Testing Ransomware
-
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
How do are you guys testing Ransomware?
I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.
Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?
That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.
Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.
I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?
-
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
How do are you guys testing Ransomware?
I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.
Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?
That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.
Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.
I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?
I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.
-
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
How do are you guys testing Ransomware?
I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.
Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?
That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.
Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.
I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?
I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.
AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?
-
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
How do are you guys testing Ransomware?
I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.
Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?
That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.
Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.
I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?
I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.
AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?
It all runs locally. You just set up a cron job and it can email out the results.
-
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
How do are you guys testing Ransomware?
I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.
Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?
That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.
Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.
I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?
I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.
AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?
It all runs locally. You just set up a cron job and it can email out the results.
Ah, so it monitors the local server. No way to monitor other servers?
-
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
@stacksofplates said in Testing Ransomware:
@IRJ said in Testing Ransomware:
How do are you guys testing Ransomware?
I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.
Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?
That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.
Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.
I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?
I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.
AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?
It all runs locally. You just set up a cron job and it can email out the results.
Ah, so it monitors the local server. No way to monitor other servers?
No. It's just a local service. I mean you could mount directories and such from other systems, but it's just as easy to have it configure during the post install and then start checking on each system.
-
-
I posted about this recently
https://www.mangolassi.it/topic/11225/ransim-ransomware-simulator -
@Ambarishrh said in Testing Ransomware:
I posted about this recently
https://www.mangolassi.it/topic/11225/ransim-ransomware-simulatorRight, which is the same thing I just posted above you
-