MatthewL Posted January 29, 2018 Posted January 29, 2018 Thought I'd share this article I was sent the other day, apparently works quite well, not had the need to implement myself but thought I'd share for those not aware. Works with Server 2008 R2 onwards. 3
colacao82 Posted January 29, 2018 Posted January 29, 2018 Thanks for this! I have question though... Why don't you need to implement this?
Arthur Posted January 29, 2018 Posted January 29, 2018 I have question though... Why don't you need to implement this? Because it's ultimately pointless? The file screen isn't going to stop ransomware that generates random file extensions, uses the existing file extension(s) or new extensions that weren't in FSRMs file screen.
colacao82 Posted January 29, 2018 Posted January 29, 2018 Fair enough. But at least you can honestly say you did everything you could’ve.
Arthur Posted January 29, 2018 Posted January 29, 2018 Perhaps a better alternative would be CryptoBlocker (which also uses FSRM) since it has a much more comprehensive list of ransomware extensions and is constantly updated (it was last updated this morning). The TechNet script on the other hand was updated almost a year ago on 13/02/2017!
roc1479 Posted February 19, 2018 Posted February 19, 2018 Can also use FSRM and create a 'Whitelist' to only allow the extension you want. Much easier to manage than blacklists.
snagrat Posted July 9, 2019 Posted July 9, 2019 Has anyone else implemented this with Server 2019? Seems to block you from editing Group Policies. I've added an exception rule for the c:\Windows\Sysvol but this did not help. Even taking the rules out didn't work so have temporarily had to remove FSRM
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now