Ransomware Monitoring
Curious if anyone is leveraging LM for first line Ransomware detection. Reading indicators typically include a high number of file name changes on the server/PC. Seems like that would be something that LM could help us identify early on and alert out to take action before additional servers are compromised. Looks like a working number is about 4 renames a second for the threshold.
Thanks,
Mitch
Mitchel_Erb
Posted 8 years ago·Last reply 8 years ago
1 comment
John_Certeza
·8 years agoMitchel, if your monitoring Windows Systems for ransomware, you could likely adapt the FSRM script linked here and trigger alerts on a file monitor or such? https://fsrm.experiant.ca/