logo

Ransomware in the honeypot: how we capture keys with sticky canary files

ID: b8b960bb-bc1b-559b-91a9-c06ef0e22e09

STIX ID: report--b8b960bb-bc1b-559b-91a9-c06ef0e22e09

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2024-02-23

Date Updated: 2026-04-27

...
...

Elastic's ON Week research extends its Endpoint canary ransomware protection to synchronously generate process memory dumps of suspected ransomware, storing them securely for DFIR teams; the report demonstrates recovering NOTPETYA's AES session key from a dump and predicting WANNACRY's per-file AES keys via emulation of the PRNG (with CPU-affinity mitigation), providing a practical method to decrypt files and improve forensic response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.