Anti-ransomware para o adm de redeAnti-ransomware for the network admin

O ransomware ataca os seus servidores. Defenda-os lá.

Ransomware hits your servers. Defend them there.

Pontue o risco da sua rede, monitore os servidores em tempo real — inclusive a criptografia que vem pela rede e passa despercebida pelo antivírus — e contenha o ataque em segundos. Self-hosted, com os recursos nativos do Windows, sem depender de licenças caras.

Score your network's risk, monitor your servers in real time — including encryption that comes over the network and slips past antivirus — and contain the attack in seconds. Self-hosted, using Windows' native features, with no expensive licenses.

Agente via GPO · painel na sua rede · metadado, nunca conteúdoAgent via GPO · dashboard on your network · metadata, never content

O problemaThe problem

Muitas vezes, o ransomware não invade. Ele faz login.

Often, ransomware doesn't break in. It logs in.

O ataque moderno usa uma conta legítima e criptografa seus arquivos pela rede — onde o antivírus do endpoint não enxerga. Quando o alerta chega, o estrago já passou.

The modern attack uses a legitimate account and encrypts your files over the network — where endpoint antivirus can't see. By the time the alert arrives, the damage is done.

🕳️

O ponto cego do EDR

The EDR blind spot

A criptografia dominante hoje é remota via SMB: uma máquina invadida cifra os shares pela rede, e o processo malicioso nunca roda no servidor.

Today's dominant encryption is remote over SMB: a compromised machine encrypts the shares over the network, and the malicious process never runs on the server.

Sophos · CryptoGuard / WantToCry

⏱️

Menos de 4 horas

Under 4 hours

É o tempo para um domínio inteiro ser criptografado. Resposta manual não existe nessa escala — a contenção precisa ser automática e em segundos.

That's how long it takes to encrypt an entire domain. Manual response doesn't exist at that speed — containment must be automatic, in seconds.

relatórios de resposta a incidente, 2025

incident response reports, 2025

🎯

88% das violações em PMEs

88% of SMB breaches

têm ransomware — e 1 em cada 5 empresas atacadas fecha as portas. Sem orçamento para plataforma enterprise ou o stack E5.

involve ransomware — and 1 in 5 attacked companies goes out of business. With no budget for an enterprise platform or the E5 stack.

Huntress · Mastercard SMB survey

Como o RansomGuard ajuda: ele mora nos seus servidores, no ponto exato do dano. Pontua seu risco antes do ataque, a criptografia em ação (inclusive a remota) e contém em segundos — derrubando a sessão, bloqueando o IP e desabilitando a conta. Sem E5, sem EDR, sem seus dados saírem da rede.

How RansomGuard helps: it lives on your servers, exactly where the damage happens. It scores your risk before the attack, sees encryption in action (including remote) and contains it in seconds — killing the session, blocking the IP and disabling the account. No E5, no EDR, nothing leaves your network.

O produtoThe product

Três frentes, uma jornada

Three fronts, one journey

Instale pelo score, mantenha pelo monitor, durma tranquilo com a contenção.

Install for the score, stay for the monitoring, sleep well with containment.

1 · Prevenir · grátis1 · Prevent · free

Score de Risco de Ransomware

Ransomware Risk Score

Nota 0–100 da prontidão de cada servidor e da rede, calibrada pelas táticas reais dos últimos ataques.

A 0–100 readiness grade per server and network-wide, calibrated to real tactics from recent attacks.

  • Hardening SMB, shares expostos, VSS/backup
  • SMB hardening, exposed shares, VSS/backup
  • Lista priorizada com o comando/GPO de correção
  • Prioritized fix list with the exact command/GPO
  • Relatório PDF executivo para a diretoria
  • Executive PDF report for management
2 · Ver · grátis2 · See · free

Monitor dos servidores

Server monitor

Detecção em camadas com recursos nativos — funciona mesmo quando o ataque vem de outra máquina.

Layered detection on native features — works even when the attack comes from another machine.

  • FSRM dirigido por catálogo assinado e atualizado
  • FSRM driven by a signed, updated catalog
  • Arquivos-canário + sessões SMB (quem, de onde, o quê)
  • Canary files + SMB sessions (who, from where, what)
  • Deleção de VSS e tamper do agente = incidente
  • VSS deletion and agent tamper = incident
3 · Agir · pago3 · Act · paid

Contenção automática

Automatic containment

Escada de resposta em segundos, com guard-rails para o I/O legítimo de backup e sincronização.

A response ladder in seconds, with guard-rails for legitimate backup and sync I/O.

  • Derruba a sessão SMB e bloqueia o IP de origem
  • Kills the SMB session and blocks the source IP
  • Desabilita a conta no AD e isola o share
  • Disables the AD account and isolates the share
  • Modos monitor → alerta → bloqueio, por regra
  • Monitor → alert → block modes, per rule
Como funcionaHow it works

Da instalação à contenção em 4 passos

From install to containment in 4 steps

O agente vê o ataque no ponto cego do EDR (Endpoint Detection and Response), reporta ao painel na sua rede e contém em segundos.

The agent sees the attack in the EDR (Endpoint Detection and Response) blind spot, reports to the dashboard on your network and contains it in seconds.

Implante via GPO

Deploy via GPO

MSI assinado do agente nos servidores de arquivos; painel self-hosted na sua rede. Nada sai para a nuvem.

Signed agent MSI on your file servers; self-hosted dashboard on your network. Nothing goes to the cloud.

Receba seu score

Get your score

O agente audita a postura (SMB, shares, VSS, auditoria) e o painel entrega a nota com as correções priorizadas.

The agent audits posture (SMB, shares, VSS, auditing) and the dashboard delivers the grade with prioritized fixes.

Monitore em camadas

Monitor in layers

FSRM + canários + sessões SMB detectam criptografia local e remota; o catálogo assinado mantém tudo atualizado.

FSRM + canaries + SMB sessions detect local and remote encryption; the signed catalog keeps it all current.

Contenha em segundos

Contain in seconds

Canário tocado? Sessão derrubada, IP bloqueado, conta desabilitada — e o incidente inteiro documentado no painel.

Canary touched? Session killed, IP blocked, account disabled — the whole incident documented in the dashboard.

PlanosPlans

Grátis para prevenir e ver. Pago para agir.

Free to prevent and see. Paid to act.

Light
GrátisFree

Score de Risco + monitoramento completo, sem limite de tempo.

Risk Score + full monitoring, no time limit.

  • Score de Risco com relatório PDF
  • Risk Score with PDF report
  • FSRM orquestrado + canários + sessões SMB
  • Orchestrated FSRM + canaries + SMB sessions
  • Painel central + alertas por e-mail
  • Central dashboard + e-mail alerts
  • Catálogo assinado com atualização automática
  • Signed catalog with automatic updates
contençãocontainment Premium
Assinatura anualAnnual license

Tudo do grátis + resposta automática que impede a propagação.

Everything in free + automatic response that stops the spread.

  • Escada de contenção: sessão SMB → IP → conta AD → share
  • Containment ladder: SMB session → IP → AD account → share
  • Modos monitor → alerta → bloqueio por regra
  • Monitor → alert → block modes per rule
  • Modo aprendizado + allowlist (backup passa ileso)
  • Learning mode + allowlist (backups sail through)
  • Export SIEM + relatório de incidente assinado
  • SIEM export + signed incident report

Preço em definição — lista de espera aberta.Pricing being finalized — waitlist open.

PrincípiosPrinciples

Seus dados, sua rede, seu controle

Your data, your network, your control

Nascido da prática: industrializa a abordagem FSRM que o autor publicou e usou com sucesso em ambientes reais — agora com as camadas que os ataques de hoje exigem.

Born from practice: it industrializes the FSRM approach the author published and ran successfully in real environments — now with the layers today's attacks demand.

🔒
Metadado, nunca conteúdoMetadata, never contentUsuário, IP, share, contagens — nenhum conteúdo de arquivo sai do servidor.User, IP, share, counts — no file content ever leaves the server.
🏠
Self-hosted de verdadeTruly self-hostedPainel na sua rede; o agente só fala com o seu backend.Dashboard on your network; the agent talks only to your backend.
🧩
Nativo do WindowsWindows-nativeFSRM, auditoria SMB, firewall, AD — sem kernel driver, sem agente exótico.FSRM, SMB auditing, firewall, AD — no kernel driver, no exotic agent.
✍️
Catálogo assinadoSigned catalogA inteligência de detecção vem numa lista assinada (Ed25519), com anti-rollback.Detection intelligence ships in a signed list (Ed25519), with anti-rollback.
Para quem éWho it's for

Feito para o admin, não para o SOC

Built for the admin, not the SOC

✔ É para você se…

✔ It's for you if…

Você administra uma rede Windows/AD com servidores de arquivos, não tem licenças caras (E5) nem plataforma enterprise anti-ransomware, e quer proteção que se instala por GPO numa tarde — com evidência para mostrar à diretoria.

You run a Windows/AD network with file servers, don't have expensive licenses (E5) or an enterprise anti-ransomware platform, and want protection you can deploy via GPO in an afternoon — with evidence to show management.

✘ Não é para você se…

✘ It's not for you if…

Você procura EDR de endpoint, DLP de conteúdo ou backup — o RansomGuard complementa essas camadas (e assume que backup é a última linha de defesa), mas não as substitui.

You're looking for endpoint EDR, content DLP or backup — RansomGuard complements those layers (and assumes backup is the last line of defense), but doesn't replace them.

Programa de testersTester program

Instalação em 10 minutos 🧅

Install in 10 minutes 🧅

Você é um tester convidado. Este é o passo a passo completo — do download ao primeiro Score de Risco. Tudo roda na sua rede: nada é enviado para a internet.

You're an invited tester. This is the complete walkthrough — from download to your first Risk Score. Everything runs on your network: nothing is sent to the internet.

📋 Antes de começar

📋 Before you start

  • Uma máquina para o painel — pode ser seu próprio PC (Windows 10/11) ou um servidor. É onde você vê tudo.
  • Um servidor para o agente — idealmente um servidor de arquivos Windows. Para só experimentar, o mesmo PC serve.
  • Não precisa instalar .NET, banco de dados ou qualquer dependência.
  • Direito de administrador no servidor onde o agente vai rodar.
  • A machine for the dashboard — your own PC (Windows 10/11) or a server. It's where you see everything.
  • A server for the agent — ideally a Windows file server. Just to try it out, the same PC works.
  • No need to install .NET, a database or any dependency.
  • Administrator rights on the server where the agent will run.

1 Baixar os instaladores

1 Download the installers

Windows x64 · não precisa de .NETno .NET required

São dois instaladores. Instale o painel na máquina que vai centralizar tudo, e o agente em cada servidor que quer proteger.

There are two installers. Install the dashboard on the machine that centralizes everything, and the agent on each server you want to protect.

Painel (.msi) →Dashboard (.msi) → Agente (.msi) →Agent (.msi) → Versão portátil (.zip)Portable version (.zip)

⚠️ O Windows vai avisar que o editor é desconhecido. É esperado: nesta fase de testes o instalador ainda não é assinado digitalmente (o certificado entra depois). Clique em Mais informações → Executar assim mesmo. Para conferir a integridade, o SHA-256 de cada arquivo está publicado na página do release.
⚠️ Windows will warn about an unknown publisher. Expected: at this testing stage the installer is not code-signed yet (the certificate comes later). Click More info → Run anyway. To verify integrity, each file's SHA-256 is published on the release page.
💡 Prefere não instalar nada? A versão portátil (.zip) traz os mesmos executáveis para rodar de uma pasta — bom para uma avaliação rápida.
💡 Rather not install anything? The portable version (.zip) has the same executables to run from a folder — good for a quick look.

2 Instalar e abrir o painel

2 Install and open the dashboard

Execute o RansomGuard-Painel.msi (aceite o aviso do Windows). Ele instala em Arquivos de Programas e cria o atalho RansomGuard — Painel no Menu Iniciar.

Run RansomGuard-Painel.msi (accept the Windows warning). It installs to Program Files and creates a RansomGuard — Painel shortcut in the Start Menu.

Abra pelo atalho. Uma janela de console mostra o endereço — por padrão http://localhost:5000. Abra no navegador e deixe a janela aberta.

Open it from the shortcut. A console window shows the address — by default http://localhost:5000. Open it in your browser and keep the window open.

Usando a versão portátil? Extraia o zip, entre em painel\ e execute:

Using the portable version? Extract the zip, go into painel\ and run:

Go into the painel\ folder and run:

RansomGuard.Server.exe

Uma janela de console abre e mostra o endereço. Por padrão é http://localhost:5000 — abra no navegador. Deixe essa janela aberta: fechá-la para o painel.

A console window opens showing the address. By default it's http://localhost:5000 — open it in your browser. Keep that window open: closing it stops the dashboard.

💡 Se a porta 5000 estiver ocupada, rode RansomGuard.Server.exe --urls http://localhost:5050 (ou outra porta livre).
💡 If port 5000 is taken, run RansomGuard.Server.exe --urls http://localhost:5050 (or another free port).
💡 Se o agente vai rodar em outra máquina, o painel precisa aceitar conexões da rede: RansomGuard.Server.exe --urls http://0.0.0.0:5000 e libere a porta no firewall.
💡 If the agent runs on another machine, the dashboard must accept network connections: RansomGuard.Server.exe --urls http://0.0.0.0:5000 and open the port in the firewall.

3 Instalar o agente no servidor

3 Install the agent on the server

No servidor que você quer proteger, execute o RansomGuard-Agente.msi. Ele se instala como Serviço do Windows — inicia sozinho no boot e continua rodando mesmo sem ninguém logado.

On the server you want to protect, run RansomGuard-Agente.msi. It installs as a Windows Service — starts on boot and keeps running even with nobody logged in.

Instalação com um clique duplo: funciona, mas o agente vai apontar para http://localhost:5000. Use isso se o painel estiver no mesmo servidor.

Double-click install: works, but the agent will point to http://localhost:5000. Use this if the dashboard is on the same server.

Painel em outra máquina? Instale pela linha de comando (PowerShell como Administrador), informando o endereço do painel:

Dashboard on another machine? Install from the command line (PowerShell as Administrator), passing the dashboard address:

msiexec /i RansomGuard-Agente-0.1.7-tester.msi BACKENDURL=http://192.168.1.10:5000 SERVERNAME=FS01
  • BACKENDURL — endereço do painel. Padrão: http://localhost:5000
  • SERVERNAME — nome com que o servidor aparece no painel. Padrão: o nome da máquina
  • MODEMonitor, Alert ou Block. Padrão: Monitor
  • BACKENDURL — dashboard address. Default: http://localhost:5000
  • SERVERNAME — the name the server shows as in the dashboard. Default: the machine name
  • MODEMonitor, Alert or Block. Default: Monitor
O agente já começa em Monitor. Ele apenas observa e reporta — não bloqueia nada. Os modos Alert e Block pertencem ao plano pago e só devem ser usados depois de conhecer o comportamento no seu ambiente.
The agent starts in Monitor mode. It only observes and reports — blocks nothing. Alert and Block modes belong to the paid plan and should only be used after you know the behavior in your environment.
💡 Vários servidores? A mesma linha de comando com /quiet ao final funciona por GPO — é assim que se implanta em todo o parque de uma vez.
💡 Many servers? The same command line with /quiet at the end works via GPO — that's how you deploy across the whole fleet at once.
💡 Versão portátil: edite agente\appsettings.json (campos ServerName, BackendUrl, Mode) e execute RansomGuard.Agent.Service.exe num PowerShell como Administrador.
💡 Portable version: edit agente\appsettings.json (ServerName, BackendUrl, Mode) and run RansomGuard.Agent.Service.exe in an elevated PowerShell.

4 Conferir se está rodando

4 Check that it's running

O serviço sobe sozinho ao final da instalação. Para confirmar, rode num PowerShell:

The service starts on its own at the end of the installation. To confirm, run in PowerShell:

Get-Service RansomGuardAgent

O status deve ser Running. Se não estiver, inicie com Start-Service RansomGuardAgent.

Status should be Running. If not, start it with Start-Service RansomGuardAgent.

5 Ver o resultado

5 See the result

Volte ao painel no navegador. Em poucos minutos você verá:

Go back to the dashboard in your browser. Within a few minutes you'll see:

  • Visão geral — a nota de risco (0–100) do servidor e da rede.
  • Servidor — a lista priorizada de correções, cada uma com o comando ou GPO que resolve.
  • Incidentes — detecções, quando houver (quem, de onde, qual share).
  • Licença — o número da sua instalação (usado para ativar o plano pago).
  • Overview — the risk score (0–100) for the server and the network.
  • Server — the prioritized fix list, each with the command or GPO that solves it.
  • Incidents — detections, when they occur (who, from where, which share).
  • License — your installation number (used to activate the paid plan).

Manual detalhado de cada tela em Documentação.

Detailed manual for each screen in the Documentation.

🔍 O que queremos que você teste

🔍 What we'd like you to test

Quatro perguntas — as respostas valem mais que qualquer relatório:

Four questions — your answers are worth more than any report:

  • 1. O Score faz sentido? As correções recomendadas batem com a realidade do seu parque, ou tem alguma que não se aplica?
  • 2. A atribuição está certa? Quando aparece um incidente, o usuário e o IP de origem conferem?
  • 3. Falso positivo (o mais importante). Rode um backup pesado, um robocopy, uma sincronização. Apareceu algum alerta indevido?
  • 4. Está claro? Alguma tela ou texto confundiu você? O que é grátis e o que é pago ficou evidente?
  • 1. Does the Score make sense? Do the recommended fixes match your fleet's reality, or is any of them irrelevant?
  • 2. Is attribution correct? When an incident shows up, do the user and source IP check out?
  • 3. False positives (most important). Run a heavy backup, a robocopy, a sync. Did any undue alert appear?
  • 4. Is it clear? Did any screen or wording confuse you? Was it obvious what's free and what's paid?
Como reportar: anote o que funcionou, o que confundiu e qualquer falso positivo, e envie junto o texto da janela do agente e do painel. É esse retorno que define as próximas versões.
How to report: note what worked, what confused you and any false positive, and send along the text from the agent and dashboard windows. This feedback shapes the next versions.

🔒 Privacidade e limites desta versão

🔒 Privacy and limits of this version

Metadado e configuração, nunca conteúdo. O RansomGuard observa quem acessou, de onde, qual pasta e quantos arquivos — jamais o conteúdo deles. O agente conversa somente com o painel que você hospeda; nada vai para a internet.

Metadata and configuration, never content. RansomGuard observes who accessed, from where, which folder and how many files — never their contents. The agent talks only to the dashboard you host; nothing goes to the internet.

O que ainda não está nesta versão: instalador MSI e deploy por GPO, assinatura digital dos executáveis, e alguns coletores de evento do Windows em modo completo (em validação em laboratório).

Not in this version yet: MSI installer and GPO deployment, digital signature of the executables, and some Windows event collectors in full mode (under lab validation).

DocumentaçãoDocumentation

Manual de operação

Operation manual

Do primeiro acesso à contenção automática. Versão de avaliação — as telas ilustradas entram após o piloto.

From first access to automatic containment. Evaluation version — illustrated screens come after the pilot.

1 · O que é

1 · What it is

O RansomGuard vive nos seus servidores — o ponto exato onde o ransomware causa dano. Ele faz três coisas: pontua o risco antes do ataque (Score), a criptografia em ação (inclusive a que vem pela rede, que o antivírus de endpoint não enxerga) e contém em segundos. Tudo self-hosted, sobre recursos nativos do Windows.

RansomGuard lives on your servers — exactly where ransomware does damage. It does three things: scores the risk before the attack, sees encryption in action (including over the network, invisible to endpoint antivirus) and contains it in seconds. All self-hosted, on native Windows features.

2 · Instalar o painel

2 · Install the dashboard

O painel é o cérebro: recebe os dados dos agentes e mostra tudo. Rode RansomGuard.Server.exe numa máquina que fique ligada (pode ser um servidor comum ou uma VM). Ele abre um endereço local — anote a porta mostrada no console. Não precisa instalar .NET nem banco de dados: tudo já vem embutido.

The dashboard is the brain: it receives agent data and shows everything. Run RansomGuard.Server.exe on a machine that stays on. It opens a local address — note the port shown in the console. No .NET or database installation required.

3 · Instalar o agente

3 · Install the agent

O agente vai em cada servidor que você quer proteger (tipicamente os servidores de arquivos). Edite o appsettings.json:

The agent goes on each server you want to protect (typically file servers). Edit appsettings.json:

  • ServerName — como o servidor aparecerá no painel
  • BackendUrl — o endereço do painel (ex.: http://painel:5000)
  • ModeMonitor (padrão), Alert ou Block
  • LicensedForResponsefalse no plano grátis
  • ServerName — how the server appears in the dashboard
  • BackendUrl — the dashboard address (e.g. http://dashboard:5000)
  • ModeMonitor (default), Alert or Block
  • LicensedForResponsefalse on the free plan

Rode como Administrador — ele precisa disso para ler os eventos do Windows. Na versão final, o MSI faz isso como serviço, distribuído por GPO.

Run as Administrator — required to read Windows events. In the final version, the MSI installs it as a service, deployed via GPO.

4 · Score de Risco

4 · Risk Score

Minutos após o agente subir, o servidor aparece na Visão geral com uma nota de 0 a 100. A nota é calculada por regras calibradas pelas táticas reais dos ataques atuais: hardening de SMB, shares expostos, resiliência de VSS/backup, cobertura de auditoria. Abra o servidor para ver a lista priorizada de correções — cada uma com o comando ou a GPO que resolve.

Minutes after the agent starts, the server appears in the Overview with a 0–100 score, computed from rules calibrated by real attack tactics: SMB hardening, exposed shares, VSS/backup resilience, audit coverage. Open a server to see the prioritized fix list — each with the command or GPO that solves it.

5 · Incidentes

5 · Incidents

A tela de Incidentes mostra as detecções correlacionadas: quem (usuário), de onde (IP de origem), o quê (share e nº de arquivos) e por quê (canário tocado, renomeação em massa, VSS apagado). O IP de origem é o que permite identificar a criptografia remota — quando o ataque vem de outra máquina da rede.

The Incidents screen shows correlated detections: who (user), from where (source IP), what (share and file count) and why (canary touched, mass rename, VSS deleted). The source IP is what identifies remote encryption — when the attack comes from another machine.

6 · Contenção (plano pago)

6 · Containment (paid plan)

Com licença ativa e modo Bloqueio, o produto reage sozinho: derruba a sessão SMB do atacante, bloqueia o IP no firewall, desabilita a conta no AD e, em último caso, isola o share. Só incidentes de alta confiança disparam contenção; os de confiança média apenas alertam — é o que evita derrubar um backup legítimo. Há ainda modo aprendizado e allowlist de contas de serviço.

With an active license and Block mode, the product reacts on its own: kills the attacker's SMB session, blocks the IP, disables the AD account and, as a last resort, isolates the share. Only high-confidence incidents trigger containment; medium-confidence ones only alert — that's what prevents taking down a legitimate backup. There's also learning mode and a service-account allowlist.

7 · Licença

7 · License

A tela Licença mostra o número da instalação do seu painel. Ao contratar, você informa esse número e recebe por e-mail um token assinado, que cola na mesma tela. A validação é 100% offline — nenhum dado sai da sua rede, e a licença só funciona naquela instalação.

The License screen shows your dashboard's installation number. When you subscribe, you provide that number and receive a signed token by e-mail, which you paste on the same screen. Validation is 100% offline — no data leaves your network, and the license only works on that installation.

8 · Privacidade

8 · Privacy

Metadado e configuração, nunca conteúdo. O produto observa quem acessou, de onde, qual share e quantos arquivos — jamais o conteúdo dos seus arquivos. O agente conversa somente com o painel que você hospeda; nada é enviado para a internet.

Metadata and configuration, never content. The product observes who accessed, from where, which share and how many files — never your file contents. The agent talks only to the dashboard you host; nothing goes to the internet.