logo

Deception Engineering: exploring the use of Windows Service Canaries against ransomware

ID: 63169730-761d-5649-b1d8-bf86a802697a

STIX ID: report--63169730-761d-5649-b1d8-bf86a802697a

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2025-03-10

Date Updated: 2026-08-02

...
...

This report describes a prototype defensive technique—'Killed Process Canary'—designed to detect Ryuk-style ransomware activity that terminates Windows services prior to encryption; multiple disguised Windows services share a counter, trigger a DNS canary token when stopped, and hibernate the host to limit impact. The write-up covers Ryuk TTPs motivating the approach, implementation details, how DNS tokens encode host identity for alerting, and caveats about unknown real-world effectiveness and possible attacker countermeasures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.