A free tool has been created for security reasons by a security researcher which can detect any kind of attempts that are made by ransomware programs towards the encryption of the files that are saved on Mac user. This tool not only detects the attempts, however also before any major damage s caused, blocks any kind of attempt.
Patrick Wardle, the creator of RansomWhere is also the director of security firm Synack’s research and development department. This app can go ahead and detect as well as block the encrypted files of processes that not trustworthy. With the help of the user’s home directory, all the necessary monitoring is done by the tool and also helps in the detection of the creation of the encrypted files inside the,.
The minute this kind of activity is detected, the tool not only goes ahead and determines however also suspends the process that is responsible. For the limitation of false positives, ransomware detects the encrypted programs that are legitimate. The tool also has a white list which includes all the applications that Apple signs and those that were already installed on the computer prior to the installation of RansomWhere?
This means that in order for the tool to work as per the expectation, the installation of the tool has to be done on a computer that is not infected with the ransomware files. If it is, then the tool will not work not just on the already installed infected files, but also on the new ones. This also means that if there are any inject code or computer hijack then there will be no action take since the computer is already infected.
An encryption process is suspended by RansomWhere? The user will get a prompt which will give you the option to either terminate or allow the program to continue. This will also let the user know about which encrypted programs are legitimate and which can be trusted.