GuardMode 2024.2
Catalogic SoftwareKnowledge BaseMySupport
  • Welcome to GuardMode!
  • Intro
  • Installation
    • System requirements
    • Installing GuardMode Agent on Windows
      • Updating GuardMode Agent on Windows
    • Installing GuardMode Agent on Linux
      • Using GuardMode Agent as a Container
    • Uninstalling GuardMode Agent on Windows
    • Uninstalling GuardMode Agent on Linux
    • Configuring GuardMode Agent for SAMBA setup
    • Uninstalling GuardMode Agent on SAMBA setup
  • Agent Configuration
    • General Settings
    • Excluded Paths Configuration
    • Adding malware detection rules
      • Honeypot and Decoy Files
      • Write Operations Threshold
      • Detecting File Renaming with Abnormal File Extensions
      • Special Files Monitoring
    • Security Incident Detection
    • SMB Monitoring (Linux Only)
    • Event Reports
      • Configuring Event Reports
      • Excluding Paths From Event Reports
      • Tagging Agent
    • NFS Share Monitoring
    • Altering Audit Rules
    • Configuring DPX for Automatic Blocklist Updates
    • Using TLS
    • Configuring YARA-X
  • Using GuardMode Agent Command Line
  • REST API Documentation
  • On-demand Scanning
  • Logging
  • FAQ
  • Found an issue?
Powered by GitBook
On this page

Intro

Since version 4.8.1, Catalogic DPX bundles the Catalogic GuardMode, which provides early detection of ransomware or data-related anomalies before you back up your data.

Integrated Ransomware Detection and Recovery

GuardMode Agent analyzes file system events to find anomalies in access patterns.

GuardMode Agent monitors filesystem activity for:

  • Ransomware-specific patterns and extensions

  • Processes that are consistently altering data on the system for longer periods

  • Rapid file renames and modifications

  • Attempts to modify decoy files

  • Files with high entropy and unreadable metadata

GuardMode ransomware protection for backups is complementary to the endpoint and edge protection, monitoring file shares and system behavior, even over the network, instead of relying on a specific binary fingerprint. GuardMode maintains and regularly updates over 5000 known ransomware threat patterns, and assesses affected files.

While ransomware detection solutions are mostly built for security teams, GuardMode is designed with the backup administrator and your backup solution in mind, with easy-to-configure detection mechanisms, and the ability to guide administrators through recovering the affected data.

PreviousWelcome to GuardMode!NextInstallation

Last updated 10 months ago