ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Testing Ransomware

    Scheduled Pinned Locked Moved IT Discussion
    20 Posts 5 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • IRJI
      IRJ
      last edited by

      How do are you guys testing Ransomware?

      I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

      stacksofplatesS 1 Reply Last reply Reply Quote 1
      • DustinB3403D
        DustinB3403
        last edited by

        This is almost as bad as the topic on SW a few months back where the person was actively seeking Ransomware to demo how dangerous it is "on a private network".

        IRJI 1 Reply Last reply Reply Quote 0
        • IRJI
          IRJ @DustinB3403
          last edited by

          @DustinB3403 said in Testing Ransomware:

          This is almost as bad as the topic on SW a few months back where the person was actively seeking Ransomware to demo how dangerous it is "on a private network".

          I'd say practicing procedures and testing out countermeasures is pretty important.

          DustinB3403D 1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403 @IRJ
            last edited by

            @IRJ said in Testing Ransomware:

            @DustinB3403 said in Testing Ransomware:

            This is almost as bad as the topic on SW a few months back where the person was actively seeking Ransomware to demo how dangerous it is "on a private network".

            I'd say practicing procedures and testing out countermeasures is pretty important.

            But procedure is to always stay current with software and updates, perform educational training, pen. testing, and if you do get infected, restore from backups.

            1 Reply Last reply Reply Quote 0
            • DustinB3403D
              DustinB3403
              last edited by

              The reason that "testing ransomware" is so dangerous is because no matter how "safe" you are, you still run the risk of causing unintentional damage.

              Lacking a better example; Testing condoms to see if they actually stop the HIV virus by having intercourse with someone with the HIV virus.

              Sure... you're testing the protection, but what if something goes wrong?

              IRJI 1 Reply Last reply Reply Quote 1
              • IRJI
                IRJ @DustinB3403
                last edited by

                @DustinB3403 said in Testing Ransomware:

                The reason that "testing ransomware" is so dangerous is because no matter how "safe" you are, you still run the risk of causing unintentional damage.

                Lacking a better example; Testing condoms to see if they actually stop the HIV virus by having intercourse with someone with the HIV virus.

                Sure... you're testing the protection, but what if something goes wrong?

                Well if you are testing the condom itself for leaks then you are fine. I wouldn't test it on my body (live system).

                DustinB3403D 1 Reply Last reply Reply Quote 0
                • DustinB3403D
                  DustinB3403 @IRJ
                  last edited by

                  @IRJ said in Testing Ransomware:

                  @DustinB3403 said in Testing Ransomware:

                  The reason that "testing ransomware" is so dangerous is because no matter how "safe" you are, you still run the risk of causing unintentional damage.

                  Lacking a better example; Testing condoms to see if they actually stop the HIV virus by having intercourse with someone with the HIV virus.

                  Sure... you're testing the protection, but what if something goes wrong?

                  Well if you are testing the condom itself for leaks then you are fine. I wouldn't test it on my body (live system).

                  But the test is worthless without a whole-system approach; right? So the only true way to know is by doing the test in a real world scenario.

                  Which no one would willfully do (I would hope)

                  1 Reply Last reply Reply Quote 0
                  • stacksofplatesS
                    stacksofplates @IRJ
                    last edited by

                    @IRJ said in Testing Ransomware:

                    How do are you guys testing Ransomware?

                    I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                    Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                    IRJI 1 Reply Last reply Reply Quote 0
                    • IRJI
                      IRJ @stacksofplates
                      last edited by

                      @stacksofplates said in Testing Ransomware:

                      @IRJ said in Testing Ransomware:

                      How do are you guys testing Ransomware?

                      I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                      Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                      That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

                      stacksofplatesS 1 Reply Last reply Reply Quote 0
                      • stacksofplatesS
                        stacksofplates @IRJ
                        last edited by

                        @IRJ said in Testing Ransomware:

                        @stacksofplates said in Testing Ransomware:

                        @IRJ said in Testing Ransomware:

                        How do are you guys testing Ransomware?

                        I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                        Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                        That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

                        Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

                        IRJI 1 Reply Last reply Reply Quote 0
                        • IRJI
                          IRJ @stacksofplates
                          last edited by

                          @stacksofplates said in Testing Ransomware:

                          @IRJ said in Testing Ransomware:

                          @stacksofplates said in Testing Ransomware:

                          @IRJ said in Testing Ransomware:

                          How do are you guys testing Ransomware?

                          I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                          Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                          That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

                          Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

                          I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

                          stacksofplatesS 1 Reply Last reply Reply Quote 0
                          • stacksofplatesS
                            stacksofplates @IRJ
                            last edited by

                            @IRJ said in Testing Ransomware:

                            @stacksofplates said in Testing Ransomware:

                            @IRJ said in Testing Ransomware:

                            @stacksofplates said in Testing Ransomware:

                            @IRJ said in Testing Ransomware:

                            How do are you guys testing Ransomware?

                            I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                            Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                            That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

                            Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

                            I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

                            I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.

                            IRJI 1 Reply Last reply Reply Quote 1
                            • IRJI
                              IRJ @stacksofplates
                              last edited by

                              @stacksofplates said in Testing Ransomware:

                              @IRJ said in Testing Ransomware:

                              @stacksofplates said in Testing Ransomware:

                              @IRJ said in Testing Ransomware:

                              @stacksofplates said in Testing Ransomware:

                              @IRJ said in Testing Ransomware:

                              How do are you guys testing Ransomware?

                              I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                              Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                              That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

                              Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

                              I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

                              I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.

                              AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?

                              stacksofplatesS 1 Reply Last reply Reply Quote 0
                              • stacksofplatesS
                                stacksofplates @IRJ
                                last edited by

                                @IRJ said in Testing Ransomware:

                                @stacksofplates said in Testing Ransomware:

                                @IRJ said in Testing Ransomware:

                                @stacksofplates said in Testing Ransomware:

                                @IRJ said in Testing Ransomware:

                                @stacksofplates said in Testing Ransomware:

                                @IRJ said in Testing Ransomware:

                                How do are you guys testing Ransomware?

                                I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                                Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                                That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

                                Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

                                I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

                                I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.

                                AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?

                                It all runs locally. You just set up a cron job and it can email out the results.

                                IRJI 1 Reply Last reply Reply Quote 0
                                • IRJI
                                  IRJ @stacksofplates
                                  last edited by

                                  @stacksofplates said in Testing Ransomware:

                                  @IRJ said in Testing Ransomware:

                                  @stacksofplates said in Testing Ransomware:

                                  @IRJ said in Testing Ransomware:

                                  @stacksofplates said in Testing Ransomware:

                                  @IRJ said in Testing Ransomware:

                                  @stacksofplates said in Testing Ransomware:

                                  @IRJ said in Testing Ransomware:

                                  How do are you guys testing Ransomware?

                                  I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                                  Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                                  That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

                                  Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

                                  I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

                                  I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.

                                  AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?

                                  It all runs locally. You just set up a cron job and it can email out the results.

                                  Ah, so it monitors the local server. No way to monitor other servers?

                                  stacksofplatesS 1 Reply Last reply Reply Quote 0
                                  • stacksofplatesS
                                    stacksofplates @IRJ
                                    last edited by

                                    @IRJ said in Testing Ransomware:

                                    @stacksofplates said in Testing Ransomware:

                                    @IRJ said in Testing Ransomware:

                                    @stacksofplates said in Testing Ransomware:

                                    @IRJ said in Testing Ransomware:

                                    @stacksofplates said in Testing Ransomware:

                                    @IRJ said in Testing Ransomware:

                                    @stacksofplates said in Testing Ransomware:

                                    @IRJ said in Testing Ransomware:

                                    How do are you guys testing Ransomware?

                                    I have some rules set up in IDS to shut a system down if it were to get infected. However I am not sure how I can test if this works without creating a major threat on our network.

                                    Can you replicate on a standalone system? Just two VMs, one for the IDS and the other for the ransomware?

                                    That is kind of what I was thinking. I may need to talk to AV support to find out how I can do that for testing.

                                    Ya. Buy a junk drive and just trash it when you're done if you're really concerned. Or just use an old junk drive and trash it.

                                    I saw on your other post, you use AIDE. Would that help detect ransomware, or would it be too late by then?

                                    I think it would be too late. You take a "snapshot" of a good config and it makes a database. Then when you run the check it compares the database to the actual files on your system. It's more for systems that don't change at all, like our workstations and hypervisors.

                                    AlienVault has an agent that checks file integrity and registry changes. Unfortunately you have to deploy an agent. How does the file check on AIDE work for networked systems? Do they need some type of agent?

                                    It all runs locally. You just set up a cron job and it can email out the results.

                                    Ah, so it monitors the local server. No way to monitor other servers?

                                    No. It's just a local service. I mean you could mount directories and such from other systems, but it's just as easy to have it configure during the post install and then start checking on each system.

                                    1 Reply Last reply Reply Quote 1
                                    • S
                                      Shuey
                                      last edited by

                                      "RanSim"

                                      1 Reply Last reply Reply Quote 1
                                      • AmbarishrhA
                                        Ambarishrh
                                        last edited by

                                        I posted about this recently
                                        https://www.mangolassi.it/topic/11225/ransim-ransomware-simulator

                                        S 1 Reply Last reply Reply Quote 0
                                        • S
                                          Shuey @Ambarishrh
                                          last edited by

                                          @Ambarishrh said in Testing Ransomware:

                                          I posted about this recently
                                          https://www.mangolassi.it/topic/11225/ransim-ransomware-simulator

                                          Right, which is the same thing I just posted above you 😛

                                          1 Reply Last reply Reply Quote 0
                                          • AmbarishrhA
                                            Ambarishrh
                                            last edited by

                                            😄

                                            1 Reply Last reply Reply Quote 0
                                            • 1 / 1
                                            • First post
                                              Last post