Well. This is impossible. There is no way to see difference between normal file access and virus crypting all your files..
Eero 7.6.2016 6.31 ip. "Nate" <[email protected]> kirjoitti: > We currently have samba file servers, which of course log access and > whatnot to the samba logs. > > I'm curious if I might be able to leverage ossec as a means to detect if a > system is attempting to lock up one of our shares due to a ransomware > infection. > > I could picture a rule that either detected a large amount of access from > a single client, or maybe a file name match on different extensions and > whatnot. The idea would be to detect this behavior and then block the > client before they get a chance to encrypt the share. > > Has anyone done something like this? I'm curious if it might be possible. > > > Thanks! > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
