# How do the Endpoint preventions work?

**URL:** <https://discuss.elastic.co/t/how-do-the-endpoint-preventions-work/310179>\
**Category:** Endpoint Security\
**Created:** [July 20, 2022, 4:18pm UTC](https://discuss.elastic.co/t/how-do-the-endpoint-preventions-work/310179 "2022-07-20T16:18:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tmahany419](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tmahany419/32/102898_2.png) [@tmahany419](https://discuss.elastic.co/u/tmahany419)\
**Post date:** [July 20, 2022, 4:18pm UTC](https://discuss.elastic.co/t/how-do-the-endpoint-preventions-work/310179/1 "2022-07-20T16:18:11Z")

</div>

On this page under the policies:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fb90d19e2f53e69114c38bafc921d292216d4927.png)

If click the link to "related detection rules" it just shows all the elastic rules. How do I know which rules will prevent traffic because it is ransomeware?

---

<div class="post-metadata">

**Author:** ![mager](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mager/32/108879_2.png) [@mager](https://discuss.elastic.co/u/mager)\
**Post date:** [July 26, 2022, 8:34pm UTC](https://discuss.elastic.co/t/how-do-the-endpoint-preventions-work/310179/2 "2022-07-26T20:34:34Z")

</div>

Our behavioral ransomware protection feature is fully enabled in Prevent mode according to the policy configuration you provided. Processes on your endpoints which exhibit anomalous file modification behavior will be alerted on and terminated.

The "related detection rules" towards the bottom of the UI screenshot refers to a [prebuilt rule](https://github.com/elastic/detection-rules/blob/9cc342dab7427751e200ef346b51976d5f2266c8/rules/promotions/endgame_ransomware_prevented.toml) we have in place for further promoting awareness for our users when ransomware alerts are generated. In addition to this rule, we have several other rules in place which offer more granular methods for alerting on activity that may be related to ransomware attacks such as [volume shadow copy deletion](https://github.com/elastic/detection-rules/blob/1276f98a70475042b2c8fc0e3dc04f60b54f42ce/rules/windows/impact_volume_shadow_copy_deletion_via_powershell.toml) and [boot configuration modification](https://github.com/elastic/detection-rules/blob/1276f98a70475042b2c8fc0e3dc04f60b54f42ce/rules/windows/impact_modification_of_boot_config.toml).

---

<div class="post-metadata">

**Author:** ![tmahany419](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tmahany419/32/102898_2.png) [@tmahany419](https://discuss.elastic.co/u/tmahany419)\
**Post date:** [July 27, 2022, 12:49pm UTC](https://discuss.elastic.co/t/how-do-the-endpoint-preventions-work/310179/3 "2022-07-27T12:49:12Z")

</div>

Thanks for the clarification.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2022, 12:50pm UTC](https://discuss.elastic.co/t/how-do-the-endpoint-preventions-work/310179/4 "2022-08-24T12:50:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
