Configure anomaly detection for ransomware file extensions
A typical ransomware attacks the data and encrypts it. After file encryption, it renames the files with a specific extension such as .lockbit. NetBackup detects such known ransomware extensions during backups and generates an anomaly.
Note:
In the NetBackup web UI, if you mark a file extension anomaly as a false positive, anomalies for the same file extension will not be generated in future.
To configure anomaly detection for ransomware file extensions
- Enable NetBackup to check file extensions against the ransomware file extensions list.
- Enable automatic malware scan for the file extension anomalies that are detected.
Ensure that the anomaly_config.conf configuration file contains the following option under the [AUTOMATED_MALWARE_SCAN_SETTINGS] section:
TRIGGER_SCAN_FOR_RANSOMWARE_EXT_IMAGES=1