Early Detection to Block Ransomware
Know which files were affected and when so you can act early.
Ransomware detection and recovery built into your backup software. GuardMode provides early detection of ransomware or data-related anomalies before you back up your data. It complements endpoint and edge protection by monitoring file shares and system behavior instead of relying on a specific binary fingerprint.

GuardMode maintains and regularly updates thousands of known ransomware threat patterns and assesses affected files for anomalies. While most ransomware detection solutions are built for security teams, GuardMode is designed with the backup administrator and backup workflows in mind, with an easy-to-configure detection mechanism and the ability to guide administrators in recovering affected data.

Why GuardMode
We designed GuardMode to be a complementary ransomware and data anomaly detection solution that enhances the security posture of your backup and storage teams, and therefore your company.

Data-related events are stored on the client and synchronized with the server. Analysis and anomaly detection happen independently from the server.

GuardMode only processes active data and analyzes file heuristics rather than block heuristics (significantly fewer events).

Modular architecture for plugin-like extensibility for data sources and targets, making integration with SIEMs via REST API or Syslog as simple as possible.
“It is the responsibility of every company to do all they can to harden their cybersecurity stance. This includes ensuring that the data they are backing up has not been compromised by ransomware, and that they can recover their systems and data from their backups. With the GuardMode agent in the new DPX 4.9 release, Campus and our clients' IT backup teams have a valuable tool to help ensure that their data is being proactively monitored and protected, and that they can identify and recover any data that may have been compromised.”
Timo Fischer
System Architect, Campus Computer Systems
Know which files were affected and when so you can act early.
Restore only the affected data without reverting entirely to a point-in-time snapshot.
GuardMode allows for customizable alerts, so an admin can be notified immediately in case of an attack.
Integrate with snapshots and maximize customer investments in primary storage.
Easy to set up and use, and can be integrated with existing security solutions, making it an effective addition to an overall security strategy.
Continuously monitors for ransomware-like behaviors and takes action to block it, providing proactive detection for known and unknown threats.
Get awesome support from our highly rated support team. Contact us to discuss how our secure data protection solutions address your enterprise and cloud data protection needs, including filling any gaps you have.
Request Demo