đNOTE: The availability of this feature may be limited based on the license type, region, and other criteria. To enable this feature, contact support.
Overview
Ransomware Detection is a multi-stage detection framework that utilizes Machine Learning (ML) and pattern recognition to identify ransomware activity within backed up data.
It analyzes key ransomware indicators and behavioral patterns such as suspicious file extension changes, dropped artifacts, and encryption techniques to generate high-confidence, explainable alerts. This enables precise differentiation between legitimate operational activity and malicious behavior.
Key Benefits
Precision Detection: Get alerted only when it truly matters, high-confidence signals of real issues, with minimal noise and near-zero false positives.
Alert Prioritization: Clear severity mapping (warning and critical) based on the stage of detection.
Zero-Day Protection: It detects known, unknown, and new ransomware strains by identifying suspicious behavioral patterns.
Scalable Telemetry: Powered by field-driven data for continuous model refinement.
Minimize Business Impact: Identify the specific impact of an attack and locate exact restore points needed for a surgical and clean recovery.
Reduce Infrastructure Overhead: Fully managed SaaS platform with zero local software or hardware maintenance.
Access Path for Ransomware Detection
To access this feature, from the Druva Cloud Platform Console, go to the Global Navigation menu > Cyber Resiliency > Posture & Observability > Ransomware Detection. Click Ransomware Detection. You will be redirected to the Ransomware Detection dashboard page.
Here's a quick video tour that helps you get started with Ransomware Detection feature.
Set up
Ransomware Detection is designed as a plug-and-play capability, requiring no configuration. Once enabled, it begins to detect suspicious ransomware activity on your backed up data.
Supported workloads
VMware Virtual Machines
Azure Virtual Machines
AWS Workloads - EC2 and EBS Volume
What Druva License is required to use this feature?
Ransomware Detection feature is available with the Premium Security SKU.
How to enable this Ransomware Detection feature?
Contact your Account Manager or raise a case via Dru Assist to enable this feature.
What permissions are required to access Ransomware Detection?
You must have a Druva Cloud Administrator role to access Ransomware Detection feature.
đNote: Druva Cloud Administrators have full authorization to perform Read, Write, Create, Delete, Edit, and Block actions. In contrast, the Druva Cloud Platform View-Only Administrator role provides strict view access, prohibiting any Create, Delete, Edit, or Block operations. For more information, see Role Based Access Control for Cyber Resiliency and Manage Druva Administrators.
How it Works: The Multi-Stage Framework
Ransomware Detection utilizes a layered defense strategy to correlate multiple signals before escalating an alert.
Stage | Category | Alert Title | Alert Severity |
Stage 1 | Pre-Ransom Checks | Suspicious Indicators | Warning |
Stage 2 | Ransom Impact | Encryption Detected | Critical |
Stage 1: Potential Ransomware Detection of Ransomware Activity
During this stage, Druva uses proprietary enhanced Machine Learning (ML) models to continuously analyze backup snapshots for high-risk behavioral indicators, including mass renaming, ransom notes, and suspicious file extensions. If any high-risk indicators are detected, Druva generates a âSuspicious Indicators Foundâ notification via email to alert you to potential ransomware activity, automatically escalating the affected snapshot for forensic analysis.
Stage 2: Forensic Validation of Ransomware Activity
When Stage 1 flags a snapshot for potential ransomware activity, the system automatically initiates Stage 2 to conduct an in-depth forensic analysis and confirm active encryption. To ensure high accuracy, this confirmation relies on a robust, multi-layered process that evaluates multiple indicators of encryption and file tampering rather than a single signal. Once confirmed, an Encryption Detected alert is sent via email alongside supporting evidence to enable confident incident response.
Action: What should you do once you receive alerts for Ransomware Detection?
After investigating alerts, take appropriate action:
For Suspicious Indicators alert
Mark as Not Impacted if deemed as a false positive alert. This should be used in case of Stage 1 - Suspicious Indicators alert after a thorough investigation of the alert.
For Encryption Detected alert
Declare ransomware impact: You can confidently declare a ransomware incident.
Initiate containment via Manual Quarantine: Admins can manually isolate snapshots to prevent them from being used in any restore operations. Quarantined snapshots cannot be restored until you release them. If you confirm the snapshot is clean, see Manage Quarantined Snapshots to release it.
Coordinate with Backup Admin: Share the incident context with your Backup Admin to begin recovery planning.
đNote: Behavioral security tools watch for actions typical of ransomware such as rapidly modifying files, scrambling data (encryption), or renaming files in bulk. However, a false positive occurs when legitimate programs are flagged for doing these exact same things as part of their normal jobs.
Monitor Ransomware Detection
Track and monitor all the Ransomware Detection activities from Audit Trails.
View the detailed Ransomware Detection Report for auditing and offline investigation purposes.