Elastic Security 8.11 added a ransomware-response capability that triggers a full memory dump when sticky canary files detect attempted encryption. Elastic Defend stores compressed dumps locally in the protected Endpoint cache rather than sending them to Elastic, enabling responders to preserve volatile evidence from the encrypting process. Elastic demonstrated recovery of an in-memory AES-128 session key from a captured NotPetya process dump and showed that, under constrained CPU-affinity conditions, a dumped WannaCry process's Windows PRNG state can help predict future per-file AES keys.
The capability is intended as a forensic and recovery aid rather than a universal ransomware control, since key handling and encryption behavior differ across families. Separately, Malpedia published an autogenerated YARA rule for the Windows LockBit family; it targets files below 2,049,024 bytes and requires at least seven matches from 18 sample-derived byte sequences, providing an additional static-detection option for LockBit artifacts.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Felix Bilstein's yara-signator autogenerated the "win_lockbit_auto" YARA rule to detect the LockBit Windows malware family. The rule targets files below 2,049,024 bytes and requires at least seven of 18 byte-pattern sequences to match.
Elastic reconstructed WANNACRY process memory and thread context and emulated the Windows random-number-generation workflow, correctly predicting output on a single-core system. It found that constraining the detected process to a selected CPU affinity could enable reliable prediction of future per-file AES keys on multi-core systems.
In contained testing, Elastic identified NOTPETYA's active encryption thread in a captured dump and extracted its in-memory AES-128 session key from the CryptoAPI context. Elastic concluded that the key could enable decryption of files encrypted by that ransomware process.
Elastic Defend/Elastic Security 8.11 added generation of complete local process-memory dumps when ransomware protection detects attempted encryption of a canary file. The compressed dumps are stored in the protected Endpoint cache directory and are not submitted to Elastic.
Elastic Endpoint began using canary files in version 7.14 to identify processes attempting to overwrite decoy files and trigger ransomware protection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.