Views:

File Reputation

Detection NamePattern branch/version
Ransom.Win32.CRYPSPORT.A
Ransom.Win32.CRYPSPORT.B
Ransom.Win32.CRYPSPORT.C
Ransom.Win32.CRYPSPORT.B.note
Ransom.Win32.CRYPSPORT.A.SM – One to Many detection
ENT OPR 15.505.00

Predictive Machine Learning

Detection NamePattern branch/version
Rapid ProliferationIn-the-cloud

Rapid Proliferation is a mechanism to detect suspicious files that exceed the threshold by attaching the "Bad Rating" to the suspicious sample.

Behavior Monitoring

Policy IDPattern branch/version
RAN4056T – Generic DEL Shadow Copy commands
Supported by ADC (Access Document Control)
BM OPR 1.907

Sandbox Solution

Detection NamePattern branch/version
VAN_RANSOMWARESandbox Behavior

Recommendations

Comments (0)