Ransomware Detection Pack
64 detection rules targeting the full ransomware kill chain — from initial access and lateral movement through backup deletion and encryption initiation. Stop ransomware before files are lost, not after.
Pack summary
- Detection rules
- 64
- Critical severity
- 24
- Kill chain coverage
- All stages
- ATT&CK techniques
- 22
What's included
64 rules across the full ransomware kill chain — from precursors to encryption impact.
Shadow copy deletion, backup vault tampering, S3 object mass deletion, snapshot removal.
SMB spray, RDP brute force, DCSync, scheduled task persistence, credential dumping.
MFA bypass, phishing indicators, exploit of public-facing applications, C2 IOC matches.
Mass file rename, SharePoint/OneDrive bulk modification, ransomware note creation.
Defender disabling, backup agent uninstallation, log clearing, AMSI bypass.
Detection rules (20 of 64 shown)
Showing 20 representative rules. All 64 rules activate with one click.
| Rule name | Severity |
|---|---|
| Endpoint Detection — Mass File Rename with Encryption Extension | Critical |
| AWS S3 — Mass Object Deletion (No Versioning) | Critical |
| Azure Backup Vault Soft Delete Disabled | Critical |
| GCP — Snapshot Deletion Across Multiple Projects | Critical |
| Okta / Entra ID — MFA Bypass Followed by Mass File Access | Critical |
| AWS Backup Vault Access Policy Modified to Allow Deletion | Critical |
| Active Directory — KRBTGT Hash Reset (DCSync Precursor) | Critical |
| Lateral Movement — SMB Spray to Multiple Hosts | Critical |
| Volume Shadow Copy Deletion | Critical |
| Windows Defender Tampered — Real-Time Protection Disabled | Critical |
| Ransomware IOC — Known C2 Domain or IP in DNS / Network Log | Critical |
| SharePoint / OneDrive — Mass File Encryption Pattern | Critical |
| Backup Agent Uninstalled or Service Stopped | High |
| Remote Desktop — Successful Login After Multiple Failures (Brute Force) | High |
| PowerShell — Download Cradle Executing Encoded Command | High |
| Network Scan — Internal Reconnaissance Across /16 Subnet | High |
| Ransomware Note File Created (README.txt, RESTORE_FILES.txt) | Critical |
| AWS — EC2 Instance Terminate All in Region | Critical |
| Domain Admin Account Created Outside Provisioning | High |
| Scheduled Task Created to Execute Payload at Boot | High |
Prerequisites
- Endpoint Detection and Response (CrowdStrike, SentinelOne, Microsoft Defender) connected for endpoint-layer rules
- Cloud audit logs (AWS CloudTrail, Azure Activity Log, GCP Audit) enabled for cloud-native ransomware detection
- Identity provider (Okta or Entra ID) connected for identity-layer initial access detection
- Threat intelligence integration (Recorded Future or MISP) for ransomware C2 IOC matching
Ransomware Detection Pack: frequently asked questions
What makes this a ransomware-specific detection pack versus general endpoint security?
The ransomware detection pack combines pre-encryption precursor detection (backup deletion, shadow copy removal, lateral movement) with encryption-phase detection (mass file rename, M365 bulk modification) and cloud-layer detection (S3 mass deletion, Azure backup vault tampering). Most endpoint security products detect only the encryption phase. ManySignal's cross-layer correlation detects the attack chain earlier.
Can ManySignal detect ransomware before files are encrypted?
Yes — this is the primary value of the ransomware pack. The most actionable detections are precursor events: backup vault soft-delete being disabled (T1490), Volume Shadow Copy deletion, mass lateral movement via SMB, and C2 domain contact. These events occur minutes to hours before encryption begins. Detecting them enables intervention before data is lost.
Does this pack cover cloud-native ransomware (targeting S3 and Azure Storage)?
Yes. Cloud-native ransomware attacks encrypt or delete cloud storage objects rather than local files. The pack includes specific rules for S3 mass object deletion, Azure Blob mass overwrite, and GCP snapshot deletion — all patterns consistent with cloud ransomware (such as the Scattered Spider attacks on cloud infrastructure).
How does ManySignal correlate ransomware signals across identity and endpoint?
A ransomware attack typically starts with identity compromise (MFA bypass, brute force success) before moving to endpoint execution and backup deletion. ManySignal's investigation timeline links the initial identity event with subsequent endpoint and cloud events into a single correlated incident — giving responders full attack chain visibility in one view.
What automated response actions can ManySignal take on ransomware detection?
ManySignal can trigger automated response actions via integrated platforms: suspend Okta or Entra ID user sessions, isolate endpoints via CrowdStrike or SentinelOne, block network communications via Cloudflare, and create high-priority JIRA or ServiceNow incidents. Automated containment before human review is configurable per rule severity.
Detect ransomware precursors before encryption begins
64 detection rules across endpoint, identity, cloud, and SaaS — correlating the full ransomware kill chain from initial access through backup destruction.