Deception Engineering: exploring the use of Windows Service Canaries against ransomware
ID: 63169730-761d-5649-b1d8-bf86a802697a
STIX ID: report--63169730-761d-5649-b1d8-bf86a802697a
Feed Name: NCC Research
This report describes a prototype defensive technique—'Killed Process Canary'—designed to detect Ryuk-style ransomware activity that terminates Windows services prior to encryption; multiple disguised Windows services share a counter, trigger a DNS canary token when stopped, and hibernate the host to limit impact. The write-up covers Ryuk TTPs motivating the approach, implementation details, how DNS tokens encode host identity for alerting, and caveats about unknown real-world effectiveness and possible attacker countermeasures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
