ET Ducky RMM Uses ETW and eBPF to Detect Ransomware Behavior in Real Time
ET Ducky, a remote monitoring and management tool launching on Product Hunt on September 29, uses a behavioral rule engine to detect ransomware activity on both Windows and Linux endpoints. The system reads kernel event streams via ETW on Windows and eBPF tracepoints on Linux, normalizing both into a unified event format so that each rule applies across operating systems. Thirteen built-in rules monitor patterns such as mass file renaming, encryption sweeps, shadow copy deletion, and ransom note creation, with thresholds tuned to favor false positives over missed detections. A composite kill-chain rule triggers a critical alert when two or more ransomware indicators occur on the same process within five minutes. The tool is not an antivirus replacement but a behavioral monitoring layer, with one noted Linux limitation around capturing original file names during rename operations.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in