ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Testing Ransomware

    Scheduled Pinned Locked Moved IT Discussion
    20 Posts 5 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • IRJI
      IRJ @stacksofplates
      last edited by

      @stacksofplates said in Testing Ransomware:

      @IRJ said in Testing Ransomware:

      How do are you guys testing Ransomware?

      I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

      Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

      That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

      stacksofplatesS 1 Reply Last reply Reply Quote 0
      • stacksofplatesS
        stacksofplates @IRJ
        last edited by

        @IRJ said in Testing Ransomware:

        @stacksofplates said in Testing Ransomware:

        @IRJ said in Testing Ransomware:

        How do are you guys testing Ransomware?

        I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

        Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

        That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

        Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

        IRJI 1 Reply Last reply Reply Quote 0
        • IRJI
          IRJ @stacksofplates
          last edited by

          @stacksofplates said in Testing Ransomware:

          @IRJ said in Testing Ransomware:

          @stacksofplates said in Testing Ransomware:

          @IRJ said in Testing Ransomware:

          How do are you guys testing Ransomware?

          I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

          Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

          That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

          Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

          I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

          stacksofplatesS 1 Reply Last reply Reply Quote 0
          • stacksofplatesS
            stacksofplates @IRJ
            last edited by

            @IRJ said in Testing Ransomware:

            @stacksofplates said in Testing Ransomware:

            @IRJ said in Testing Ransomware:

            @stacksofplates said in Testing Ransomware:

            @IRJ said in Testing Ransomware:

            How do are you guys testing Ransomware?

            I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

            Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

            That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

            Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

            I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

            I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.

            IRJI 1 Reply Last reply Reply Quote 1
            • IRJI
              IRJ @stacksofplates
              last edited by

              @stacksofplates said in Testing Ransomware:

              @IRJ said in Testing Ransomware:

              @stacksofplates said in Testing Ransomware:

              @IRJ said in Testing Ransomware:

              @stacksofplates said in Testing Ransomware:

              @IRJ said in Testing Ransomware:

              How do are you guys testing Ransomware?

              I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

              Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

              That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

              Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

              I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

              I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.

              AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?

              stacksofplatesS 1 Reply Last reply Reply Quote 0
              • stacksofplatesS
                stacksofplates @IRJ
                last edited by

                @IRJ said in Testing Ransomware:

                @stacksofplates said in Testing Ransomware:

                @IRJ said in Testing Ransomware:

                @stacksofplates said in Testing Ransomware:

                @IRJ said in Testing Ransomware:

                @stacksofplates said in Testing Ransomware:

                @IRJ said in Testing Ransomware:

                How do are you guys testing Ransomware?

                I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

                Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

                I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

                I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.

                AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?

                It all runs locally. You just set up a cron job and it can email out the results.

                IRJI 1 Reply Last reply Reply Quote 0
                • IRJI
                  IRJ @stacksofplates
                  last edited by

                  @stacksofplates said in Testing Ransomware:

                  @IRJ said in Testing Ransomware:

                  @stacksofplates said in Testing Ransomware:

                  @IRJ said in Testing Ransomware:

                  @stacksofplates said in Testing Ransomware:

                  @IRJ said in Testing Ransomware:

                  @stacksofplates said in Testing Ransomware:

                  @IRJ said in Testing Ransomware:

                  How do are you guys testing Ransomware?

                  I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                  Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                  That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

                  Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

                  I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

                  I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.

                  AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?

                  It all runs locally. You just set up a cron job and it can email out the results.

                  Ah, so it monitors the local server. No way to monitor other servers?

                  stacksofplatesS 1 Reply Last reply Reply Quote 0
                  • stacksofplatesS
                    stacksofplates @IRJ
                    last edited by

                    @IRJ said in Testing Ransomware:

                    @stacksofplates said in Testing Ransomware:

                    @IRJ said in Testing Ransomware:

                    @stacksofplates said in Testing Ransomware:

                    @IRJ said in Testing Ransomware:

                    @stacksofplates said in Testing Ransomware:

                    @IRJ said in Testing Ransomware:

                    @stacksofplates said in Testing Ransomware:

                    @IRJ said in Testing Ransomware:

                    How do are you guys testing Ransomware?

                    I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                    Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                    That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

                    Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

                    I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

                    I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.

                    AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?

                    It all runs locally. You just set up a cron job and it can email out the results.

                    Ah, so it monitors the local server. No way to monitor other servers?

                    No. It's just a local service. I mean you could mount directories and such from other systems, but it's just as easy to have it configure during the post install and then start checking on each system.

                    1 Reply Last reply Reply Quote 1
                    • S
                      Shuey
                      last edited by

                      "RanSim"

                      1 Reply Last reply Reply Quote 1
                      • AmbarishrhA
                        Ambarishrh
                        last edited by

                        I posted about this recently
                        https://www.mangolassi.it/topic/11225/ransim-ransomware-simulator

                        S 1 Reply Last reply Reply Quote 0
                        • S
                          Shuey @Ambarishrh
                          last edited by

                          @Ambarishrh said in Testing Ransomware:

                          I posted about this recently
                          https://www.mangolassi.it/topic/11225/ransim-ransomware-simulator

                          Right, which is the same thing I just posted above you 😛

                          1 Reply Last reply Reply Quote 0
                          • AmbarishrhA
                            Ambarishrh
                            last edited by

                            😄

                            1 Reply Last reply Reply Quote 0
                            • 1 / 1
                            • First post
                              Last post