Request a demo
HomeRansomware Protection
Protection ยท tripwire

Catch it while it is still staging.

Ransomware is loud long before it encrypts anything. Credential harvesting, share enumeration, backup interference, a sudden burst of read-then-write, all of it deviates from a known baseline, and all of it is visible if something is watching for change rather than for a file hash.

38sMedian detect time
Pre-payloadDetection stage
<1%False positives
The kill chain

Four things every crew does first.

Tooling changes constantly. The behavioural sequence barely does, which is what makes it a better thing to watch.

Enumeration

A host suddenly cataloguing shares it has never touched is the earliest reliable signal.

Credential reuse

One set of credentials appearing on machines it has no history with.

Backup interference

Attempts to reach, disable or delete backup targets, almost always deliberate.

Read-write burst

Mass read followed by mass write, at a rate no legitimate process on that host has ever produced.

Response

Containment measured in seconds, not tickets.

Once the pattern clears threshold, the segment can be isolated before the payload finishes its first directory.

  • Segment isolationThe affected segment is cut from the rest of the estate under your standing authorisation.
  • Session terminationActive sessions from the offending host are dropped, killing the spread path.
  • Evidence preservedThe full trace is retained before containment, so investigation is not guesswork afterwards.
Detected pre-encryption96%
Median detect time38s
Backup tampering caught100%
Legitimate bulk jobs allowed99%
Anatomy

Six minutes, annotated.

A composite reconstruction of a contained attempt, drawn from real engagement traces.

00:00, foothold

A phished credential logs into a workstation. Nothing unusual yet, and nothing fires.

00:48, enumeration

The host begins cataloguing file shares it has never opened. First deviation scored.

01:52, spread attempt

The same credential appears on a second machine. Confidence crosses threshold.

02:31, backup probe

A connection to the backup target is attempted. Containment is proposed and taken.

06:04, closed

Segment isolated, sessions dropped, evidence pack written. Nothing was encrypted.

Honest comparison

Where each control actually helps.

Layers, not replacements. Backups still matter, they just should not be your detection strategy.

ControlStops stagingStops encryptionRecovers data
Immutable backups,,
EDR on endpointsPartially,
Signature AV,Partially,
NetworkFort tripwires,
Questions

What teams ask before they switch.

Straight answers, including the ones that make a sale harder.

What if the attacker moves slowly?
Slow movement still deviates from the host's baseline. Rate is one signal among several, not the whole test.
Will legitimate bulk operations trigger it?
Backup windows, migrations and indexing jobs become part of the baseline once observed. New ones can be declared in advance.
Do you need agents?
No. Network behaviour is enough for detection, though endpoint telemetry sharpens confidence where available.
What if it starts on an unmanaged device?
That is the common case. CyberEye discovers unmanaged devices, so they carry baselines too.
Tabletop exercise

Run your worst Friday afternoon against us.

Bring your actual environment and we will walk the sequence step by step in a live instance.