Ransomware Detection With Windows Minifilter by Intercepting File Filter and Change Events
ID: b054eacf-a902-596b-9635-ffa45c1a2a90
STIX ID: report--b054eacf-a902-596b-9635-ffa45c1a2a90
Feed Name: cybersecurityNews.com
Threat Score
Security researcher 0xflux published a proof-of-concept Windows minifilter driver (Sanctum/fs_minifilter) that monitors filesystem I/O to detect ransomware behaviors—rapid file writes, renames to LockBit-like extensions, and high-entropy changes—logging process context and alerting a user-mode engine; the report includes a Rust simulator, implementation details, and suggested enhancements for integration with behavioral EDR solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
