Endpoint Detection
Host-level detection that catches encryption as it begins
Some of the clearest evidence of ransomware appears on the host itself — in the sudden storm of file changes and the spike in randomness that mass encryption produces. Immune watches for these host signals so an attack is caught in its first moments, not after the damage is done.
Immune's endpoint detection monitors file activity, process behavior, and file entropy on hosts, recognizing the signature of ransomware encryption within moments and feeding it into the platform's response loop.
What ransomware looks like from inside a host
When ransomware finally begins encrypting, it does something no legitimate application does at that scale: it opens, rewrites, and renames enormous numbers of files in a very short time. And because encrypted data is mathematically random, the entropy of those files leaps upward. To a defense watching the host, this combination — a spike in file-change rate together with a spike in entropy — is one of the most reliable signals in all of ransomware detection. It is hard for an attacker to hide, because it is a direct consequence of what encryption does.
Ransomware also tends to prepare the ground on the host before it strikes. It may try to delete the local backups and shadow copies that would let you recover, disable protective services, or establish persistence so it survives a reboot. Each of these actions is observable at the host level, and each is a strong indicator that an attack is underway. Immune's endpoint detection watches for all of them, so the earliest moves of an attack on a system become an early-warning signal rather than a discovery made after the fact.
See it in action
Host-level entropy and file-change signals surface mass encryption in its first seconds — before it can spread to other systems.

Features
What endpoint detection provides
File-entropy monitoring
Detects the rise in randomness that accompanies mass encryption, in real time.
File-change-rate analysis
Flags the rapid create/modify/rename storm that legitimate apps never produce.
Process behavior analysis
Identifies unusual processes, injection, and ransomware execution patterns.
Backup-tampering detection
Catches attempts to delete shadow copies or disable recovery — a staging hallmark.
Persistence & privilege watch
Notices changes that let an attacker survive reboots or escalate access.
Lightweight sensor
Runs with minimal CPU and memory so clinical applications are unaffected.
How it works
How endpoint detection works
Watch host activity
Immune's lightweight sensor observes file, process, and access activity on servers and workstations.
Track entropy & change rate
It continuously measures file-change rates and entropy, the direct fingerprints of encryption.
Spot the staging
Attempts to delete backups, disable services, or establish persistence are flagged as attack indicators.
Correlate with the network
Host findings are combined with network, identity, and deception signals for a complete picture.
Trigger the response
An entropy-and-file-change spike can immediately trigger containment before encryption spreads.
Advantages
The advantages of host-level detection
Catches encryption instantly
The entropy-and-change signal reveals mass encryption in its first moments.
Two vantage points
Host detection plus network detection means an attack is caught wherever it shows.
Sees the staging
Backup-deletion and persistence attempts are caught before encryption even begins.
Complete coverage
Deep host visibility where possible, network protection for devices where it isn't.
Lightweight
Minimal overhead keeps clinical systems fast and responsive.
Feeds fast containment
A host signal can trigger isolation before the attack spreads further.
Use cases
Where endpoint detection matters
Server & workstation protection
Deep host visibility on the managed estate where encryption often starts.
Encryption onset detection
Catch the entropy spike the instant bulk encryption begins.
Backup-sabotage prevention
Flag attempts to destroy shadow copies before recovery is compromised.
Persistence discovery
Spot the footholds attackers plant to survive reboots and remediation.
Common questions
Endpoint and host detection, answered
+How do you detect ransomware encryption on an endpoint?
When ransomware encrypts files, it rewrites large numbers of them very quickly and the mathematical randomness — the entropy — of those files jumps sharply. Immune watches file-change rates and entropy on hosts, so the onset of mass encryption is recognized within moments and can trigger an immediate response.
+What host signals does Immune monitor?
Immune observes file activity (creation, modification, rename, and encryption patterns), process behavior, access events, and system changes such as attempts to delete backups or shadow copies — the tell-tale actions of a ransomware attack on a host.
+Does endpoint detection replace network monitoring?
No — they are complementary. Network monitoring catches an attacker moving between systems; endpoint detection catches what happens on a system itself. Immune correlates both so an attack is visible whether it shows up on the wire or on the host.
+How much overhead does the host sensor add?
Immune's host sensor is engineered to be lightweight, running with minimal CPU and memory impact so it does not interfere with clinical applications.
+What about systems that can't run the sensor?
Servers and workstations get full host-level detection; the medical devices and legacy systems that cannot host software are covered at the network boundary instead, so nothing is left in the dark.
+Can it catch attempts to destroy backups?
Yes. Ransomware commonly tries to delete local backups and shadow copies before encrypting. Immune watches for exactly these actions and treats them as strong indicators of an attack in its staging phase.
Explore the platform
Related capabilities
Detect encryption the moment it starts
Book a demo and see how Immune reads the file and entropy signals of ransomware on the host — and stops it before it spreads.
