Immune — Self Heal, an iStudio Technologies product

Endpoint Detection

Host-level detection that catches encryption as it begins

Some of the clearest evidence of ransomware appears on the host itself — in the sudden storm of file changes and the spike in randomness that mass encryption produces. Immune watches for these host signals so an attack is caught in its first moments, not after the damage is done.

Immune's endpoint detection monitors file activity, process behavior, and file entropy on hosts, recognizing the signature of ransomware encryption within moments and feeding it into the platform's response loop.

Entropyspike detection
< 3% CPUlightweight host sensor
Host + nettwo vantage points

What ransomware looks like from inside a host

When ransomware finally begins encrypting, it does something no legitimate application does at that scale: it opens, rewrites, and renames enormous numbers of files in a very short time. And because encrypted data is mathematically random, the entropy of those files leaps upward. To a defense watching the host, this combination — a spike in file-change rate together with a spike in entropy — is one of the most reliable signals in all of ransomware detection. It is hard for an attacker to hide, because it is a direct consequence of what encryption does.

Ransomware also tends to prepare the ground on the host before it strikes. It may try to delete the local backups and shadow copies that would let you recover, disable protective services, or establish persistence so it survives a reboot. Each of these actions is observable at the host level, and each is a strong indicator that an attack is underway. Immune's endpoint detection watches for all of them, so the earliest moves of an attack on a system become an early-warning signal rather than a discovery made after the fact.

See it in action

Host-level entropy and file-change signals surface mass encryption in its first seconds — before it can spread to other systems.

app.immuneselfheal.com
Immune endpoint detection console — entropy and file-change rate analysis

Features

What endpoint detection provides

File-entropy monitoring

Detects the rise in randomness that accompanies mass encryption, in real time.

File-change-rate analysis

Flags the rapid create/modify/rename storm that legitimate apps never produce.

Process behavior analysis

Identifies unusual processes, injection, and ransomware execution patterns.

Backup-tampering detection

Catches attempts to delete shadow copies or disable recovery — a staging hallmark.

Persistence & privilege watch

Notices changes that let an attacker survive reboots or escalate access.

Lightweight sensor

Runs with minimal CPU and memory so clinical applications are unaffected.

How it works

How endpoint detection works

1

Watch host activity

Immune's lightweight sensor observes file, process, and access activity on servers and workstations.

2

Track entropy & change rate

It continuously measures file-change rates and entropy, the direct fingerprints of encryption.

3

Spot the staging

Attempts to delete backups, disable services, or establish persistence are flagged as attack indicators.

4

Correlate with the network

Host findings are combined with network, identity, and deception signals for a complete picture.

5

Trigger the response

An entropy-and-file-change spike can immediately trigger containment before encryption spreads.

Advantages

The advantages of host-level detection

Catches encryption instantly

The entropy-and-change signal reveals mass encryption in its first moments.

Two vantage points

Host detection plus network detection means an attack is caught wherever it shows.

Sees the staging

Backup-deletion and persistence attempts are caught before encryption even begins.

Complete coverage

Deep host visibility where possible, network protection for devices where it isn't.

Lightweight

Minimal overhead keeps clinical systems fast and responsive.

Feeds fast containment

A host signal can trigger isolation before the attack spreads further.

Use cases

Where endpoint detection matters

Server & workstation protection

Deep host visibility on the managed estate where encryption often starts.

Encryption onset detection

Catch the entropy spike the instant bulk encryption begins.

Backup-sabotage prevention

Flag attempts to destroy shadow copies before recovery is compromised.

Persistence discovery

Spot the footholds attackers plant to survive reboots and remediation.

Common questions

Endpoint and host detection, answered

+How do you detect ransomware encryption on an endpoint?

When ransomware encrypts files, it rewrites large numbers of them very quickly and the mathematical randomness — the entropy — of those files jumps sharply. Immune watches file-change rates and entropy on hosts, so the onset of mass encryption is recognized within moments and can trigger an immediate response.

+What host signals does Immune monitor?

Immune observes file activity (creation, modification, rename, and encryption patterns), process behavior, access events, and system changes such as attempts to delete backups or shadow copies — the tell-tale actions of a ransomware attack on a host.

+Does endpoint detection replace network monitoring?

No — they are complementary. Network monitoring catches an attacker moving between systems; endpoint detection catches what happens on a system itself. Immune correlates both so an attack is visible whether it shows up on the wire or on the host.

+How much overhead does the host sensor add?

Immune's host sensor is engineered to be lightweight, running with minimal CPU and memory impact so it does not interfere with clinical applications.

+What about systems that can't run the sensor?

Servers and workstations get full host-level detection; the medical devices and legacy systems that cannot host software are covered at the network boundary instead, so nothing is left in the dark.

+Can it catch attempts to destroy backups?

Yes. Ransomware commonly tries to delete local backups and shadow copies before encrypting. Immune watches for exactly these actions and treats them as strong indicators of an attack in its staging phase.

Detect encryption the moment it starts

Book a demo and see how Immune reads the file and entropy signals of ransomware on the host — and stops it before it spreads.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.