Elevate Your Egnyte Expertise. Join our Customer Community to connect with a network of peers and share game-changing strategies. Join Today

Welcome to
Help Desk

Product Updates
Training
Support
Ideas Community Contact Support

Snapshot-Based Ransomware Recovery - Overview

Within the past few years, the focus of many security teams has been shifting from pure prevention of cyber-attacks to richer detection and response/recovery capabilities. With the Snapshot-Based Ransomware Recovery tool, domain administrators can access their data on a snapshot within 15-30 minutes and recover them within minutes (for small folders) or hours (for very large folders). The snapshots of the domain's data are taken according to the following schedule:

50-Day Basic Coverage  

Age of Data Snapshot Frequency Snapshots per day
Days 0–2 Every 6 hours 4
Days 3–9 Every 12 hours 2
Days 10–30 Every 24 hours 1
Days 31–50 Once every 10 days 1 in 10 days, taken at the end of the day (UTC)

120-Day Extended Coverage  

Age of Data Snapshot Frequency Snapshots per day
Days 0–2 Every 6 hours 4
Days 3–9 Every 12 hours 2
Days 10–30 Every 24 hours 1
Days 31–120 Once every 10 days 1 in 10 days, taken at the end of the day (UTC)

For the 120-day extended coverage, customers will receive 9 snapshots between day 31 and day 120, with a 10-day interval between each snapshot.
   - For days 31–120, nine snapshots are captured, with one snapshot taken every 10 days at the end of the day. Recovery during this period is therefore limited to these snapshot points; it is not possible to recover to an arbitrary time. For example, if a file is created and deleted between two 10-day snapshots, it will not be available in the extended snapshots.
   - The snapshots are retained on a sliding 120-day window. As a result, the oldest available snapshot is always between 111 and 120 days old. The minimum guaranteed look-back is 111 days, while the maximum is 120 days.
 
Similarly, for the 50-day coverage, customers will receive 2 snapshots between day 31 and day 50, with a 10-day interval between each snapshot. The snapshots are retained on a sliding 50-day window. As a result, the oldest available snapshot is always between 41 and 50 days old. The minimum guaranteed look-back is 41 days, while the maximum is 50 days.

- The 50-Day Basic Coverage is included with the Platform Enterprise plan and GxP with Governance Plan. The 50-Day Basic Coverage is also available as an add-on for Platform Business and Enterprise Lite plans. 

- The 120-day extended snapshot coverage is available for customers having the Ultimate plan.
Contact your account manager or Egnyte Sales team for more information.

 

Skip Ahead to...

Mounting a Snapshot

Remounting a Snapshot

Browsing Files on the Mounted Snapshot

File Preview or Download

Restoring Folders and Files From a Snapshot

Additional Resources

 

Mounting a Snapshot

A domain admin can mount a snapshot by selecting one of the available snapshots and then clicking on Mount snapshot.

On the next pop-up, the admin can specify the name of the preview and the reason for it (the most common cause is Recovery from Ransomware attack) and then click the Mount button.

WebUI_Snapshot Ransomware_2.png

Although rare, sometimes links and permissions may not be available in the snapshot to restore. If users plan to move existing files to a different location before restoring content from the snapshot, they can mount it but may lose links and permissions. This constraint doesn't apply if restoring content to the same location. However, it's recommended not to mount such a snapshot

It will take 15-30 minutes (and usually less than that) to mount the snapshot - the status will change from Mounting to Mounted. Also, the system will send emails when the mounting process begins and the snapshot is ready for preview.

WebUI_Snapshot Ransomware_3.png

Remounting a Snapshot

The user will also have an option to remount an already unmounted snapshot provided no other snapshot is already mounted or being mounted.  From the history table, the user can click on the three dots and then the Remount option from the context menu.  

WebUI_Snapshot Ransomware_4.png

Browsing Files on the Mounted Snapshot

One can click on the Preview button from the currently mounted snapshot tile.

WebUI_Snapshot Ransomware_5.png

That will open a Snapshot Preview that looks similar to a regular Web UI preview, but it will have a blue border around it as a reminder that it is a snapshot preview, not the regular domain preview:

image7.png

File Preview or Download

An admin can preview or download files on a snapshot to double-check that these are the file versions that are needed to be restored:

Snapshot-Based Ransomware Recovery-3.png

File Preview or Download-2.png

Restoring Folders and Files From a Snapshot

To restore folders and files from a snapshot, the admin can select specific folders and then select More actions ->Restore in the context menu for the folder (file):

Snapshot-Based Ransomware Recovery-1.png

  • The user can now restore up to 10 folders in a single restore job. However, there is no limit on the number of files being selected for restoration.

  • The user can also have up to 3 concurrent restoration jobs in progress.

Based on the reason selected at the time of mounting the snapshot, the mechanics of restoration will be slightly different. 

When restoring the content from the snapshot that was mounted with the reason Recovery from Accidental deletion, the latest version of the deleted file will be restored along with the associated links and permissions. The user will be informed accordingly, as shown below before they choose to restore the content.

WebUI_Snapshot Ransomware_6.png

When restoring the content from the snapshot that was mounted with the reason Recovery from Ransomware attack or Other, the user will have two options as shown below.  

image12.png

In case of a ransomware attack, depending on the ransomware type, the admin might have experienced a situation when the existing files are encrypted by ransomware. For that situation, the default and recommended option is to Restore files to the same location. The links to the files, comments, folder permissions, etc., are kept intact with this option.

There might be a situation when ransomware deletes the existing files (so that the files are in Trash now) and creates new files (with cryptic names) in the folder. In this case, it is better to select the option to move all the existing files to a different location before restoring them. That will rename the original folder and restore the files into a folder under the original path.

Currently, the snapshots do not contain comments, custom metadata, workflows, etc. They will not be restored when the "Move all the existing files to a different location before restoring them to the same location" option is selected. The files, folders, links, and permissions will be restored.

Once the restoration begins, the user will be presented with the confirmation as shown below.

 

image10.png

Users can track the Restoration jobs as shown below. 

Users can also get more details about a specific restoration job by clicking on the restoration job as shown below.

image13.png

Sometimes while restoring the files using the option, Restore files to the same location, it may happen that after restoring the files the number of files exceeds the limitation of 50k files per folder and in that case, the restoration job may fail or complete with errors.  In such occurrences, the user can select the other option as Move all the existing files to a different location before restoring them to the same location

Note that you may not see this option Move all the existing files to a different location before restoring them to the same location to restore the content if you had mounted the snapshot with the reason Recovery from Accidental deletion.  In this case, you will need to unmount the snapshot and then mount it again for a different reason.

Limitations

  • The Trash is not included in the snapshot, and hence it cannot be restored.  For additional information regarding files and folders in Trash, please see here.
  • The file comments, custom metadata and workflows are not included in the snapshot, and hence it cannot be restored.
  • File versions that are directly deleted through the Version Pruning Policy cannot be restored.
    • This limitation applies only to file versions deleted before the feature is enabled. Once the feature is activated, file versions will be retained and are not subject to deletion via the Version Pruning Policy.
  • Any other entities, such as users, groups, and permissions, cannot be restored using the snapshot.

Additional Resources

Learn more about Snapshot Based Ransomware Recovery by watching a Quick Tip on Egnyte University:  Snapshot-Based Ransomware Recovery.

 

Was this article helpful?
3 out of 4 found this helpful

For technical assistance, please contact us.