Skip to content

Ransomware detection

NGBackup watches your data in real time and reacts to ransomware as it happens — not after the backup fails.

Active ransomware detection and response

A File-Daemon sentinel monitors the filesystem and flags attacks using multiple signals:

  • Shannon entropy spikes (mass encryption looks random).
  • Burst renames and suspicious extensions.
  • Altered-ratio thresholds across a tree.

When an attack is detected, NGBackup can take any of nine configurable response actions — from raising a high-priority alert and tagging the job, to pausing backups so a poisoned copy never overwrites a good one. Your clean, immutable backups survive the attack.

The same plugin includes an Incremental Accelerator that skips the File Daemon’s full tree-walk on Linux — reading the filesystem’s own change journal instead of re-scanning every file — so incrementals run up to 3× faster on large filesystems. The gain scales with your change ratio: the more files that stay unchanged between backups, the bigger the speed-up. Detection that also speeds up everyday backups.

See the Ransomware Detection plugin page for the full option list, and pair it with Immutability / WORM.