Working with Enhanced Ransomware Detection

NAVIGATION  Policies

PERMISSIONS   Datto EDR subscription with administrator, analyst, or external analyst-level platform access

PERMISSIONS   Service account or administrator-level rights on the target endpoint

Overview

Datto EDR's Enhanced Monitoring feature improves ransomware detection by deploying the Datto Rollback service in a low-overhead monitoring mode. In this mode, the Rollback service supplies real-time process and file telemetry to the ransomware detection engine, enabling faster detection and more aggressive containment, without tracking file history for recovery.

What’s improved

  • Faster ransomware detection: When the ransomware process can be identified through Rollback telemetry, detection can trigger after as few as three encrypted files (compared to 10 with Standard detection), stopping attacks earlier in the encryption cycle.
  • Smarter, more aggressive containment: Terminates not only the offending process but also its parent and grandparent processes, and blocks the suspected ransomware process from restarting, minimizing blast radius.
  • Write blocking at the driver level: Suspected ransomware processes can be blocked from creating, modifying, renaming, or deleting files on disk while containment completes.
  • Improved rollback efficiency: File rollback is more targeted and configurable, allowing protection of critical folders and file types without full-disk tracking overhead.
  • Lower performance impact: Enhanced detection leverages lightweight, in-memory Rollback telemetry without significant resource usage increases.
  • Better operational control: Rollback and response actions are preserved during upgrades, ensuring no disruption to existing configurations.

Why This Matters

  • Faster recovery (lower MTTR): Quickly restore critical business files so you can get back to work sooner after an attack.
  • Less business disruption: Early detection and aggressive containment reduce file impact.
  • Practical ransomware protection: Enhanced Ransomware Detection is not a backup replacement. It complements backup solutions by addressing time-critical recovery needs.
  • Balanced security and performance: Strong ransomware protection without over-provisioning systems.

Requirements

  • You must have an active Datto EDR subscription.
  • Ransomware detection must be enabled and configured with the Enhanced option. For more information, refer to Ransomware configuration options.
  • The Datto Endpoint Security agent must be installed on all endpoints you wish to monitor and those devices must be able to communicate with your EDR instance.
  • Enhanced Ransomware Detection is supported on the same operating systems as Standard detection: Windows 10 and above and Windows Server 2012 and above.

What gets installed on the endpoint

Enhanced Monitoring is powered by the Datto Rollback service. When you enable the Enhanced detection option in your ransomware policy, the Rollback service components are deployed to all monitored, supported endpoints, even if File Recovery is set to Disable. You should expect the following components to install:

  • Kernel minifilter driver
  • Datto Rollback Driver Service (Windows service)
  • Datto Rollback Updater, Datto Rollback Status, and Datto Rollback Autorepair scheduled tasks
  • Rollback Driver Desktop application and Start Menu shortcut
  • A hidden tracking folder ($.td) in the root of each supported volume

When File Recovery is set to Disable, the Rollback service runs in a low-overhead monitoring mode. It observes file activity in memory to attribute it to processes for the detection engine, but it does not copy file data, keep file history, or consume the tracking cache. In this mode, file recovery (rollback) is not available and the Rollback Driver Desktop application will not show tracked file changes. Selecting Full Disk Tracking or Folders & Extensions enables full file tracking and recovery in addition to enhanced detection. For details about the components and their management, refer to Working with Ransomware Rollback.

NOTE  To prevent the Rollback service from installing on a specific device, refer to the "Controlling Ransomware Rollback installation" section of Working with Ransomware Rollback.

Comparing Standard and Enhanced Ransomware Detection

The following table summarizes key differences between Datto EDR’s Standard and Enhanced Ransomware Detection.

Feature Standard Enhanced
Detect file changes to alert against ransomware activity Available Available
Attribute file activity to the responsible process by using Rollback driver telemetry Not available Available
Detect attacks after as few as three encrypted files instead of 10 Not available Available
Kill suspected ransomware process Available Available
Kill parent and grandparent process of suspected ransomware process Not available Available
Block suspected ransomware processes from writing to disk and from restarting Not available Available

FAQs

 

Revision Date
Initial release. 12/17/25
Technical review against agent source: added What gets installed on the endpoint section documenting Rollback component deployment in low-overhead mode when File Recovery is disabled; corrected detection thresholds (3 vs. 10 encrypted files); corrected custom-extensions FAQ (inclusions, not exclusions); clarified OS support is the same as Standard detection; expanded Standard vs. Enhanced comparison. 8/7/26