Skip to content
English
  • There are no suggestions because the search field is empty.

How do I set up automated action flows for ransomware or encrypted content alerts?

 

Note: Ransomware action flows are available only for customers who have purchased the Ransomware add-on. If you don’t have the add-on enabled, contact Sales to purchase it and unlock ransomware action flows. 

Not sure what action flows are? See What are custom action flows? to learn how automated actions work. 

Step 1: Locate “Configure add-ons” in “Jobs” and enable “Ransomware”. Select “Configure” to choose the ransomware scans you want to perform. 

Step 2: Select the ransomware scan(s) you want to run on the backed-up archives. 

Step 3: Move to “Define action flows” and enable action flows for “Ransomware”. Select “Configure” to define the action flow. 

 
 

Step 4: Enter a name for the ransomware action flow. 

Step 5: Define the trigger criteria for the action flow: 

  • Detection type: Ransomware or Encrypted

  • Risk category: High, Medium, or Low 

Step 6: Define the automated action(s) to perform: 

  1. Transfer ownership / Grant access 
  2. Remove all file sharing 
  3. Remove external sharing / collaborator 
  4. Remove link sharing 

(Optional) Enable notifications to:  

  1. Admin
  2. Content owner 

Step 7: To add more action flows, select “Create new action flow” and repeat the steps above. 

Step 8: Enable the action flow by selecting “Confirm”. Once you select “Start backup”, the action flow will run based on the configured criteria and actions.