Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

SMB Ransomware Protection Demo: Sangfor Athena EPP

Sangfor
07/04/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


detects ransomware activity on an SMB network share and automatically blocks the compromised endpoint. Before running the simulation, we'll first make sure the protection policy is enabled. Open the Athena EPP Manager console and go to the anti-ransomware configuration page. Under ransomware protection, enable SMB-based remote ransomware protection. With the policy in place, let's move to the demo environment. In this setup, one endpoint is acting as a compromised machine. It has access to the SMB server and will be used to run a ransomware script against the network share. Here, we are logged into the SMB server, shown on the left, while the SMB share being accessed from the compromised endpoint is shown on the right. This confirms that the endpoint currently has normal access to the shared folder. Now, we'll simulate the ransomware attack. On the endpoint, the script attempts to encrypt files on the SMB network share. As soon as suspicious encryption activity is detected, the Athena EPP agent responds automatically. An alert appears on the SMB server and the endpoint is immediately blocked from accessing the share. At this point, the attack has been stopped and the affected SMB access has been cut off. Next, let's see how this incident appears from the administrator's view. Return to the Athena EPP Manager console. On the malware page, click suspicious activities to view the alerts generated by the platform. Open the relevant alert to review the detected behavior, affected asset, and recommended remediation steps. This gives administrators a centralized view of what happened and what action was taken. Now, let's check the local protection logs on the SMB server. Open the Athena EPP agent on the server. From the home page, click logs, go to real-time protection, and filter the logs by ransomware protection and ransomware activity. Here, we can confirm that the suspicious remote file activity was detected and blocked by the agent. After the incident has been reviewed, administrators can decide whether to restore access for the blocked endpoint. To do this, go to settings, ransomware protection, restore encrypted files, then select blocked IPs. This page shows the SMB connections that were blocked by the agent. Before restoring access, let's verify that the block is still active. Switch back to the endpoint and try to access the SMB server again. As expected, the SMB share is still unavailable. Now, return to the server and remove the IP block. Once the block is lifted, we'll test the connection again from the endpoint. The SMB share can now be accessed successfully. This completes the demonstration of Sanford Athena EPP's SMB anti-ransomware protection, including detection, automatic blocking, alert review, and access restoration. Thank you for watching.

TL;DR

  • Sangfor Athena EPP's SMB-based Remote Ransomware Protection detects malicious encryption attempts on network shares and automatically blocks the compromised endpoint without requiring manual intervention.
  • The Athena EPP Manager console provides centralized alert visibility, showing affected assets, detected behaviors, and recommended remediation steps for each ransomware incident.
  • Local agent logs on the SMB server can be filtered by ransomware protection category, giving administrators granular forensic detail on exactly what activity was detected and blocked.
  • After a threat is neutralized, administrators can restore SMB access by removing the blocked IP entry from the ransomware protection settings page, with connectivity verified immediately.

Summary

This product demonstration walks through the complete lifecycle of an SMB-based remote ransomware attack and shows how Sangfor Athena EPP detects, blocks, and remediates the threat in real time. The demo begins with enabling the SMB-based Remote Ransomware Protection policy inside the Athena EPP Manager console — a straightforward toggle under the anti-ransomware configuration page. From there, a simulated attack is staged using a compromised endpoint that has legitimate access to an SMB network share. When a ransomware script attempts to encrypt files on that share, the Athena EPP agent on the SMB server detects the suspicious encryption activity and immediately cuts off the attacker's network access — no manual intervention required. Administrators can then review the incident through the centralized management console, where the malware page surfaces suspicious activity alerts with details on the affected asset, detected behavior, and recommended remediation steps. Local protection logs on the agent provide an additional layer of forensic visibility, filterable by ransomware protection and ransomware activity categories. Once the threat has been reviewed and neutralized, administrators can selectively restore access by navigating to the blocked IPs list under ransomware protection settings and removing the relevant IP block — with the demo confirming that SMB connectivity is fully restored afterward. The demonstration covers the full incident response workflow from policy configuration through detection, alerting, log review, and access recovery.

Chapters

0:00 - Introduction & Overview
0:20 - Enabling SMB Protection Policy
0:35 - Demo Environment Setup
1:00 - Ransomware Attack & Auto-Block
1:31 - Alert Review in EPP Console
1:55 - Local Agent Log Analysis
2:22 - Restoring Access & Verification

Key Quotes

1:04 "The script attempts to encrypt files on the SMB network share. As soon as suspicious encryption activity is detected, the Athena EPP agent responds automatically."
1:17 "An alert appears on the SMB server and the endpoint is immediately blocked from accessing the share."
1:44 "Open the relevant alert to review the detected behavior, affected asset, and recommended remediation steps. This gives administrators a centralized view of what happened and what action was taken."
2:09 "Here, we can confirm that the suspicious remote file activity was detected and blocked by the agent."

FAQ

Does Athena EPP require manual action to block a ransomware attack on an SMB share?

No. The Athena EPP agent responds automatically the moment suspicious encryption activity is detected on the SMB network share, immediately blocking the compromised endpoint's access without requiring administrator intervention.

How do administrators restore SMB access after a ransomware block is applied?

Administrators navigate to Settings > Ransomware Protection > Restore Encrypted Files > Blocked IPs in the Athena EPP console, locate the blocked connection, and remove the IP block. SMB connectivity is restored immediately once the block is lifted.


Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Endpoint Security
  • Threat Intelligence
  • Security Operations
  • Demo
  • Getting Started
  • Data Protection
  • SMB ransomware protection
  • endpoint protection platform
  • network share security
  • ransomware detection and response
  • automatic threat blocking
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: SMB Ransomware Protection Demo: Sangfor Athena EPP

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Ensuring Compliance Through Audit Evidence: From CJIS to FERPA

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Ensuring Compliance Through Audit Evidence: From CJIS to FERPA
                      https://www.truthinit.com/index.php/channel/2159/ensuring-compliance-through-audit-evidence-from-cjis-to-ferpa/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version