Anti-ransomware protection in Fall Creators Update

Page 4 of 4 FirstFirst ... 234

  1. Posts : 5,452
    Windows 11 Home
       #31

    When you want anti-ransomware protection, deny access to Users and SYSTEM to any backup folder. Tested on wannacry.
    Users, obviously and SYSTEM, because ransomware usually gains system rights, not admin, so it is very easy to avoid.
    Windows method works by denying access to every software except allowed, it is better to just deny access to all.
    Attached Thumbnails Attached Thumbnails Anti-ransomware protection in  Fall Creators Update-capture_07302017_205032.jpg  
      My Computer


  2. Posts : 5,478
    2004
       #32

    TairikuOkami said:
    When you want anti-ransomware protection, deny access to Users and SYSTEM to any backup folder.
    Probably you should deny Trusted Installer as well. Any Administrator process can do what it wants though so if you run as part of Administrator group there is no point restricting anything really.
      My Computer


  3. Posts : 5,452
    Windows 11 Home
       #33

    Trusted Installer and Administrators, are very unlikely to be used by ransomware. Ransomware uses SeTcbPrivilege, which gives it SYSTEM rights, that is more elevated than admins, so when blocked, admins can have access, but SYSTEM not.
      My Computer


  4. Posts : 5,478
    2004
       #34

    Oh come on you (or any malware) can use this Launch processes with TrustedInstaller privilege

    If you don't run under a standard account you only have yourself to blame.
      My Computer


  5. Posts : 5,452
    Windows 11 Home
       #35

    lx07 said:
    Oh come on you (or any malware) can use this Launch processes with TrustedInstaller privilege
    Hackers might, but malware is generally dumb.
    Petya, Wannacry, Badrabbit, all use SeTcbPrivilege.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:00.
Find Us




Windows 10 Forums