elastic / security-docs

Elastic Security Documentation
Other
67 stars 179 forks source link

Ransomware protection[DOCS] #533

Closed caitlinbetz closed 3 years ago

caitlinbetz commented 3 years ago

Description

OLM team issue: https://github.com/elastic/security-team/issues/515

Behavioral ransomware prevention on the Elastic Agent detects and stops ransomware attacks on Windows systems by analyzing data from low-level system processes, and is effective across an array of widespread ransomware families — including those targeting the system’s master boot record.

Ransomware protection for Windows can be toggled on or off via the Endpoint integration policy. Users can set the protection level to Detect or Prevent. Default configuration is Prevent ON, Notify User ON. User notification can be customized in the same way as the Malware notification. This is a licensed feature - available for Platinum licenses and above (Platinum, Enterprise).

Acceptance Test Criteria

Notes

Ransomware view - Platinum, Enterprise image

Ransomware view - Basic, Gold image

jmikell821 commented 3 years ago

Merged #559 and #567.