ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Preventive measures against ransomware

    IT Discussion
    nomoreransomware
    5
    12
    1.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • AmbarishrhA
      Ambarishrh
      last edited by Ambarishrh

      We are hardening our environment to reduce the risk of ransomware attack and would like to get some advise from ML

      Few of the changes we are enforcing includes:

      Backup: All endpoints are being backed up to a remote location. Veeam backup repo now uses Linux NFS instead of windows NTFS for storage.

      Servers: Least privilege method and logging/audit enabled on AD and File server. Harden all servers, reference points from https://adsecurity.org

      FSRM to be updated for File server screening using https://github.com/nexxai/CryptoBlocker
      https://fsrm.experiant.ca/

      End point protection: Av+ Malwarebytes

      Usb/removable drives: I would like to have the usbs scanned on a few dedictaed machines that is disconnected from the network, scan with multiple av engines and would even want to go further by opening all files, may be allow all possible options like auto run and see if there are threats. If clean then allow the user to use that USB for that session only. We disabled usb read and write centrally but can't block that permanently as we get usb from third parties. The scanning station can have something like deep freeze which will bring the machine back to its original state after a reboot.

      User education: use something like knowbe4 security awareness programs to train employees to identify common threats like spam phishing mails, suspicious links etc.

      Firewall with the usual security settings DPI, IDS, IPS etc.

      Patch management: Looking at ivanti or shavlik to enhance our sccm and cover third party patches as well. Currently it's package and update

      J 4 Replies Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller
        last edited by

        LANless is one of the biggest factors.

        1 Reply Last reply Reply Quote 0
        • J
          Jimmy9008 @Ambarishrh
          last edited by

          @ambarishrh said in Preventive measures against ransomware:

          Backup: All endpoints are being backed up to a remote location. Veeam backup repo now uses Linux NFS instead of windows NTFS for storage.

          What is the retention period? I've seen a few places that only hold 1 x backup for workstations and overwrite that nightly. If a machine is infected, you could overwrite the good backup before finding out...

          AmbarishrhA 1 Reply Last reply Reply Quote 2
          • J
            Jimmy9008 @Ambarishrh
            last edited by

            @ambarishrh said in Preventive measures against ransomware:

            Usb/removable drives: I would like to have the usbs scanned on a few dedictaed machines that is disconnected from the network, scan with multiple av engines and would even want to go further by opening all files, may be allow all possible options like auto run and see if there are threats. If clean then allow the user to use that USB for that session only. We disabled usb read and write centrally but can't block that permanently as we get usb from third parties. The scanning station can have something like deep freeze which will bring the machine back to its original state after a reboot.

            Do you have to allow USB at all?

            1 Reply Last reply Reply Quote 0
            • J
              Jimmy9008 @Ambarishrh
              last edited by

              @ambarishrh said in Preventive measures against ransomware:

              Firewall with the usual security settings DPI, IDS, IPS etc.

              Also look at vulnerability testing on the LAN side, and get audit/Pentesting done to verify external threats that you could be open to.

              1 Reply Last reply Reply Quote 1
              • J
                Jimmy9008 @Ambarishrh
                last edited by

                @ambarishrh

                Look at SRP. Default to all denied, and only allow what you approve to run.

                1 Reply Last reply Reply Quote 1
                • AmbarishrhA
                  Ambarishrh @Jimmy9008
                  last edited by

                  @jimmy9008 said in Preventive measures against ransomware:

                  @ambarishrh said in Preventive measures against ransomware:

                  Backup: All endpoints are being backed up to a remote location. Veeam backup repo now uses Linux NFS instead of windows NTFS for storage.

                  What is the retention period? I've seen a few places that only hold 1 x backup for workstations and overwrite that nightly. If a machine is infected, you could overwrite the good backup before finding out...

                  30 days

                  1 Reply Last reply Reply Quote 0
                  • iroalI
                    iroal
                    last edited by

                    I've installed ransomfree https://ransomfree.cybereason.com/

                    Good tool, and free, to avoid ransomware.

                    AmbarishrhA 1 Reply Last reply Reply Quote 1
                    • AmbarishrhA
                      Ambarishrh @iroal
                      last edited by

                      @iroal said in Preventive measures against ransomware:

                      I've installed ransomfree https://ransomfree.cybereason.com/

                      Good tool, and free, to avoid ransomware.

                      Check if that detects when you run ransim https://www.knowbe4.com/ransomware-simulator

                      RojoLocoR iroalI 3 Replies Last reply Reply Quote 1
                      • RojoLocoR
                        RojoLoco @Ambarishrh
                        last edited by

                        @ambarishrh said in Preventive measures against ransomware:

                        @iroal said in Preventive measures against ransomware:

                        I've installed ransomfree https://ransomfree.cybereason.com/

                        Good tool, and free, to avoid ransomware.

                        Check if that detects when you run ransim https://www.knowbe4.com/ransomware-simulator

                        We have Webroot and RansomFree. Scored 10/10 on ransim, everything blocked.

                        1 Reply Last reply Reply Quote 1
                        • iroalI
                          iroal @Ambarishrh
                          last edited by

                          @ambarishrh

                          Cool tool Rainsim

                          1 Reply Last reply Reply Quote 0
                          • iroalI
                            iroal @Ambarishrh
                            last edited by

                            @ambarishrh said in Preventive measures against ransomware:

                            @iroal said in Preventive measures against ransomware:

                            I've installed ransomfree https://ransomfree.cybereason.com/

                            Good tool, and free, to avoid ransomware.

                            Check if that detects when you run ransim https://www.knowbe4.com/ransomware-simulator

                            Ransomfree create a few folders in the system with many dummy files inside (.doc .jpg .xlsx..)

                            In case one of these files change, Ramonfree block the computer and ask you if you allow these changes.

                            Ransim just check his installation folder so Rasomfree cannot detect it.

                            1 Reply Last reply Reply Quote 1
                            • 1 / 1
                            • First post
                              Last post