Guide · 7 min read

The signals that precede a ransomware incident

Encryption is the last stage of a ransomware attack, not the first. The days or weeks before it are noisy, and that noise is detectable.

Encryption is the end of the attack, not the beginning

The most damaging misconception about ransomware is that it happens suddenly. In reality, encryption is the final action, taken once the attacker has already achieved everything else: access, escalation, spread, and the removal of your ability to recover without paying.

The period before encryption is typically days and sometimes weeks. It is also comparatively noisy, because the attacker is doing unfamiliar things on an unfamiliar network. That window is where detection is worth having.

Stage one: initial access

Entry is usually unremarkable: a phished credential, an exposed remote access service, or an unpatched internet-facing system. At this point activity looks like a legitimate login, which is precisely why prevention alone is unreliable.

  • Successful authentication from an unusual location, device or time of day.
  • A single account authenticating from two distant locations within an implausible interval.
  • Access to remote services from addresses with no prior history.
  • Exploitation attempts against internet-facing services immediately preceding a successful login.

Stage two: reconnaissance

Having gained access, the attacker must work out where they are. They enumerate the domain, look for file shares, identify backup infrastructure and locate the systems that matter. A legitimate user does not do this, which makes it high-signal activity.

  • Domain and directory enumeration from a workstation that has never done it before.
  • Network and share scanning from an internal host.
  • Unusual queries against directory services.
  • Access to systems the account has rights to but has never touched.
  • Interaction with decoy systems, which no legitimate process should ever contact.

Stage three: credential access and escalation

A single user account is rarely sufficient. The attacker needs administrative rights, and obtaining them produces some of the most reliable detections available.

  • Credential dumping and access to process memory associated with authentication.
  • New accounts appearing, or existing accounts added to privileged groups.
  • Service accounts authenticating interactively when they normally do not.
  • Administrative tooling appearing on hosts that have no reason to run it.

Stage four: staging and recovery denial

Before encrypting, competent operators remove your alternatives. They locate and destroy backups, disable security tooling, and frequently exfiltrate data first so they retain leverage even if you can restore.

  • Backup systems accessed, altered or deleted - often the last clear warning.
  • Security agents stopped, uninstalled, or exclusions added.
  • Volume shadow copies deleted.
  • Large outbound transfers to file-sharing or cloud storage services, frequently outside business hours.
  • Deployment tooling used to distribute a payload across many hosts at once.

Why this is a monitoring problem

Every signal above is recorded somewhere by systems most organisations already run. The failure is almost never that the evidence did not exist. It is that nobody was collecting it, correlating it, or looking at it.

It is also why detecting agents being stopped matters so much. An attacker disabling your security tooling is one of the clearest indicators available - but only if something notices that the tool went quiet. A monitoring platform that treats silence as good news will miss the most important alert of the entire intrusion.

Get started

Find out what is actually happening on your network

A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.