objective-see / RansomWhere

Generic ransomware detector
GNU General Public License v3.0
74 stars 15 forks source link

Still Useful? #1

Open chrisspiegl opened 3 years ago

chrisspiegl commented 3 years ago

Hello, I am wondering if everything is still good with this program and if it is still useful and working as expected on newest versions (macOS Big Sur). I am on Intel but may be also interesting to know if it works on M1 mac machines?

I have it installed and it is running, but I do not have the technical knowledge to verify if it actually is doing as it is expected.

Thank you for developing these tools like LuLu and more 🌸.

axeII commented 3 years ago

Hey @chrisspiegl 👋🏻 I can confirm that on M1 machine it works well via Rosetta 2. I would love native support for arm. But that is another issue.

JayBrown commented 2 years ago

It's occasionally pretty resource-intensive (still on Intel), so an update would be most welcome.

huyz commented 1 year ago

I think it uses a lot of CPU over time. I really wish it would be released for ARM.

JayBrown commented 10 months ago

It's still useful… @objective-see wrote in April 2023:

And though "RansomWhere?" is a bit dated, it appears to be able to generically detect this LockBit sample… even though it had no a priori knowledge of this malware

https://objective-see.org/blog/blog_0x75.html