01 Detonate
Execute live malware against production-grade Cohesity products in an air-gapped lab using current software.
We detonated 53 live ransomware strains against production-grade backup infrastructure in an air-gapped lab. then recorded exactly what happened.
Cohesity REDLab is a team of expert researchers who run an air-gapped facility, executing live malware against production-grade DataProtect and NetBackup deployments. We’re the data protection industry's only dedicated source of actionable intelligence on how malware interacts with backup infrastructure.
Execute live malware against production-grade Cohesity products in an air-gapped lab using current software.
Map every strain to MITRE ATT&CK and capture the same five measurement points per detonation for cross-strain comparison.
Log every test with timestamp, sample hash, and platform version.
Live ransomware strains detonated against real backup infrastructure in our air-gapped lab
Backup-tier signals that catch ransomware: Client Offline, Job Metadata, Image Entropy, Threat Scan, and Rapid Threat Hunt.
Every detonation ends one of three ways: communication cut, backup corrupted, or recovery preserved
Steps in the Anti-Backup Kill Chain: discover, steal credentials, disable recovery, target configs, attempt snapshot tampering
Attackers no longer hit backups by accident. They go after them deliberately, often within the first hours of an intrusion.
Multiple strains specifically encrypted backup files via the underlying OS. They did this to disrupt recovery (Find, Trial recovery, Payload).
The same attack patterns show up again and again: recovery inhibition (T1490), service stop (T1489), and abuse of valid accounts (T1078).
How malware compromises backups, and how you can stop it
Backup process
discovery
Credential harvesting of
backup admins
Shadow copy
disabling
Configuration file
encryption of backups
Snapshot tamper
attempts
Architectural resistance to the techniques in REDLab's Anti-Backup Kill Chain (process discovery, credential harvesting, shadow-copy deletion, configuration tampering, and snapshot tampering)
Backup-tier signal availability for detecting ransomware-driven backup deviation prior to restore
Architectural assurance that a recovery point is clean prior to use in restore
Elapsed time from initial anomaly signal to validated clean restore