Catalogic Software

DPX GuardMode Product Brief

DPX GuardMode product brief: ransomware and data anomaly detection built into your backup workflow, with real-time alerts and targeted recovery. Free with Catalogic DPX.

GuardMode is ransomware and data anomaly detection software from Catalogic, included at no charge with every Catalogic DPX license. It monitors file shares and system behavior on live systems and alerts within seconds of encryption activity starting, showing exactly which files were affected and when.

Why early detection matters

Ransomware activity often runs for days before encrypted files surface, and by then the damage has usually reached your backups. GuardMode catches that activity while it’s happening, so recovery starts from yesterday’s clean files rather than a backup set that turns out to be compromised too. It complements endpoint and edge protection by watching how data behaves instead of relying on binary fingerprints, which lets it catch known and unknown ransomware strains before encrypted files ever flow into a backup.

Four detection mechanisms

GuardMode draws on a regularly updated base of thousands of known ransomware threat patterns through:

  • Yara scanning — deep on-demand scans of files for structures and patterns specific to ransomware.
  • Honeypots — decoy files planted across the environment, watched for any process that touches them.
  • Blocklist matching — known ransomware file types flagged on sight, updated from Catalogic’s threat list.
  • Pattern matching — known access patterns, signatures, and abnormal I/O thresholds detected as they occur.

Key features

  • Real-time detection and alerts within seconds of encryption starting, with recovery guidance that lets admins roll back only the affected files instead of the whole system.
  • Customizable alerting notifies admins immediately when an attack is detected.
  • Post-backup scanning checks snapshots in the DPX vStor repository, confirming which recovery point is clean before you restore from it.
  • Agents run on both Windows and Linux, with a distributed architecture that stores and analyzes events on the client independently of the server.
  • Smart processing analyzes file heuristics on active data only, keeping the event volume manageable.
  • A REST API, Syslog output, and plugin architecture support integration with SIEM and other security tooling.

Download the product brief now to see how GuardMode adds ransomware detection to your backup workflow at no additional cost.

Share this resource

Download

Secure Data Protection

Get awesome support from our highly rated support team. Contact us to discuss how our secure data protection solutions address your enterprise and cloud data protection needs, including filling any gaps you have.

Request Demo