Skip to main content

FAQ's for Ransomware Detection

Provides a list of frequently asked questions for Ransomware Detection

📝NOTE: The availability of this feature may be limited based on the license type, region, and other criteria. To enable this feature, contact support.

What is Ransomware Detection?

Ransomware Detection is a multi-stage detection framework that utilizes Machine Learning (ML) and pattern recognition to identify ransomware activity within backed up data. It analyzes key ransomware indicators and behavioral patterns such as suspicious file extension changes, dropped artifacts, and encryption techniques to generate high-confidence, explainable alerts. This enables precise differentiation between legitimate operational activity and malicious behavior.

How is Ransomware Detection different from Data Anomalies?

Ransomware Detection and Data Anomalies serve different purposes. Ransomware Detection confirms ransomware impact with evidence. Data Anomalies flags deviations from baseline activity that may or may not be malicious.

Criteria

Ransomware Detection

Data Anomalies

Purpose

Confirm ransomware impact

Flag unusual data activity

Detection method

Behavioral correlations & Forensic Validations

Anomaly-based

Zero-day coverage

Yes

No

False positives

Minimal

Low

How is Ransomware Detection different from Threat Watch?

Threat Watch detects known malicious files using IOC (Indicator of Compromise) signatures. Ransomware Detection uses behavioral analysis to identify ransomware activity. This includes unknown and zero-day variants that Threat Watch cannot detect.

Criteria

Ransomware Detection

Threat Watch

Detection method

Behavioral based correlations

IOC/signature-based

Zero-day coverage

Yes

No

Known threat detection

Yes

Yes (very high accuracy)

False positives

Minimal

Minimal

How frequently does Ransomware Detection run?

Ransomware Detection runs at an interval of every 6 hours.

What workloads are supported for Ransomware Detection?

Here’s the list:

  • VMware VMs

  • Azure VMs

  • AWS EC2

  • AWS EBS

What happens to Encryption alerts generated by Data Anomaly?

If you have both Data Anomaly and Ransomware Detection enabled, the encryption check via Ransomware Detection takes precedence.

Can Ransomware Detection identify the ransomware family?

Ransomware Detection can identify known ransomware families when disallowed extensions or known ransom note patterns are detected. For unknown variants, the system identifies the attack based on behavioral patterns. It does not attribute unknown variants to a specific family.

What if Ransomware Detection generates a false positive?

If you believe a snapshot was incorrectly flagged, follow these steps:

  1. Review the detection evidence in the alert details.

  2. If you confirm the snapshot is clean, use the Mark as not impacted option to release it from quarantine.

Does Ransomware Detection require additional licensing?

Yes, Ransomware Detection requires the Premium Security SKU.

How does quarantine work?

When Ransomware Detection confirms ransomware impact, you must isolate the infected resource to prevent further spread of infection. Quarantined snapshots cannot be restored until you release them. This prevents accidental restoration from infected backups.

Did this answer your question?