Encryption is the last act, not the first
A modern ransomware attack unfolds over a kill chain: initial access through a stolen credential or exposed service, then reconnaissance, lateral movement, privilege escalation, data exfiltration, and finally encryption. Often days pass between the first foothold and the first encrypted file. By the time encryption starts, the attacker already owns the environment — detecting it then is detecting a fire that's already spread.
The opportunity is earlier, in that quiet middle, where the attacker is behaving abnormally but hasn't yet triggered the obvious alarm.
The signals that appear before encryption
- Credential abuse: a valid account suddenly reaching systems it never touches, or logging in at odd hours.
- Lateral movement: unusual internal connections — one host probing many, or east-west traffic that doesn't fit the baseline.
- Reconnaissance: scanning of shares and directories, especially near backup systems.
- Deception triggers: any interaction with a decoy file or lure — a near-certain sign of an intruder.
- Data staging and exfiltration: large or unusual outbound transfers.
Why signatures miss the early window
Much of this activity uses legitimate tools and valid credentials — 'living off the land' — so there's no malware signature to match. The tell isn't what the attacker runs; it's how they behave. Catching it requires behavioral baselining, network visibility, and deception, not just a library of known-bad indicators.
How Immune catches the quiet phase
Immune is built to defend the pre-encryption window. Continuous access verification flags credentials behaving abnormally; network monitoring surfaces the lateral movement and reconnaissance that precede encryption; and deception traps generate a high-confidence alarm the instant an attacker touches a decoy. Fused together, these let Immune raise the alarm and begin containment during the quiet middle — before encryption spreads across a hospital network, when there's still time to stop it cleanly.
Sources
Figures are drawn from the cited sources and were current as of publication. Content was rephrased for compliance with source licensing.
