Ransomware Detection

Ransomware Detection in VSA 9, part of the Endpoint Protection module, is a secure and fully featured cloud platform which provides an extra layer of security, allowing you to deploy the Ransomware engine to the endpoints. The RDM monitors for the existence of crypto ransomware on endpoints using proprietary behavioral analysis of files and alerts you when a device is infected. Once ransomware is detected, RDM can isolate the device and attempt to stop suspected ransomware processes to prevent the ransomware from spreading.

Operations

How to...

Ransomware Detection logging

NAVIGATION   Endpoint Protection > Application > Logging

The Logging page maintains a history log of all the events associated with ransomware deployment, which includes ransomware events, event logs, and information collected from the endpoints. This information is primarily used for troubleshooting purposes.

The Logging page displays the following information in a tabular format:

  • Event Date: The date on which the event occurred.
  • Event Name: The name of the event.
  • Machine ID: The machine that the event applies to.
  • Group ID: The machine group that the event applies to.
  • Message: Details of the event.
  • Admin: The VSA admin who initiated the event.

Filtering columns

In the columns drop-down menu, select the column you want to filter.

The selected column is displayed in the Filter columns field.