Ransomware Recovery at the Filesystem Layer

https://hackernoon.imgix.net/images/jglaKPRQx4TSvDvi27igdEZpRMJ3-uj83dhb.jpeg

In the last piece I wrote about closing the gap between "attacker gets in" and "attacker detonates" — using a kernel-level access record to see anomalous behavior in real time, and an append-only archive to shrink what's even reachable for a mass-encryption routine to find. That piece was about prevention and detection.

This one is about the morning after. Because even with good detection, something eventually gets encrypted, deleted, or corrupted — a hot-tier file, a misconfigured share, a process that slipped past the anomaly threshold before it was throttled. And when that happens, the thing that actually determines how bad your day is isn't your defenses. It's your recovery process, and specifically, how long it takes.

That number gets far less attention than it deserves.

Two Numbers, One of Which Everyone Ignores

Disaster recovery planning usually centers on Recovery Point Objective (RPO) — how much data you can afford...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more