Published on September 10, 2026 · 10 min read
In May 2021, Colonial Pipeline got hit by ransomware. The pipeline shut down and gas stations across the southeastern US ran dry for days. When the details came out, the way in was an old VPN account — one that was supposed to be retired but still worked, and never had two-factor enabled.
There was no exploit. No zero-day. Just a password that shouldn't have worked anymore.
That one made headlines, but most ransomware gets in through similar gaps. Nothing very clever about it.
I've watched people spend weeks deciding which antivirus to buy, when the more useful question is simpler: how are they getting in? The three entry points below cover most of the attacks I've seen.
Remote Desktop, port 3389. It's handy — employees can log into the office machine from home. The issue is that a lot of people leave it exposed directly to the internet.
Attackers scan the whole internet for open 3389 ports and then run tools against them to guess passwords. If the password is weak, they're in within minutes.
Once inside, they don't rush. They sit there and look around — what else can this machine reach, is there a shared drive, can they get to the domain controller. That can take days, sometimes weeks. By the time anyone notices, encryption happens all at once, across the whole network instead of just one machine.
Either don't put RDP on the public internet, or add two-factor. If neither is possible, at least limit which IPs can connect. Port 3389 wide open is basically an unlocked door.
Phishing emails. Old trick. Still works.
The attachment might be a zip with an exe inside, or a Word doc that asks you to enable macros. You click, it starts.
Why does an old trick keep working? Because it goes after the person, not the system. Nobody reads dozens of emails a day without slipping up eventually. Expecting hundreds of employees to never misclick once isn't a security plan.
Relying on employee training alone to stop phishing doesn't really work. Run the training, sure — but the thing that actually catches it is mail filtering, attachment sandboxing, disabling macros, and if something does start running, behavior monitoring that shuts it down.
WannaCry, 2017. Around 200,000 machines in about 150 countries. The vulnerability it used was EternalBlue, and Microsoft had released the patch for it two months earlier. Anyone who applied the patch was fine. Anyone who hadn't was not.
The lesson is that attackers don't need to be brilliant — they just need to find the machines that haven't updated. There are scanning tools that do that search automatically.
Patching is genuinely hard in a company. A machine needs downtime, testing, a change request. IT schedules these months out. That's a management problem, not a technical one. Attackers don't care about your schedule.
"But we have backups."
This comes up every time. Backups matter, obviously. But there are plenty of cases where they don't save you:
The backup drive sits on the same network as the original data, so ransomware encrypts both together. The backup was never tested for restore, and when the day finally comes, it's corrupt or missing files. The attacker copied data before encrypting, so you can restore the files but the leaked data is already out.
Backups give you a way to recover. They don't stop the attack.
Where WinRansomProtect fits in
I built this tool with one idea in mind — not another antivirus. Antivirus relies on signatures, and the moment a new variant appears it goes blind. What matters more is behavior. Ransomware can change how it looks, but it still has to do the same things: delete shadow copies, encrypt files in bulk, mess with system settings.
That's what the protection side watches.
Take vssadmin deleting shadow copies. That's standard practice for ransomware, because it's how they make sure you can't recover. I watch that process in real time. The moment a vssadmin with a delete parameter appears, it gets terminated. PowerShell downloading and running scripts, WMIC lateral movement, scheduled task creation — same approach. Don't wait for encryption to start.
On the file side, I don't bother with extensions. By the time a file turns into .lockbit, it's already too late. What I look at is behavior: a burst of files modified in a short window, mass renames, batches of hidden files appearing, disk write rates suddenly spiking. When those cross a threshold, the process gets killed and the files get quarantined.
Then there's the system layer. Shadow copies, system time, the hosts file, critical config — these are all things ransomware has to break first. I lock them down before anything else.
The other half is 32 hardening rules — block port 445, disable SMBv1, turn off LLMNR, enable DEP and ASLR, and so on. They come from CIS Benchmarks and NSA guidance. Doing them manually is a pain. I turned them into one click.
Everything runs locally. No network calls, no uploads.
Last thing
You can't stop ransomware every time, for everyone. But most attackers aren't patient. If one entry point doesn't open, they'll move on to the next target.
Lock down these three, and you'll get further than another antivirus install would.
Try WinRansomProtect free for 14 days.
⬇️ Download Free Trial