Skip to content
Open access

BehaviorGuard: A Host-Based Behavioral Ransomware Detection and Automated Containment System Using Wazuh SIEM and Microsoft Sysmon

Sep 2026 · Journal of Artificial Intelligence and Technological Development · 0 citations · 2 references

Abstract

Ransomware remains one of the most disruptive cyber threats facing organizations globally. Modern families including LockBit 3.0, ALPHV/BlackCat, Akira, and Cl0p employ polymorphic code, fileless execution, and living-off-the-land (LOLBin) techniques that defeat traditional signature-based defenses. BehaviorGuard is an integrated host-based behavioral ransomware detection and automated containment system built on Wazuh 4.14 SIEM and Microsoft Sysmon v15. Twenty-one custom detection rules covering nine MITRE ATT&CK techniques across eight tactics detect behavioral indicators including bulk file encryption, Volume Shadow Copy (VSS) deletion, Windows Defender tampering, registry persistence, and canary file modification. A multi-stage temporal correlation engine escalates individual indicators to high-confidence alerts, triggering automated host isolation, process termination, outbound connection blocking, and email notification via AWS SNS. Controlled simulations on a live Windows 11 endpoint validated the pipeline: burst detection latency of 4.86 ± 0.42 s (95% CI: [4.34, 5.38], N=5), automated containment under 3 s, 100% host isolation success across five repeated runs, and an F1-score of 0.974 across a 20-run evaluation using ransomware-inspired behavioral profiles. The implementation is openly released at https://github.com/opennets/wazuh-ransomware-detection (MIT License).

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.