We use cookies to try and give you a better experience in Freshdesk.
You can learn more about what kind of cookies we use, why, and how from our Privacy policy. If you hate cookies, or are just on a diet, you can disable them altogether too. Just note that the Freshdesk service is pretty big on some cookies (we love the choco-chip ones), and some portions of Freshdesk may not work properly if you disable cookies.
We’ll also assume you agree to the way we use cookies and are ok with it as described in our Privacy policy, unless you choose to disable them altogether through your browser.
Hi
I am testing EventSentry Light as a tool to detect and stop ransomware. I followed the procedure as described in ‘Defeating Ransomware with EventSentry & Auditing (Part 3/3)’. This seems to stop ransomware, but the number of false positives is way too high. As soon as a user copies a relatively large number of files to the server (e.g. a series of photos from a camera) this is also detected as ransomware. Am I missing something?
Best greetings,
Koen
0 Votes
2 Comments
Koen Gryspeerdt posted almost 2 years ago
Hi,
Thank you for the informative reply. I will test this further, but I'm afraid that it will be dificult to define a 'normal' file server usage pattern. I will also take a good look at the other features of EventSentry.
Best greetings,
Koen
0 Votes
Mariano Bruno posted almost 2 years ago Admin
Hello Koen,
This method primarily targets high volumes of file activity. However, the article already mentions that it may not be suitable for file servers:
You could consider adjusting the alert threshold. For instance, if users typically copy a folder containing 50 pictures, try increasing the Threshold Interval from 30 to 55.
If copying pictures is a frequent occurrence for your users, it might be worth filtering out .jpg extensions to reduce unnecessary alerts.
Keep in mind, this is a "nuclear" approach. It monitors any file activity exceeding 30 changes within 3 minutes, and it cannot distinguish between ransomware encryption and regular file copying. Any event that meets the criteria will trigger an alert.
For a more refined solution, check out this better approach outlined in the article HERE. Additionally, the full-featured version of EventSentry is now available for free for home labs. You can request your license HERE
0 Votes
Login or Sign up to post a comment