Heimdal Ransomware Encryption Protection

Detects and blocks ransomware encryption and file-tampering activity.

Relevant where Windows recovery copies and Microsoft 365 workspaces need protection from ransomware encryption and file tampering.

Block ransomware encryption and file tampering

Ransomware commonly encrypts files while attempting to interfere with recovery copies, leaving IT teams with fewer options for restoring affected data. File reads, writes, renames and deletions can indicate that encryption or tampering is under way.

Heimdal Ransomware Encryption Protection monitors these operations through encryption, rename, shadow copy and canary engines. It blocks detected ransomware activity before encryption completes and blocks attempts to alter or delete Windows Volume Shadow Copies and recovery tools.

Where Heimdal Ransomware Encryption Protection is used

The module is suited to monitoring file activity on Windows systems, protecting Volume Shadow Copies from ransomware interference, and using canary files in targeted locations to identify file tampering. It also monitors modifications, extensions and read/write operations in supported Microsoft 365, SharePoint, OneDrive and Teams workspaces. Dashboards and reporting provide a record of ransomware activity for review.

Fits within these solutions

Ransomware Protection
Endpoint Protection
File Activity Monitoring

Suitable environments

Heimdal Ransomware Encryption Protection is applicable in on-premises and cloud environments. Its scope includes Windows systems that use Volume Shadow Copies, plus supported Microsoft 365, SharePoint, OneDrive and Teams workspaces.

Benefits

Limit File Encryption

Blocking detected activity before encryption completes helps limit ransomware damage to files.

Protect Recovery Copies

Protection against shadow-copy interference helps preserve Windows recovery options.

Identify Tampering Early

Canary and rename detection identifies suspicious file tampering in targeted locations.

Review Ransomware Activity

Dashboards and reports provide visibility of detected ransomware activity for review.

Capabilities

File Operation Monitoring

Monitors file reads, writes, renames and deletions for suspicious encryption patterns.

Multi-Engine Detection

Uses encryption, rename, shadow copy and canary engines to detect ransomware activity.

Ransomware Activity Blocking

Blocks detected ransomware activity before file encryption completes.

Canary File Detection

Uses canary files in targeted locations to identify file-tampering activity.

Shadow Copy Protection

Blocks attempts to delete or alter Windows Volume Shadow Copies and recovery tools.

Cloud Workspace Monitoring

Monitors file modifications, extensions and read/write operations in supported cloud workspaces.

Ransomware Activity Reporting

Provides reporting and dashboards on detected ransomware activity.

Common Use Cases

Windows Recovery Protection

Protect Windows Volume Shadow Copies and recovery tools from ransomware tampering.

Microsoft 365 Monitoring

Monitor file activity in supported Microsoft 365, SharePoint, OneDrive and Teams workspaces.

Targeted Canary Monitoring

Place canary files in targeted locations to identify file-tampering activity.

Ransomware Activity Review

Use reporting and dashboards to review detected ransomware activity.

How we help

Armstrong discusses ransomware protection requirements with customer IT teams, including relevant Windows systems, cloud workspaces and reporting needs, then recommends whether Heimdal Ransomware Encryption Protection is suitable for the required scope.

Part of (depending on licence)

Resources

How would you like to proceed?