1 · O que é
1 · What it is
O RansomGuard vive nos seus servidores — o ponto exato onde o ransomware causa dano. Ele faz três coisas: pontua o risco antes do ataque (Score), vê a criptografia em ação (inclusive a que vem pela rede, que o antivírus de endpoint não enxerga) e contém em segundos. Tudo self-hosted, sobre recursos nativos do Windows.
RansomGuard lives on your servers — exactly where ransomware does damage. It does three things: scores the risk before the attack, sees encryption in action (including over the network, invisible to endpoint antivirus) and contains it in seconds. All self-hosted, on native Windows features.
2 · Instalar o painel
2 · Install the dashboard
O painel é o cérebro: recebe os dados dos agentes e mostra tudo. Rode RansomGuard.Server.exe numa máquina que fique ligada (pode ser um servidor comum ou uma VM). Ele abre um endereço local — anote a porta mostrada no console. Não precisa instalar .NET nem banco de dados: tudo já vem embutido.
The dashboard is the brain: it receives agent data and shows everything. Run RansomGuard.Server.exe on a machine that stays on. It opens a local address — note the port shown in the console. No .NET or database installation required.
Na primeira vez, o painel pede para criar a senha do administrador (mínimo 8 caracteres). Sem essa conta, ninguém entra — o painel não fica aberto na sua rede. Guarde a senha: não há "esqueci a senha" nesta versão (o reset é apagar a conta no banco e refazer o setup).
On first run, the dashboard asks you to create the admin password (minimum 8 characters). Without this account, no one gets in — the dashboard is not left open on your network. Keep the password: there's no "forgot password" in this version (reset = delete the account row and redo setup).
3 · Instalar o agente
3 · Install the agent
O agente vai em cada servidor que você quer proteger (tipicamente os servidores de arquivos). Edite o appsettings.json:
The agent goes on each server you want to protect (typically file servers). Edit appsettings.json:
ServerName — como o servidor aparecerá no painel
BackendUrl — o endereço do painel (ex.: http://painel:5000)
Mode — Monitor (padrão), Alert ou Block
ProtectedPaths — pastas a proteger, separadas por ; (ex.: D:\Shares\Financeiro)
ServerName — how the server appears in the dashboard
BackendUrl — the dashboard address (e.g. http://dashboard:5000)
Mode — Monitor (default), Alert or Block
ProtectedPaths — folders to protect, separated by ; (e.g. D:\Shares\Finance)
O MSI instala o agente como Serviço do Windows — ele já sobe com o privilégio que precisa para ler os eventos. A contenção automática vem do painel (com licença), não de um arquivo local.
The MSI installs the agent as a Windows Service — it starts with the privilege it needs to read events. Automatic containment comes from the dashboard (with a license), not from a local file.
Pré-requisito da detecção: ligue a auditoria de acesso a arquivo no servidor, num PowerShell elevado — sem isso o Windows não emite os eventos que o agente lê:
auditpol /set /subcategory:"Detailed File Share" /success:enable
Detection prerequisite: enable file-access auditing on the server, in an elevated PowerShell — without it Windows doesn't emit the events the agent reads:
auditpol /set /subcategory:"Detailed File Share" /success:enable
Confira se o agente está enxergando: rode RansomGuard.Agent.Service.exe --diagnostico (elevado). Ele diz, em português, se a auditoria está certa, se consegue ler o log de segurança e se as pastas estão configuradas — e explica o que fazer se faltar algo.
Check the agent can see: run RansomGuard.Agent.Service.exe --diagnostico (elevated). It tells you, in plain language, whether auditing is right, whether it can read the security log and whether folders are configured — and explains what to fix.
4 · Score de Risco
4 · Risk Score
Minutos após o agente subir, o servidor aparece na Visão geral com uma nota de 0 a 100. A nota é calculada por regras calibradas pelas táticas reais dos ataques atuais: hardening de SMB, shares expostos, resiliência de VSS/backup, cobertura de auditoria. Abra o servidor para ver a lista priorizada de correções — cada uma com o comando ou a GPO que resolve.
Minutes after the agent starts, the server appears in the Overview with a 0–100 score, computed from rules calibrated by real attack tactics: SMB hardening, exposed shares, VSS/backup resilience, audit coverage. Open a server to see the prioritized fix list — each with the command or GPO that solves it.
5 · Incidentes
5 · Incidents
A tela de Incidentes mostra as detecções correlacionadas: quem (usuário), de onde (IP de origem), o quê (share e nº de arquivos) e por quê (canário tocado, renomeação em massa, VSS apagado). O IP de origem é o que permite identificar a criptografia remota — quando o ataque vem de outra máquina da rede.
The Incidents screen shows correlated detections: who (user), from where (source IP), what (share and file count) and why (canary touched, mass rename, VSS deleted). The source IP is what identifies remote encryption — when the attack comes from another machine.
6 · Provocar uma detecção (ensaio seguro)
6 · Trigger a detection (safe drill)
Para ver o produto pegar um ataque sem esperar um de verdade, o agente traz um ensaio: ele imita ransomware numa pasta de teste — sem criptografar nada e sem tocar em dados reais. Cinco travas de segurança garantem que ele só age numa pasta que ele mesmo criou.
To watch the product catch an attack without waiting for a real one, the agent ships a drill: it mimics ransomware in a test folder — encrypting nothing and never touching real data. Five safety locks ensure it only acts on a folder it created itself.
RansomGuard.Agent.Service.exe --ensaio-preparar C:\PastaDeTeste
RansomGuard.Agent.Service.exe --preparar
RansomGuard.Agent.Service.exe --ensaio C:\PastaDeTeste --confirmar
RansomGuard.Agent.Service.exe --ensaio-limpar C:\PastaDeTeste
Depois do --confirmar, o incidente deve aparecer no painel com o usuário e a origem. O --ensaio-limpar desfaz tudo.
After --confirmar, the incident should appear on the dashboard with the user and origin. --ensaio-limpar undoes everything.
⚠️ Seu antivírus pode reclamar. O ensaio cria arquivos com extensão .locked e um "bilhete de resgate" de mentira — nada é malicioso, mas alguns antivírus alertam pela aparência. É esperado. Se o AV apagar os arquivos de teste, ele está fazendo o trabalho dele; use uma pasta de teste e, se precisar, uma exclusão temporária.
⚠️ Your antivirus may complain. The drill creates files with the .locked extension and a fake "ransom note" — nothing is malicious, but some antivirus flags the appearance. That's expected. If the AV deletes the test files, it's doing its job; use a test folder and a temporary exclusion if needed.
7 · Contenção (plano pago)
7 · Containment (paid plan)
Com licença ativa e modo Bloqueio, o produto reage sozinho: derruba a sessão SMB do atacante, bloqueia o IP no firewall, desabilita a conta no AD e, em último caso, isola o share. Só incidentes de alta confiança disparam contenção; os de confiança média apenas alertam — é o que evita derrubar um backup legítimo. Há ainda modo aprendizado e allowlist de contas de serviço.
With an active license and Block mode, the product reacts on its own: kills the attacker's SMB session, blocks the IP, disables the AD account and, as a last resort, isolates the share. Only high-confidence incidents trigger containment; medium-confidence ones only alert — that's what prevents taking down a legitimate backup. There's also learning mode and a service-account allowlist.
8 · Licença
8 · License
A tela Licença mostra o número da instalação do seu painel. Ao contratar, você informa esse número e recebe por e-mail um token assinado, que cola na mesma tela. A validação é 100% offline — nenhum dado sai da sua rede, e a licença só funciona naquela instalação.
The License screen shows your dashboard's installation number. When you subscribe, you provide that number and receive a signed token by e-mail, which you paste on the same screen. Validation is 100% offline — no data leaves your network, and the license only works on that installation.
9 · Privacidade
9 · Privacy
Metadado e configuração, nunca conteúdo. O produto observa quem acessou, de onde, qual share e quantos arquivos — jamais o conteúdo dos seus arquivos. O agente conversa somente com o painel que você hospeda; nada é enviado para a internet.
Metadata and configuration, never content. The product observes who accessed, from where, which share and how many files — never your file contents. The agent talks only to the dashboard you host; nothing goes to the internet.