Well. This is impossible. There is no way to see difference between normal
file access and virus crypting all your files..

Eero
7.6.2016 6.31 ip. "Nate" <[email protected]> kirjoitti:

> We currently have samba file servers, which of course log access and
> whatnot to the samba logs.
>
> I'm curious if I might be able to leverage ossec as a means to detect if a
> system is attempting to lock up one of our shares due to a ransomware
> infection.
>
> I could picture a rule that either detected a large amount of access from
> a single client, or maybe a file name match on different extensions and
> whatnot.  The idea would be to detect this behavior and then block the
> client before they get a chance to encrypt the share.
>
> Has anyone done something like this?  I'm curious if it might be possible.
>
>
> Thanks!
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> For more options, visit https://groups.google.com/d/optout.
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to