Catch it while it is still staging.
Ransomware is loud long before it encrypts anything. Credential harvesting, share enumeration, backup interference, a sudden burst of read-then-write, all of it deviates from a known baseline, and all of it is visible if something is watching for change rather than for a file hash.
Four things every crew does first.
Tooling changes constantly. The behavioural sequence barely does, which is what makes it a better thing to watch.
Enumeration
A host suddenly cataloguing shares it has never touched is the earliest reliable signal.
Credential reuse
One set of credentials appearing on machines it has no history with.
Backup interference
Attempts to reach, disable or delete backup targets, almost always deliberate.
Read-write burst
Mass read followed by mass write, at a rate no legitimate process on that host has ever produced.
Containment measured in seconds, not tickets.
Once the pattern clears threshold, the segment can be isolated before the payload finishes its first directory.
- Segment isolationThe affected segment is cut from the rest of the estate under your standing authorisation.
- Session terminationActive sessions from the offending host are dropped, killing the spread path.
- Evidence preservedThe full trace is retained before containment, so investigation is not guesswork afterwards.
Six minutes, annotated.
A composite reconstruction of a contained attempt, drawn from real engagement traces.
00:00, foothold
A phished credential logs into a workstation. Nothing unusual yet, and nothing fires.
00:48, enumeration
The host begins cataloguing file shares it has never opened. First deviation scored.
01:52, spread attempt
The same credential appears on a second machine. Confidence crosses threshold.
02:31, backup probe
A connection to the backup target is attempted. Containment is proposed and taken.
06:04, closed
Segment isolated, sessions dropped, evidence pack written. Nothing was encrypted.
Where each control actually helps.
Layers, not replacements. Backups still matter, they just should not be your detection strategy.
| Control | Stops staging | Stops encryption | Recovers data |
|---|---|---|---|
| Immutable backups | , | , | ✓ |
| EDR on endpoints | Partially | ✓ | , |
| Signature AV | , | Partially | , |
| NetworkFort tripwires | ✓ | ✓ | , |
What teams ask before they switch.
Straight answers, including the ones that make a sale harder.
What if the attacker moves slowly?
Will legitimate bulk operations trigger it?
Do you need agents?
What if it starts on an unmanaged device?
Run your worst Friday afternoon against us.
Bring your actual environment and we will walk the sequence step by step in a live instance.