Ransomware is one of the most significant security threats that businesses face, as it can cause serious damage and financial losses.
User behavior specialist Exabeamhas launched Analytics for Ransomware, a new application designed for early detection across the entire enterprise network. Unlike other security products, Exabeam can detect ransomware traffic and activity across network services, servers, workstations, BYOD devices and cloud services.
Exabeam uses the latest technology to detect ransomware as it first enters the network and begins to spread. These include both behavioral analysis and file analysis. In addition, it can detect new ransomware through machine learning and identify anomalies associated with a ransomware infection.
It is also able to detect known ransomware through specific indicators. Known ransomware processes use certain file extensions and have known patterns or other indicators that are considered threats. The Exabeam Threat Research Team verifies these indicators and applies them to the product.
By examining machine logs, Exabeam can detect ransomware operating on endpoints, in the data center, or in cloud-based storage services. For example, an employee may access corporate files through a cloud sharing service from home, using their personal device, and in the process, allow the ransomware to begin encrypting the cloud files. Other employees accessing the same corporate files provide the malware with a path to begin moving throughout the corporate network. Exabeam can detect this activity, but it is too early to be disruptive.
Exabeam Analytics for Ransomware is available as either a physical appliance or a virtual machine. It can be deployed and start protecting systems quickly, and existing Exabeam customers can upgrade their systems to gain these new capabilities. More information is available on the company’s website.

