Is "assume the attacker has admin, make the files immutable" a useful ransomware defense, or does backup already cover this?
This content discusses a proposed ransomware defense approach that assumes an attacker has local administrative privileges and enforces immutability on files at the kernel level to prevent modification or deletion. The author built a kernel-level filter driver enforcing Write Once Read Many (WORM) semantics on a mapped drive, tested it against a ransomware sample, and observed that files on the protected drive remained unchanged. The discussion questions whether this approach adds value beyond good backups and considers operational challenges. No exploit or vulnerability is reported; rather, it is a conceptual defense technique shared for community feedback.
AI Analysis
Technical Summary
The post describes a kernel-level filter driver designed to enforce immutability on files within a mapped drive, preventing modification or deletion regardless of privilege level, including local admin. This approach targets ransomware scenarios where the attacker has already gained administrative access. The author tested the driver against a live AvosLocker ransomware sample in an isolated environment, finding that files on the protected drive were not encrypted. The post solicits community input on the practicality and value of this defense compared to traditional backup strategies and operational trade-offs. No specific vulnerability or exploit is detailed.
Potential Impact
No direct impact or vulnerability is described. The content is a discussion of a potential defensive technique against ransomware. The impact is conceptual, suggesting that enforcing file immutability at the kernel level could prevent ransomware from encrypting protected files even if the attacker has admin rights. However, no operational or security risks of this approach are detailed.
Mitigation Recommendations
This is not a vulnerability or exploit but a proposed defense mechanism. No official patch or remediation applies. The author is seeking feedback on the approach's usefulness and operational feasibility. Organizations should continue to rely on established ransomware defenses such as reliable backups and tested recovery procedures. Consideration of kernel-level immutability controls could be explored as a supplementary measure but requires thorough evaluation before deployment.
Is "assume the attacker has admin, make the files immutable" a useful ransomware defense, or does backup already cover this?
Description
This content discusses a proposed ransomware defense approach that assumes an attacker has local administrative privileges and enforces immutability on files at the kernel level to prevent modification or deletion. The author built a kernel-level filter driver enforcing Write Once Read Many (WORM) semantics on a mapped drive, tested it against a ransomware sample, and observed that files on the protected drive remained unchanged. The discussion questions whether this approach adds value beyond good backups and considers operational challenges. No exploit or vulnerability is reported; rather, it is a conceptual defense technique shared for community feedback.
Reddit Discussion
I've been building a kernel-level filter driver that enforces WORM semantics
on a mapped drive — existing files can't be modified or deleted regardless of
the caller's privilege level. No detection, no signatures. The premise is that
detection has already failed and the attacker has local admin, which is the
state most real ransomware reaches before it encrypts anything.
Tested against a live AvosLocker sample in an isolated VM with no AV: files
outside the protected drive were encrypted, files inside came through with
matching hashes.
What I actually want to know is whether the idea is worth pursuing:
- Does an immutable-at-the-kernel layer add anything over good backups?
- Would you deploy something like this, or is the operational cost of
"some files can never be changed" too high in practice?
- What breaks this that I'm not seeing?
Video if it helps: https://www.youtube.com/watch?v=RgzEtQrlI9s
Not selling anything — no EV cert yet, so I can't ship even if I wanted to.
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The post describes a kernel-level filter driver designed to enforce immutability on files within a mapped drive, preventing modification or deletion regardless of privilege level, including local admin. This approach targets ransomware scenarios where the attacker has already gained administrative access. The author tested the driver against a live AvosLocker ransomware sample in an isolated environment, finding that files on the protected drive were not encrypted. The post solicits community input on the practicality and value of this defense compared to traditional backup strategies and operational trade-offs. No specific vulnerability or exploit is detailed.
Potential Impact
No direct impact or vulnerability is described. The content is a discussion of a potential defensive technique against ransomware. The impact is conceptual, suggesting that enforcing file immutability at the kernel level could prevent ransomware from encrypting protected files even if the attacker has admin rights. However, no operational or security risks of this approach are detailed.
Defensive Guidance
This is not a vulnerability or exploit but a proposed defense mechanism. No official patch or remediation applies. The author is seeking feedback on the approach's usefulness and operational feasibility. Organizations should continue to rely on established ransomware defenses such as reliable backups and tested recovery procedures. Consideration of kernel-level immutability controls could be explored as a supplementary measure but requires thorough evaluation before deployment.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Domain
- null
- Newsworthiness Assessment
- {"score":30,"reasons":["external_link","newsworthy_keywords:ransomware","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["ransomware"],"foundNonNewsworthy":[]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a803ebcbf8831d539eab741
Added to database: 08/15/2026, 10:26:04 UTC
Last enriched: 08/15/2026, 10:26:08 UTC
Last updated: 08/15/2026, 16:41:05 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.