Home  ›  Glossary  ›  Ransomware Detection

What is ransomware detection?

Ransomware detection is the identification of ransomware activity, either during the intrusion that precedes encryption or while files are being encrypted. It draws on signals from endpoints, identity systems, the network, storage and the backup infrastructure, and the earlier it succeeds, the more systems and restore points remain intact.

Change rate and data reduction in nightly jobs

Each night the backup system reads every changed block on every protected server, which makes it one of the most complete sensors in the environment. Mass encryption is hard to miss from there. A file server that normally sends a small slice of its data in each incremental suddenly sends most of it, and the incoming data no longer compresses or deduplicates, because encrypted output looks random. Repository consumption jumps at the same time, and later jobs can begin failing for lack of space.

Many backup products now flag these patterns automatically. Even without that, whoever reads the morning job report is often the first person in the organization to see that something is rewriting production data.

Signals before any file is encrypted

Earlier signs come from the preparation work, much of which passes through identity and backup systems:

  • Identity: logins at unusual hours, new administrator accounts, MFA devices registered, accounts used from unfamiliar machines.
  • Backup console: retention shortened, jobs disabled, restore points or repositories deleted, encryption passwords changed.
  • Storage: bursts of delete or overwrite requests against backup buckets, and deletions refused because retention is still active.
  • Decoy files: any access to files that no legitimate user or process ever opens.

An alert at this point can mean resetting a few accounts and cleaning a handful of machines. The same attack noticed only from the ransom note means rebuilding from whatever backups remain.

Detection methods and their blind spots

MethodWhat it looks forBlind spot
SignaturesKnown malware files and ransom notesNew or modified variants
Behavior analysisProcesses renaming or rewriting many filesBackup and sync jobs that behave the same way
Entropy analysisWritten data that looks randomCompressed archives and media files
Decoy filesAny touch on a file nobody usesEncryption that never reaches the decoy
Storage and backup telemetryUnusual change rates, deletions and overwritesEnvironments with no baseline of normal activity

Alerts that arrive at 2 a.m. on a Sunday

Detection helps only when someone acts on it. In a team of three or four, an alert raised early on a Sunday can sit until Monday, and attackers schedule their final stages for those hours. Restore points whose retention the storage enforces get through that gap without anyone responding; restore points that rely on an administrator noticing first may not.

Thresholds carry their own trade-off. Set low, they catch slow encryption and also fire during legitimate full backups, migrations and large software updates. Set high, they stay quiet until the damage is extensive. The environment's own backup schedule is the baseline that separates a real change in behavior from noise. Detection feeds recovery too: once the start of the intrusion is dated, that date marks how far back a restore has to reach to avoid bringing the attacker's tools back with the data.

ARTESCA and ransomware detection

ARTESCA is not a ransomware detection tool; it supplies storage telemetry to the tools that are. Its audit logs forward to Splunk, Graylog, Elasticsearch or syslog, and Grafana and Prometheus expose operational metrics, so a burst of deletes on a backup bucket can be lined up against identity and endpoint events in the SIEM.

Retention set through S3 Object Lock in compliance mode does not wait for the alert: the protected versions hold until their retain-until date whether or not anyone has looked.