file encryption (For example: 14/154 alerts).
MIME Mismatch: Discrepancy between a file’s extension and its underlying binary MIME header (For example: 14/154 alerts).
File Header Mismatch: Structural file corruption or header modification matching encryption techniques (For example: 14/154 alerts).
Ransomware Family
A distribution list categorizing alerts by known threat families and signatures (For example: Akira, Anubis, Aurora, LockBit, Royal / BlackSuit, Unknown).
Impacted Resources Tab
The Impacted Resources tab lists all resources that have triggered Suspicious Indicators or Encryption Detected alerts.
Resource Name: Name of the affected virtual machine or workload.
Resource Type: Infrastructure platform (For example: VMware, Azure Virtual Machine).
Detection Status:
Encryption Detected (Red Badge): High-confidence detection indicating confirmed malicious encryption or activity.
Suspicious Indicators (Yellow Badge): Suspicious behavior requiring administrator review and validation.
Ransomware Family: Detected threat signatures associated with the workload, including overflow counters (For example: Anubis, Unknown +2).
Indicators Detected: List of specific indicator tags attached to the resource (For example: File Header Mismatch, Ransomware File Extensions +3).
First Detected On: Timestamp of the initial alert triggered for the resource.
Search, filters, and actions
Search Bar: Quickly locate workloads using Search by Resource Name.
Use the Filter icon, to search and filter the list based on Resource Type and Detection Status as per your requirement.
Selection Checkboxes: Select single or multiple resources to perform bulk actions.
Quarantine Button: Click Quarantine to immediately isolate selected resources.
Action Menu (...):
Mark Resource as Not Impacted: Select this option to mark false positives or investigated items, clearing the resource from active impact lists.
Resource Details View
Clicking any Resource Name opens a dedicated page providing deep-dive forensic details, environment metadata, and individual alert histories.
1. Resource Details
Resource Name: Full hostname or identifier.
Resource Type: Infrastructure workload platform.
Organization: Assigned Druva tenant organization (For example: Default Organization).
vCenters/ESXi Hosts [ For VMware only]: Associated management host or hypervisor address.
Subscription, Resource Group, and Region [For Azure Virtual Machines]
2. Detection Summary
Provides an aggregated snapshot of the threat state:
Status: Overall workload status (Encryption Detected or Suspicious Indicators).
Ransomware Family: Combined threat families identified on this specific workload.
Total Alerts: Total count of alert events recorded for the resource.
First Detected: Earliest timestamp of detection.
Last Detected: Most recent timestamp of detection.
Total Impacted Files: Aggregated total count of modified or encrypted files across all alerts (For example: 30K).
Summary Banner: Contextual text explaining the precise detection logic (For example: "Encryption detected on the resource based on the presence of encrypted files, entropy spikes, ransom notes, suspicious/randomized file extensions, and high-volume file modifications."
3. Recommended Actions
A collapsible guidance section providing step-by-step instructions to assist incident responders in investigating, containing, and recovering the resource safely.
Take action on this alert
Immediate containment and resolution workflows available directly from the console:
Download Logs: Download forensic log files to review specific detected indicators, impacted file paths, and modified file extensions.
Quarantine: Quarantine the impacted snapshot or resource to prevent the spread of ransomware to adjacent backup sets (snapshots) or production systems.
Mark as Not Impacted: Mark the alert or resource as not impacted if the alert is determined to be a false positive or has already been remediated.
Continue investigation and recovery
Broader investigative and recovery workflows across the Druva platform and external security ecosystem:
Threat Hunting: Navigate to Threat Hunting under Ransomware Recovery to search for Indicators of Compromise (IOCs) across all protected infrastructure.
Cyber Recovery: Navigate to Cyber Recovery tab to initiate clean-point-in-time recovery for impacted resources and restore data safely.
Verify in your security tools: Search your security monitoring systems using the alert's time and specific clues (like suspicious files or IP addresses). This helps you connect the dots to see what happened and figure out how far the issue spread.
Navigate from alert to affected resources to identify the last clean recovery point
In the alert details, click the Impacted Resource link.
The system opens the resource's restore view.
Select the Cyber Recovery tab to view ransomware detection status for each recovery point.
Identify the most recent snapshot that shows no warning icons.
Select the checkbox next to the clean recovery point and click Restore. Monitor the restore job from the Jobs page. After the restore completes, verify the restored data is clean and functional.
4. Alert Details Breakdown
An expandable timeline list of individual alert instances recorded for the workload (For example: Aug 3 2026, 23:11):
Alert Status and Family: Status and specific threat family linked to that timestamp.
Total Impacted Files: Total file count affected specifically during that alert event.
Indicator Breakdown:
Counts per indicator type (Ransom Note, High Entropy Files, File Extension Changes, File Header Mismatch, Ransomware File Extensions, MIME Mismatch).
Specific detected file extension tags/chips (For example: .f2sw, .jwlj).
Download Logs: Located inside each individual alert card to allow administrators to export raw forensic logs for external SIEM or SOC analysis.
Download Logs for Suspicious Indicators
You can use the Download Logs option to download Suspicious Indicators reports for offline investigation and auditing purposes.
The data is downloaded in a compressed file format when you click the Download Logs option. Following is an example of the file naming convention of the downloaded file:
ResourceABC_SuspiciousIndicators_Sun-Aug-02-18-30-10-2026.zip
What information does the Suspicious Indicators download logs report contain?
The report includes the following information:
Field Name | Description | Example Value |
Alert Status | Detection classification for this specific alert event. |
|
Resource Name | Full name or hostname of the affected workload. |
|
Resource Type | Cloud or virtualization environment type. |
|
Ransomware Family | Identified threat family signatures associated with the alert. |
|
Alert Generated On | Date and time timestamp when the alert was triggered. |
|
Total Impacted Files | Total count of individual files identified as suspicious or compromised during this alert. |
|
Evidence Summary | Aggregate tally across detected indicators for quick triage. |
|
File Path | The absolute system or volume path of the impacted file |
|
File Size (Bytes) | Exact size of the flagged file in bytes |
|
Modified Timestamp | System timestamp indicating when the file was last modified prior to or during the alert event |
|
Signals | The specific indicator trigger attached to the file. |
|
Download Logs for Encryption Detected
You can use the Download Logs option to download Encryption Detected reports for offline investigation and auditing purposes.
The data is downloaded in a compressed file format when you click the Download Logs option. Following is an example of the file naming convention of the downloaded file:
ResourceABC_EncryptionDetected_Sun-Aug-02-18-30-10-2026.zip
What information does the Encryption Detected download logs report contain?
The report includes the following information:
Field Name | Description | Example Value |
Alert Status | Detection classification for this specific alert event. |
|
Resource Name | Full name or hostname of the affected workload. |
|
Resource Type | Cloud or virtualization environment type. |
|
Ransomware Family | Identified threat family signatures associated with the alert. |
|
Alert Generated On | Date and time timestamp when the alert was triggered. |
|
Total Impacted Files | Total count of individual files identified as suspicious or compromised during this alert. |
|
Evidence Summary | Aggregate tally across detected indicators for quick triage. |
|
File Path | The absolute system or volume path of the impacted file |
|
File Size (Bytes) | Exact size of the flagged file in bytes |
|
Modified Timestamp | System timestamp indicating when the file was last modified prior to or during the alert event |
|
Signals | The specific indicator trigger attached to the file. |
|
Understand Ransomware Detection status in Cyber Restore tab of workloads (Recovery Intelligence)
Cyber Restore tab or the Recovery Intelligence is the dashboard view that displays backup snapshots and their security status. The Ransomware Detection banner is displayed on the Cyber Restore tab which shows the security status for each snapshot:
Suspicious indicators: Detected behavioral indicators. Snapshot may be compromised.
Encryption Detected: Validated ransomware encryption. Do not restore this snapshot.
Clean: No ransomware indicators detected. Safe for restore.
Not Scanned: Snapshot has not yet been scanned by Ransomware Detection.
Trends tab
On the Trends tab, the Recovery Points Data Trend section provides vital security insights over the last 30 days for Ransomware Detection alerts.
For more information, see,
Use the clean snapshot for restore.









