# Ransomware protection

**URL:** <https://discuss.elastic.co/t/ransomware-protection/360948>\
**Category:** Elastic Security\
**Created:** [June 6, 2024, 10:05am UTC](https://discuss.elastic.co/t/ransomware-protection/360948 "2024-06-06T10:05:29Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [June 6, 2024, 10:05am UTC](https://discuss.elastic.co/t/ransomware-protection/360948/1 "2024-06-06T10:05:29Z")

</div>

Hi

What is "Anti-Ransomware Elastic-Do-Not-Touch" appearing on the folders machines

---

<div class="post-metadata">

**Author:** ![Samir\_Bousseaden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samir_bousseaden/32/135089_2.png) [@Samir\_Bousseaden](https://discuss.elastic.co/u/Samir_Bousseaden)\
**Post date:** [June 6, 2024, 11:58am UTC](https://discuss.elastic.co/t/ransomware-protection/360948/2 "2024-06-06T11:58:51Z")

</div>

Hi Charles those folders are used by the [Elastic Defend Ransomware Canaries Detection](https://www.elastic.co/guide/en/security/current/configure-endpoint-integration-policy.html#ransomware-protection) :

_When ransomware protection is enabled, canary files placed in targeted locations on your hosts provide an early warning system for potential ransomware activity. When a canary file is modified, Elastic Defend immediately generates a ransomware alert. If **prevent** ransomware is active, Elastic Defend terminates the process that modified the file._

they will appear to the user if the [Show hidden items](https://support.microsoft.com/en-gb/windows/show-hidden-files-0320fe58-0117-fd59-6851-9b7f9840fdb2#:~:text=Select%20the%20Start%20button%2C%20then,drives%2C%20and%20then%20select%20OK.) is enabled :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c97858e1ee27fb927fff4440df3c9dfe20ad31fd.jpeg)

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [June 6, 2024, 12:28pm UTC](https://discuss.elastic.co/t/ransomware-protection/360948/3 "2024-06-06T12:28:02Z")

</div>

Hi @Samir_Bousseaden Thanks just what i have thought... is it possible to hide this from the users??

---

<div class="post-metadata">

**Author:** ![Samir\_Bousseaden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samir_bousseaden/32/135089_2.png) [@Samir\_Bousseaden](https://discuss.elastic.co/u/Samir_Bousseaden)\
**Post date:** [June 6, 2024, 1:20pm UTC](https://discuss.elastic.co/t/ransomware-protection/360948/4 "2024-06-06T13:20:57Z")

</div>

it's possible to do that locally or via GPO, example of how to disable `showing hidden files` via GPO [Using Group Policy to Disable Show Hidden Files](https://blog.canauri.com/using-group-policy-to-disable-show-hidden-files) and locally [Show hidden files - Microsoft Support](https://support.microsoft.com/en-gb/windows/show-hidden-files-0320fe58-0117-fd59-6851-9b7f9840fdb2)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/3/a32e034a12c64aa7cd74641784e1771c5e6f719f.jpeg)

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [June 6, 2024, 2:07pm UTC](https://discuss.elastic.co/t/ransomware-protection/360948/5 "2024-06-06T14:07:32Z")

</div>

Thank you!!. i thought there's a way you can do it via the console under Policy Configs

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [June 7, 2024, 5:43am UTC](https://discuss.elastic.co/t/ransomware-protection/360948/6 "2024-06-07T05:43:30Z")

</div>

@Samir_Bousseaden i know this is Separate discussion just wanted to ask if there's possible to run a query that can only show me XDR alerts from the alerts tab console ?

---

<div class="post-metadata">

**Author:** ![Samir\_Bousseaden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samir_bousseaden/32/135089_2.png) [@Samir\_Bousseaden](https://discuss.elastic.co/u/Samir_Bousseaden)\
**Post date:** [June 9, 2024, 8:15pm UTC](https://discuss.elastic.co/t/ransomware-protection/360948/7 "2024-06-09T20:15:10Z")

</div>

If I understood correctly you can use this search `event.dataset :"endpoint.alerts"` , if you want only alerts for specific features like ransomware you can add `event.code:ransomware` or `event.code:behavior` for behavior or `event.code:malicious_file` for malware alerts or `event.code:shellcode_thread` for shellcode related alerts :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3de6a8d9378b64da7481ef0f2489d9bd05b9a571.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2024, 8:15pm UTC](https://discuss.elastic.co/t/ransomware-protection/360948/8 "2024-07-07T20:15:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
