Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 4.4.0

Ransomware Snapshot and Lockout Response

Scenario

A ransomware attack encrypts critical business data, making it inaccessible.

Implementation

Configure automated snapshot capabilities so the system takes snapshots of affected data upon detection. Configure automated user lockout so the system blocks the user exhibiting suspicious behavior.

Outcome

Upon detection of ransomware activity, the system starts taking snapshots and locks out the affected user account, providing more time for the team to investigate what happened. The storage admin can then restore data from the most recent snapshot, minimizing data loss and reducing downtime.

See Also

  • Snapshot Settings — How snapshots are taken during a detection event and how to manage the snapshot quota.
  • Lockout Settings — How SMB and NFS lockout work on VAST and Qumulo.
  • Active Auditor — Configure the triggers and thresholds that drive detection and response.
  • False Positive Management — Use Monitor Only or Learned Thresholds to avoid triggering lockout on known-safe activity.
  • Restore User Access — Reverse a lockout once investigation confirms it's safe to do so.