đNOTE: The availability of this feature may be limited based on the license type, region, and other criteria. To enable this feature, contact support.
What is Ransomware Detection?
Ransomware Detection is a multi-stage detection framework that utilizes Machine Learning (ML) and pattern recognition to identify ransomware activity within backed up data. It analyzes key ransomware indicators and behavioral patterns such as suspicious file extension changes, dropped artifacts, and encryption techniques to generate high-confidence, explainable alerts. This enables precise differentiation between legitimate operational activity and malicious behavior.
How is Ransomware Detection different from Data Anomalies?
Ransomware Detection and Data Anomalies serve different purposes. Ransomware Detection confirms ransomware impact with evidence. Data Anomalies flags deviations from baseline activity that may or may not be malicious.
Criteria | Ransomware Detection | Data Anomalies |
Purpose | Confirm ransomware impact | Flag unusual data activity |
Detection method | Behavioral correlations & Forensic Validations | Anomaly-based |
Zero-day coverage | Yes | No |
False positives | Minimal | Low |
How is Ransomware Detection different from Threat Watch?
Threat Watch detects known malicious files using IOC (Indicator of Compromise) signatures. Ransomware Detection uses behavioral analysis to identify ransomware activity. This includes unknown and zero-day variants that Threat Watch cannot detect.
Criteria | Ransomware Detection | Threat Watch |
Detection method | Behavioral based correlations | IOC/signature-based |
Zero-day coverage | Yes | No |
Known threat detection | Yes | Yes (very high accuracy) |
False positives | Minimal | Minimal |
How frequently does Ransomware Detection run?
Ransomware Detection runs at an interval of every 6 hours.
What workloads are supported for Ransomware Detection?
Hereâs the list:
VMware VMs
Azure VMs
AWS EC2
AWS EBS
What happens to Encryption alerts generated by Data Anomaly?
If you have both Data Anomaly and Ransomware Detection enabled, the encryption check via Ransomware Detection takes precedence.
Can Ransomware Detection identify the ransomware family?
Ransomware Detection can identify known ransomware families when disallowed extensions or known ransom note patterns are detected. For unknown variants, the system identifies the attack based on behavioral patterns. It does not attribute unknown variants to a specific family.
What if Ransomware Detection generates a false positive?
If you believe a snapshot was incorrectly flagged, follow these steps:
Review the detection evidence in the alert details.
If you confirm the snapshot is clean, use the Mark as not impacted option to release it from quarantine.
Does Ransomware Detection require additional licensing?
Yes, Ransomware Detection requires the Premium Security SKU.
How does quarantine work?
When Ransomware Detection confirms ransomware impact, you must isolate the infected resource to prevent further spread of infection. Quarantined snapshots cannot be restored until you release them. This prevents accidental restoration from infected backups.
