Ransomware is a specific type of malware that holds data “hostage,” and is especially disruptive to business due to its data-destructive nature. The ransomware threat doesn’t need to keep security practitioners up at night. Detection of ransomware is key to removing compromised devices from an infected network but a holistic approach to security, centered around prevention, is necessary to keep organizations from falling victim to malware attacks.
This paper will take users on a step-by-step journey on how to detect unknown malware activity and early signs of compromise in a Windows environment. These techniques can be applied to detect malware and ransomware using Windows Systinternal events.