SG-093: Ransomware

Severity: CRITICAL

Encrypt-then-extort: recovery/shadow-copy destruction, ransom-note language, mass rename to ransomware extensions, or crypto-encryption co-located with destruction of the originals.

Fires when

Remediation

No safe remediation: a file that triggers this rule should be rejected, not patched. Read the flagged lines in the source before deciding.

Research