Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Is "assume the attacker has admin, make the files immutable" a useful ransomware defense, or does backup already cover this?

0
Medium
Published: 08/15/2026 (08/15/2026, 10:07:56 UTC)
Source: Reddit Cybersecurity

Description

This content discusses a proposed ransomware defense approach that assumes an attacker has local administrative privileges and enforces immutability on files at the kernel level to prevent modification or deletion. The author built a kernel-level filter driver enforcing Write Once Read Many (WORM) semantics on a mapped drive, tested it against a ransomware sample, and observed that files on the protected drive remained unchanged. The discussion questions whether this approach adds value beyond good backups and considers operational challenges. No exploit or vulnerability is reported; rather, it is a conceptual defense technique shared for community feedback.

Reddit Discussion

r/cybersecurity·posted by u/ntsyscall
00

I've been building a kernel-level filter driver that enforces WORM semantics

on a mapped drive — existing files can't be modified or deleted regardless of

the caller's privilege level. No detection, no signatures. The premise is that

detection has already failed and the attacker has local admin, which is the

state most real ransomware reaches before it encrypts anything.

Tested against a live AvosLocker sample in an isolated VM with no AV: files

outside the protected drive were encrypted, files inside came through with

matching hashes.

What I actually want to know is whether the idea is worth pursuing:

- Does an immutable-at-the-kernel layer add anything over good backups?

- Would you deploy something like this, or is the operational cost of

"some files can never be changed" too high in practice?

- What breaks this that I'm not seeing?

Video if it helps: https://www.youtube.com/watch?v=RgzEtQrlI9s

Not selling anything — no EV cert yet, so I can't ship even if I wanted to.

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 10:26:08 UTC

Technical Analysis

The post describes a kernel-level filter driver designed to enforce immutability on files within a mapped drive, preventing modification or deletion regardless of privilege level, including local admin. This approach targets ransomware scenarios where the attacker has already gained administrative access. The author tested the driver against a live AvosLocker ransomware sample in an isolated environment, finding that files on the protected drive were not encrypted. The post solicits community input on the practicality and value of this defense compared to traditional backup strategies and operational trade-offs. No specific vulnerability or exploit is detailed.

Potential Impact

No direct impact or vulnerability is described. The content is a discussion of a potential defensive technique against ransomware. The impact is conceptual, suggesting that enforcing file immutability at the kernel level could prevent ransomware from encrypting protected files even if the attacker has admin rights. However, no operational or security risks of this approach are detailed.

Defensive Guidance

This is not a vulnerability or exploit but a proposed defense mechanism. No official patch or remediation applies. The author is seeking feedback on the approach's usefulness and operational feasibility. Organizations should continue to rely on established ransomware defenses such as reliable backups and tested recovery procedures. Consideration of kernel-level immutability controls could be explored as a supplementary measure but requires thorough evaluation before deployment.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":30,"reasons":["external_link","newsworthy_keywords:ransomware","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["ransomware"],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a803ebcbf8831d539eab741

Added to database: 08/15/2026, 10:26:04 UTC

Last enriched: 08/15/2026, 10:26:08 UTC

Last updated: 08/15/2026, 16:41:05 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses