Ransomware in the honeypot: how we capture keys with sticky canary files
ID: b8b960bb-bc1b-559b-91a9-c06ef0e22e09
STIX ID: report--b8b960bb-bc1b-559b-91a9-c06ef0e22e09
Feed Name: Elastic Security Labs
Threat Score
Elastic's ON Week research extends its Endpoint canary ransomware protection to synchronously generate process memory dumps of suspected ransomware, storing them securely for DFIR teams; the report demonstrates recovering NOTPETYA's AES session key from a dump and predicting WANNACRY's per-file AES keys via emulation of the PRNG (with CPU-affinity mitigation), providing a practical method to decrypt files and improve forensic response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
