Ransomware defencePre-release
RX9
Assume the ransomware gets administrator.
Attackers take administrator before they encrypt anything, because at that level most security tools can be switched off and most copies can be deleted. Backups are hunted first, for the same reason: a customer who can restore does not pay.
RX9 is built for that move specifically. Files are preserved before they are damaged, and releasing them takes an approval from your console — which nobody sitting at the compromised machine can grant, and nothing running on it can either, including whatever the attacker brought with them.
The question it answers
When the attacker has administrator, do the files come back?
Asked by: The CISO, and the cyber insurer
What is known
Every figure below carries its source. Where we have not measured something, we do not have a figure for it.
Attackers went after the backups of 94% of ransomware victims, and succeeded against more than half.
Sophos, State of Ransomware 2025Third-party, publishedMedian time from initial access to the domain controller: 3.4 hours.
Sophos, Active Adversary Report 2026Third-party, published
The driver, agent and dashboard are built and working end to end. Not generally available until the kernel-mode signing certificate is issued.