M ManySignal
Detection Pack Cross-Platform

Ransomware Detection Pack

64 detection rules targeting the full ransomware kill chain — from initial access and lateral movement through backup deletion and encryption initiation. Stop ransomware before files are lost, not after.

Pack summary

Detection rules
64
Critical severity
24
Kill chain coverage
All stages
ATT&CK techniques
22

What's included

64 rules across the full ransomware kill chain — from precursors to encryption impact.

Backup & Recovery Destruction 16 rules

Shadow copy deletion, backup vault tampering, S3 object mass deletion, snapshot removal.

Precursor & Lateral Movement 18 rules

SMB spray, RDP brute force, DCSync, scheduled task persistence, credential dumping.

Initial Access 12 rules

MFA bypass, phishing indicators, exploit of public-facing applications, C2 IOC matches.

Encryption Phase 10 rules

Mass file rename, SharePoint/OneDrive bulk modification, ransomware note creation.

Defense Evasion 8 rules

Defender disabling, backup agent uninstallation, log clearing, AMSI bypass.

Detection rules (20 of 64 shown)

Showing 20 representative rules. All 64 rules activate with one click.

Rule name Severity
Endpoint Detection — Mass File Rename with Encryption Extension Critical
AWS S3 — Mass Object Deletion (No Versioning) Critical
Azure Backup Vault Soft Delete Disabled Critical
GCP — Snapshot Deletion Across Multiple Projects Critical
Okta / Entra ID — MFA Bypass Followed by Mass File Access Critical
AWS Backup Vault Access Policy Modified to Allow Deletion Critical
Active Directory — KRBTGT Hash Reset (DCSync Precursor) Critical
Lateral Movement — SMB Spray to Multiple Hosts Critical
Volume Shadow Copy Deletion Critical
Windows Defender Tampered — Real-Time Protection Disabled Critical
Ransomware IOC — Known C2 Domain or IP in DNS / Network Log Critical
SharePoint / OneDrive — Mass File Encryption Pattern Critical
Backup Agent Uninstalled or Service Stopped High
Remote Desktop — Successful Login After Multiple Failures (Brute Force) High
PowerShell — Download Cradle Executing Encoded Command High
Network Scan — Internal Reconnaissance Across /16 Subnet High
Ransomware Note File Created (README.txt, RESTORE_FILES.txt) Critical
AWS — EC2 Instance Terminate All in Region Critical
Domain Admin Account Created Outside Provisioning High
Scheduled Task Created to Execute Payload at Boot High

Prerequisites

  • Endpoint Detection and Response (CrowdStrike, SentinelOne, Microsoft Defender) connected for endpoint-layer rules
  • Cloud audit logs (AWS CloudTrail, Azure Activity Log, GCP Audit) enabled for cloud-native ransomware detection
  • Identity provider (Okta or Entra ID) connected for identity-layer initial access detection
  • Threat intelligence integration (Recorded Future or MISP) for ransomware C2 IOC matching

Ransomware Detection Pack: frequently asked questions

What makes this a ransomware-specific detection pack versus general endpoint security?

The ransomware detection pack combines pre-encryption precursor detection (backup deletion, shadow copy removal, lateral movement) with encryption-phase detection (mass file rename, M365 bulk modification) and cloud-layer detection (S3 mass deletion, Azure backup vault tampering). Most endpoint security products detect only the encryption phase. ManySignal's cross-layer correlation detects the attack chain earlier.

Can ManySignal detect ransomware before files are encrypted?

Yes — this is the primary value of the ransomware pack. The most actionable detections are precursor events: backup vault soft-delete being disabled (T1490), Volume Shadow Copy deletion, mass lateral movement via SMB, and C2 domain contact. These events occur minutes to hours before encryption begins. Detecting them enables intervention before data is lost.

Does this pack cover cloud-native ransomware (targeting S3 and Azure Storage)?

Yes. Cloud-native ransomware attacks encrypt or delete cloud storage objects rather than local files. The pack includes specific rules for S3 mass object deletion, Azure Blob mass overwrite, and GCP snapshot deletion — all patterns consistent with cloud ransomware (such as the Scattered Spider attacks on cloud infrastructure).

How does ManySignal correlate ransomware signals across identity and endpoint?

A ransomware attack typically starts with identity compromise (MFA bypass, brute force success) before moving to endpoint execution and backup deletion. ManySignal's investigation timeline links the initial identity event with subsequent endpoint and cloud events into a single correlated incident — giving responders full attack chain visibility in one view.

What automated response actions can ManySignal take on ransomware detection?

ManySignal can trigger automated response actions via integrated platforms: suspend Okta or Entra ID user sessions, isolate endpoints via CrowdStrike or SentinelOne, block network communications via Cloudflare, and create high-priority JIRA or ServiceNow incidents. Automated containment before human review is configurable per rule severity.

Detect ransomware precursors before encryption begins

64 detection rules across endpoint, identity, cloud, and SaaS — correlating the full ransomware kill chain from initial access through backup destruction.