Lumetrace / Ransomware detection
Ransomware

Ransomware detection: see the staging, not the ransom note.

By the time files are encrypted, the interesting part is over. Everything that happened in the days before it is a sequence of network events, and that sequence is where detection is still useful.

Ransomware is a sequence, not an event

Encryption is the last step, and it is the only step most organisations ever see. Before it, a fairly predictable sequence has to happen, and almost every stage of it crosses the network:

  • Initial foothold, then a call home. The first machine reaches out to an operator for instructions. That channel has to exist and has to keep existing.
  • Reconnaissance. Somebody enumerates hosts, shares, domain controllers and backup servers. This looks like scanning, because it is.
  • Credential reuse across shares. One account suddenly touching file servers it has never touched, at machine speed.
  • Backup destruction. Attackers go for the backup infrastructure first, because that is what turns an incident into a payment.
  • Data staging and exfiltration. Modern operators steal before they encrypt, so they can extort you twice. Large volumes go somewhere they have never gone before.
  • Deployment and spread. The payload gets pushed to many hosts at once, often over the same administrative channels used above.

Why endpoint-only detection sees part of this, not all of it

Endpoint tooling is genuinely good at the encryption stage, and it should stay. The gap is earlier and elsewhere. Hypervisors, storage appliances, network-attached storage, backup targets and industrial equipment frequently run no agent at all, and those are exactly the systems a competent operator goes after. Agents can also be tampered with by an attacker who already has administrative rights.

Network detection does not have that problem, because the sensor is not on the machine being attacked. It watches from beside the traffic, so an attacker cannot turn it off from inside the host they control.

What we detect, stated honestly

We are a detection company, not a prevention company, and we would rather say that plainly than let you assume otherwise. What we do is make the sequence visible and evidenced, early enough that intervention is still meaningful, and correlated into one story rather than six unrelated alerts.

Where you already run a firewall we can integrate to act on a confirmed indicator, but the honest framing is this: we shorten the time between the first network event and somebody knowing about it. We do not promise that no ransomware will ever execute in your environment, and any vendor who does is selling you something they cannot deliver.

Questions

Ransomware detection: straight answers

Can you detect it before the files are encrypted?

That is the entire design goal. Reconnaissance, the command-and-control channel, credential reuse across shares, backup deletion and data staging all happen before encryption and all cross the network. Whether that becomes a save depends on whether somebody acts on the finding, which is why the findings are written to be actionable rather than merely accurate.

What about double extortion, where they steal the data first?

The theft is a network event, so it is in scope. We look for large or unusual transfers to destinations that host has no history with, encoded or tunnelled transfers, and uploads to cloud services that were never approved.

Do you detect the encryption itself?

Encryption of local files is a host event, and your endpoint tool is better placed for it. What we see is the spread: the administrative channels used to push a payload to many machines at once, and the traffic pattern of mass file access over shares.

Find your blind spots before an attacker does.

Tell us whether you suspect something is already inside, or whether you want to measure what your current tools would catch. Either way you get a concrete next step.

Contact us
Related

More on what we detect