This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

CryptoGuard Ransomware Detection

Hey folks,

Does anybody know how and what triggers ransomware attack detection?

We have a process via batch script and it calls for GPG.exe encryption on the files. This process are executed via remote workstation, and the target files are from our File Server. Including in the batch script is cleaning up of unencrypted files using sdelete command.

Am i right to assume that the ransomware attack was triggered after encrypting the file via GPG?

Thanks,

Kheir



This thread was automatically locked due to age.
Parents Reply Children
  • Thanks for the info Marcel,

    It is indeed a remote detection as the logs reports the IP address of the machine. So, this new exclusion type is still in EAP, do you know when this feature will become standard? And do you know if any other type of exclusion will be available - it would be nice if we have an option to exclude IP addresses as our remote workstation's IP addresses are reserved addresses.

    Regards,

    Kheir

  • Hi ,

    I do not have any details concerning when features move from the EAP to the standard release. But this EAP is open for anyone so you could give it a try by adding a specific server to the EAP.

    I have not seen anything around IP address exceptions, so this would be something for: https://ideas.sophos.com.

    Regards,
    Marcel