is there any informationen if ransomware like locky also attacks the file system checkpoints (file snapshots) created by the VNX known as fileserver shadow copies aka "previous versions" in windows ?
Locky uses the Windows VSS service to delete snapshots. The VNX doesn't use Windows VSS service to manage the snapshots, only it's internal CLI. As dynamox said, they're read-only and they can't be deleted externally from the filesystem.
dynamox
11 Legend
•
20419 Posts
•
87439 Points
703
0
Posted March 2nd, 2016 04:00
snapshots are read-only, it can't touch them.