top of page
  • Home
  • Services
  • Cloud Services
  • Ransomware Canary
  • Ransomware Canary

    Tripwires that fire the moment encryption starts — buying back the response time that decides the outcome.

    A ransomware canary is a decoy file — a canary file — placed where ransomware reaches early in an encryption sweep and watched continuously, so the first thing encrypted is something nobody needed. No member of staff has any reason to open it, so a single write to one is a high-confidence signal rather than an alert somebody has to triage.

    The purpose of the Ransomware Canary service is to find ransomware activity on an endpoint. Canary files are deployed and monitored for changes across several directories.

    Whenever the CyberTI® agent discovers that a canary file has been changed, renamed or deleted, it notifies the threat operations team to evaluate the circumstances causing the alert, confirm ransomware, and send an incident report with full incident details.

  • EDR EDR Endpoint Detection and Response Continuous recording of process, file and network activity on the endpoint, so behaviour no prevention engine recognised can still be spotted, investigated and contained. Full glossary →
  • EPP EPP Endpoint Protection Platform Prevention at the endpoint: blocking known malware and malicious behaviour at execution, before anything runs. Full glossary →
  • On this page

  • How it works
  • The honest limit
  • If it happens: your 72-hour clock
  • Why ransomware canaries matter
  • How it works

    Decoys in the paths ransomware reaches first, watched at kernel level.

    Canary files across key directories

    Decoy files placed where ransomware reaches early in its encryption sweep. Legitimate users never open them, so any write is a high-confidence signal rather than something needing triage.

    Kernel-level file monitoring

    The agent implements this through a kernel MiniFilter driver that watches write access to specifically named files. On contact it suspends the offending process and captures a memory snapshot before encryption proceeds.

    Behaviour, not signature

    Because detection keys on behaviour, canary files cannot be fingerprinted and avoided by ransomware, and they work against families nobody has catalogued.

    Threat operations escalation

    Our team evaluates the alert, confirms whether it is genuine ransomware activity, and sends an incident report with the context needed to act.

    The honest limit

  • 01 No one can guarantee ransomware reaches a canary first. Coverage depends on placement density — a canary cannot compel ransomware to touch the monitored directory before it touches something of yours. Canaries cut the gap between first encryption and first human response to seconds. They are an early-warning layer alongside endpoint prevention, not a replacement for it.
  • If it happens: your 72-hour clock

    ASD's advice is not to pay. There is no guarantee your files will be restored, payment does not prevent stolen data being published or sold, and organisations that pay are known to be targeted again.

    On reporting, Australian law changed. Under the Cyber Security Act 2024, businesses with annual turnover above $3 million, and entities responsible for critical infrastructure assets, must report a ransomware or cyber extortion payment within 72 hours of making it or becoming aware it was made. The obligation has been in force since 30 May 2025, and the Department of Home Affairs moved to an active regulatory posture from 1 January 2026.

    Separately, if personal information is involved, the OAIC's Notifiable Data Breaches scheme requires you to assess a suspected eligible breach within 30 days and notify affected individuals and the Commissioner where serious harm is likely.

    Both clocks start at detection. Everything this service does is aimed at making that moment as early as possible.

    Why ransomware canaries matter

    Ransomware response is a race measured in minutes. The gap between the first encrypted file and the first human noticing is where most of the damage happens.

    Canary files close that gap. They are silent to your users and loud to your SOC, and they detect encryption behaviour itself rather than relying on recognising a specific malware family.

    The first thing ransomware touches should be a tripwire

    Decoys sitting in the paths encryption reaches first, watched at kernel level, so the alarm comes at the start of the sweep rather than after it.

    Frequently asked questions

    What is a ransomware canary?

    A ransomware canary is a decoy file placed on an endpoint and watched for change. Ransomware encrypts what it finds, so a file that no person ever opens becomes an alarm: the first write to it means something is encrypting files, and it means so within seconds rather than after somebody notices their own documents are unreadable.

    CyberTI® deploys canary files across several directories on each protected endpoint and watches them through a kernel MiniFilter driver — the same endpoint agent that provides endpoint protection and endpoint detection and response. On contact the offending process is suspended and a memory snapshot captured before encryption proceeds, and the threat operations team is notified to confirm the alert and issue an incident report.

    What is a canary file?

    A canary file is the decoy itself: an ordinary-looking document, planted deliberately, that exists only to be tampered with. It carries no business content, so nobody has a legitimate reason to open, rename or delete it, and any change to one is therefore a signal rather than something needing triage.

    The name is borrowed from the canary carried into a coal mine, which stopped singing before the miners noticed the gas. Because the detection keys on the behaviour — something is writing to a file it should not touch — canary files cannot be fingerprinted and avoided the way a signature can, and they work against ransomware families nobody has catalogued yet.

    Do we have to report a ransomware payment in Australia?

    ASD's advice is not to pay. There is no guarantee your files will be restored, payment does not prevent stolen data being published or sold, and organisations that pay are known to be targeted again.

    On reporting, Australian law changed. Under the Cyber Security Act 2024, businesses with annual turnover above $3 million, and entities responsible for critical infrastructure assets, must report a ransomware or cyber extortion payment within 72 hours of making it or becoming aware it was made. The obligation has been in force since 30 May 2025, and the Department of Home Affairs moved to an active regulatory posture from 1 January 2026.

    Separately, if personal information is involved, the OAIC's Notifiable Data Breaches scheme requires you to assess a suspected eligible breach within 30 days and notify affected individuals and the Commissioner where serious harm is likely.

    Both clocks start at detection. Everything this service does is aimed at making that moment as early as possible.

    More from Cloud Services

    Endpoint Protection Platform

    Block malware across Windows, macOS and Linux, with behavioural ransomware prevention on Windows.

    Endpoint Detection and Response

    Record what every endpoint actually did, and analyse it for the behaviour signature matching misses.

    Extended Detection and Response

    An endpoint alert and a network anomaly become one incident, not two tickets in two consoles.

    Security Information and Event Management

    350+ CyberTI-authored detections on top of a 1,300+ rule ATT&CK-mapped baseline, reviewed weekly.

    Cloud Security Monitoring

    Posture re-evaluated every 24 hours against CIS benchmarks, across AWS, Azure and Google Cloud.

    Ready to see your attack surface the way an attacker does?

    Book a walkthrough with an Australian-based security engineer. No scripted demo, no obligation.

    Both forms deliver to info@cyberti.com.au.

    bottom of page