Defense against specialized ransomware

chicchi

Level 1
Thread author
Jul 23, 2017
9
27
26
japan
 Hi,
Many of the Ransomware do encryption processing using the existing library,
and I think that monitoring the library is an effective means.
But,
How can you detect randomware using own library?
Are there any good opinions?

Thank you.
 
Last edited:
They cant use the libraries if they can't run in the first place : use an anti-exe or SRP coupled to an anti-exploit.