Here's what deserves your attention:
Unusual PowerShell, WMI, or remote admin tool activity
Attackers love tools that already live inside Windows, like PowerShell, WMI, and PsExec, because they let malicious activity hide in plain sight. These tools are common in everyday admin work, which makes them a perfect cover for ransomware operators trying to move quietly. Watch for PowerShell commands that download files, disable logging, or execute encoded or obfuscated scripts. Pay close attention to WMI being used to run commands across systems, especially if that behavior is new for the endpoint or user. If these tools suddenly light up on machines where they're rarely used, or start running after hours, don't shrug it off. That "normal admin activity" could be an attacker getting ready to make a much bigger move.
Unexpected access to file shares or backup systems
Before ransomware operators encrypt anything, they usually go hunting for the good stuff: file shares, sensitive folders, and backup repositories. The goal is simple: steal or encrypt what matters most, then make recovery as painful as possible. Look for accounts accessing shares they don't normally touch, mass file access across multiple folders, or login attempts to backup servers and management consoles from unfamiliar accounts or devices. Any strange activity around backups deserves immediate attention. If attackers can tamper with recovery options, they can turn an incident into a full-blown business interruption.
Unusual account activity
Ransomware operators don't always need malware to get started. Sometimes, all they need is a valid username and password. Watch for logins at odd hours, accounts accessing systems outside their normal routine, or sudden spikes in failed authentication attempts. These can be early signs that an attacker is testing credentials, escalating access, or preparing to move laterally. When a trusted account starts acting untrusted, treat it like a warning shot.
Unexpected use of remote access tools
Legitimate tools like RDP, AnyDesk, or TeamViewer are also ransomware operators' favorite means of moving through environments. If you're seeing remote desktop sessions you didn't authorize or new remote access software installed on endpoints, treat it as a red flag.
Disabled or modified security tools
Before deploying ransomware, attackers frequently try to blind your defenses. This means tampering with antivirus settings, disabling logging, or stopping security services. If your endpoint protection tool suddenly goes quiet on a machine, or alerts show a service was manually stopped, don't assume it's a glitch.
New admin accounts or privilege escalation
Once attackers get in, they often look for ways to stay in. Creating new admin accounts or elevating existing users gives them more freedom to move, spread, and return later. Unfamiliar admin accounts, sudden group membership changes, or privilege increases that nobody on the IT team approved should be treated as serious warning signs. If you can't quickly explain who created the account and why, assume it needs investigation.