BehaviorGuard: A Host-Based Behavioral Ransomware Detection and Automated Containment System Using Wazuh SIEM and Microsoft Sysmon
Abstract
Ransomware remains one of the most disruptive cyber threats facing organizations globally. Modern families including LockBit 3.0, ALPHV/BlackCat, Akira, and Cl0p employ polymorphic code, fileless execution, and living-off-the-land (LOLBin) techniques that defeat traditional signature-based defenses. BehaviorGuard is an integrated host-based behavioral ransomware detection and automated containment system built on Wazuh 4.14 SIEM and Microsoft Sysmon v15. Twenty-one custom detection rules covering nine MITRE ATT&CK techniques across eight tactics detect behavioral indicators including bulk file encryption, Volume Shadow Copy (VSS) deletion, Windows Defender tampering, registry persistence, and canary file modification. A multi-stage temporal correlation engine escalates individual indicators to high-confidence alerts, triggering automated host isolation, process termination, outbound connection blocking, and email notification via AWS SNS. Controlled simulations on a live Windows 11 endpoint validated the pipeline: burst detection latency of 4.86 ± 0.42 s (95% CI: [4.34, 5.38], N=5), automated containment under 3 s, 100% host isolation success across five repeated runs, and an F1-score of 0.974 across a 20-run evaluation using ransomware-inspired behavioral profiles. The implementation is openly released at https://github.com/opennets/wazuh-ransomware-detection (MIT License).