New Tool Uses Windows Minifilters to Detect Ransomware Attacks

New Tool Uses Windows Minifilters to Detect Ransomware Attacks

First seen 9 Feb 2026, 16:04 UTC CybersecuritynewsGbhackersCyberpress 48.3

Article Content

Browse articles
ThreatCluster

A security researcher has launched a proof-of-concept tool on GitHub aimed at preventing ransomware attacks by utilizing Windows Minifilters. This tool, part of the 'Sanctum' EDR strategy, allows for the detection and interception of malicious file encryption activities at the operating system level. Organizations are increasingly vulnerable to ransomware, which remains a leading cyber threat.

Timeline

2026-02-09
Proof-of-concept tool released on GitHub
2026-02-09
Articles published detailing ransomware detection methods