So, what does ransomware do?


I bought BD last month and today tried the Ransomware module.  I added a directory and rebooted.  Nothing has changed; shouldn't it be doing something?  Isn't it supposed to alert me when I try to delete a file from the protected directory?  It doesn't.  What does do?  How can I test it?

Comments


  • Hello,


     


    The ransomware module prevents changes to the protected files from unsigned/unknown applications.


    Should you ever get infected with a 0 day ransomware the module will prevent it from encrypting your files.


  • Is there anyway to tell it is working?  I expected something to change when I protected directories. but nothing seems to happen.


  • Hello,


     


    Have a unsigned application attempt to edit those files, access will be restricted.


    Sadly one doesn't come to mind as most consumer applications have been signed.