Reducing False Positive Potential Ransomware Attack Email Alerts

Overview

This article explains how to reduce frequent false positive email alerts for Potential Ransomware Attack detections generated by Lepide Data Security Platform (LDSP).

These alerts may be triggered during legitimate file operations, backup activities, antivirus scans, or other automated processes that result in multiple file or folder rename operations within a short period.

Symptoms

  • Frequent email alerts with the subject Potential Ransomware Attack.

  • Alerts are generated from legitimate file servers or trusted user accounts.

  • No actual ransomware activity is observed on the monitored systems.

  • Alert notifications become excessive, making it difficult to identify genuine security incidents.

Cause

The default ransomware alert threshold may be too low for the customer's environment. Environments with frequent file rename operations, automated jobs, or high file activity can generate false positive alerts.

Resolution

Create a dedicated ransomware alert for the file servers and configure an appropriate threshold based on the customer's environment.

Step 1 – Create a Separate Alert

  • Open the Lepide Data Security Platform console.

  • Navigate to Predefined Alerts.

  • Create a new alert for Potential Ransomware Attack.

  • Configure the alert to monitor only the required File Servers.

Step 2 – Configure the Threshold

Set the alert threshold for:

  • File and Folder Renamed

  • Threshold: 1 event in 10 minutes

Note: The threshold should be adjusted according to the customer's environment and the normal volume of file activity. Customers with higher file operation rates may require a higher threshold to minimize false positive alerts while still detecting suspicious behavior.

Step 3 – Save the Alert

  1. Save the new alert configuration.

  2. Monitor the alert frequency over the next few days.

  3. Fine-tune the threshold if required.

Best Practices

  • Create separate ransomware alerts for file servers instead of using a single alert for all monitored systems.

  • Review normal file activity before defining the threshold.

  • Increase the threshold gradually if false positives continue.

  • Periodically review alert configurations as the environment changes.

Expected Result

  • Significant reduction in false positive Potential Ransomware Attack email alerts.

  • Genuine ransomware-like activity continues to be detected.

  • Alert notifications become more meaningful and easier to investigate.

Additional Notes

The recommended threshold of 1 file or folder rename event within 10 minutes is a starting point and should be customized based on the customer's operational requirements and expected file activity.