This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

How to detect the presence of Wannacry Ransomware and SMBv1 servers on your network.

Very topical at the moment. Couple of things to watch out for

  1. Check your network for any SMBv1 activity. You need to disable SMBv1 or at a minimum deploy Security Update for Microsoft Windows SMB Server (4013389) where appropriate
  2. Watch out for any increase in file renames

More info in this blog post which I will keep updated as new information comes in.

https://www.netfort.com/blog/detect-wannacry-ransomware/