Ransomware Canary
Tripwires that fire the moment encryption starts — buying back the response time that decides the outcome.
A ransomware canary is a decoy file — a canary file — placed where ransomware reaches early in an encryption sweep and watched continuously, so the first thing encrypted is something nobody needed. No member of staff has any reason to open it, so a single write to one is a high-confidence signal rather than an alert somebody has to triage.
The purpose of the Ransomware Canary service is to find ransomware activity on an endpoint. Canary files are deployed and monitored for changes across several directories.
Whenever the CyberTI® agent discovers that a canary file has been changed, renamed or deleted, it notifies the threat operations team to evaluate the circumstances causing the alert, confirm ransomware, and send an incident report with full incident details.
On this page
How it works
Decoys in the paths ransomware reaches first, watched at kernel level.
Canary files across key directories
Decoy files placed where ransomware reaches early in its encryption sweep. Legitimate users never open them, so any write is a high-confidence signal rather than something needing triage.
Kernel-level file monitoring
The agent implements this through a kernel MiniFilter driver that watches write access to specifically named files. On contact it suspends the offending process and captures a memory snapshot before encryption proceeds.
Behaviour, not signature
Because detection keys on behaviour, canary files cannot be fingerprinted and avoided by ransomware, and they work against families nobody has catalogued.
Threat operations escalation
Our team evaluates the alert, confirms whether it is genuine ransomware activity, and sends an incident report with the context needed to act.
The honest limit
If it happens: your 72-hour clock
ASD's advice is not to pay. There is no guarantee your files will be restored, payment does not prevent stolen data being published or sold, and organisations that pay are known to be targeted again.
On reporting, Australian law changed. Under the Cyber Security Act 2024, businesses with annual turnover above $3 million, and entities responsible for critical infrastructure assets, must report a ransomware or cyber extortion payment within 72 hours of making it or becoming aware it was made. The obligation has been in force since 30 May 2025, and the Department of Home Affairs moved to an active regulatory posture from 1 January 2026.
Separately, if personal information is involved, the OAIC's Notifiable Data Breaches scheme requires you to assess a suspected eligible breach within 30 days and notify affected individuals and the Commissioner where serious harm is likely.
Both clocks start at detection. Everything this service does is aimed at making that moment as early as possible.
Why ransomware canaries matter
Ransomware response is a race measured in minutes. The gap between the first encrypted file and the first human noticing is where most of the damage happens.
Canary files close that gap. They are silent to your users and loud to your SOC, and they detect encryption behaviour itself rather than relying on recognising a specific malware family.
The first thing ransomware touches should be a tripwire
Decoys sitting in the paths encryption reaches first, watched at kernel level, so the alarm comes at the start of the sweep rather than after it.
Frequently asked questions
A ransomware canary is a decoy file placed on an endpoint and watched for change. Ransomware encrypts what it finds, so a file that no person ever opens becomes an alarm: the first write to it means something is encrypting files, and it means so within seconds rather than after somebody notices their own documents are unreadable.
CyberTI® deploys canary files across several directories on each protected endpoint and watches them through a kernel MiniFilter driver — the same endpoint agent that provides endpoint protection and endpoint detection and response. On contact the offending process is suspended and a memory snapshot captured before encryption proceeds, and the threat operations team is notified to confirm the alert and issue an incident report.
A canary file is the decoy itself: an ordinary-looking document, planted deliberately, that exists only to be tampered with. It carries no business content, so nobody has a legitimate reason to open, rename or delete it, and any change to one is therefore a signal rather than something needing triage.
The name is borrowed from the canary carried into a coal mine, which stopped singing before the miners noticed the gas. Because the detection keys on the behaviour — something is writing to a file it should not touch — canary files cannot be fingerprinted and avoided the way a signature can, and they work against ransomware families nobody has catalogued yet.
ASD's advice is not to pay. There is no guarantee your files will be restored, payment does not prevent stolen data being published or sold, and organisations that pay are known to be targeted again.
On reporting, Australian law changed. Under the Cyber Security Act 2024, businesses with annual turnover above $3 million, and entities responsible for critical infrastructure assets, must report a ransomware or cyber extortion payment within 72 hours of making it or becoming aware it was made. The obligation has been in force since 30 May 2025, and the Department of Home Affairs moved to an active regulatory posture from 1 January 2026.
Separately, if personal information is involved, the OAIC's Notifiable Data Breaches scheme requires you to assess a suspected eligible breach within 30 days and notify affected individuals and the Commissioner where serious harm is likely.
Both clocks start at detection. Everything this service does is aimed at making that moment as early as possible.
More from Cloud Services
Endpoint Protection Platform
Block malware across Windows, macOS and Linux, with behavioural ransomware prevention on Windows.
Endpoint Detection and Response
Record what every endpoint actually did, and analyse it for the behaviour signature matching misses.
Extended Detection and Response
An endpoint alert and a network anomaly become one incident, not two tickets in two consoles.
Security Information and Event Management
350+ CyberTI-authored detections on top of a 1,300+ rule ATT&CK-mapped baseline, reviewed weekly.
Cloud Security Monitoring
Posture re-evaluated every 24 hours against CIS benchmarks, across AWS, Azure and Google Cloud.
Ready to see your attack surface the way an attacker does?
Book a walkthrough with an Australian-based security engineer. No scripted demo, no obligation.
Both forms deliver to info@cyberti.com.au.