Blog/Security

What EDR actually does when ransomware lands

September 28, 2026·4 min read·Cyber Alamo

Ransomware doesn't start with your files encrypting. That's the finale. The show starts days earlier, quietly, with one machine doing slightly weird things — and whether you end up having a bad Tuesday or a bad quarter comes down to whether anything notices the weird phase.

Antivirus checks the guest list. EDR watches behavior.

Traditional antivirus is a bouncer with a photo book: if a file matches a known-bad picture, it gets blocked. Modern attackers don't bring known files. They use your own tools — PowerShell, remote-access software, valid stolen logins — so there's nothing in the photo book to match. EDR, endpoint detection and response, ignores the guest list and watches what everyone does once inside: which programs launch which, what touches system settings, who is suddenly renaming ten thousand files at machine speed.

The sequence, step by step

Here's the pattern EDR is built to catch, in roughly the order it happens:

  • A booby-trapped file or a phished login gives the attacker a foothold on one PC
  • Office spawns PowerShell — something your bookkeeper's laptop essentially never does legitimately
  • Shadow copies get deleted — Windows' built-in restore points — so recovery gets harder
  • The intruder probes the network for other machines and, pointedly, for the backup server
  • Then, often at 2 a.m. on a weekend, mass encryption begins

Each of those steps is a behavior, not a file. Good EDR scores the chain as it builds, and when it crosses a line it can isolate the machine — cut it off from the network in seconds — so one infected laptop stays one infected laptop instead of becoming your whole office. Some platforms can also roll back changes the malware made. Can is doing real work in that sentence; none of this is magic, which is exactly why the alert needs to reach humans.

From the owner's seat, a good catch is an anticlimax: one machine goes dark, one employee grumbles about being kicked off the network, and Tuesday otherwise proceeds. That is the entire product. The disasters you read about are usually the same story minus the isolation step.

The tool is half. The 2 a.m. human is the other half.

An EDR alert at 2 a.m. on a Sunday is only useful if someone is awake to act on it. That's the difference between buying software and having a 24/7 SOC — analysts who see the isolation trigger, confirm what happened, cut the attacker's access, and start cleanup while you're asleep. And behind all of it sit tested backups, because the honest answer to what if it gets through anyway should never be we're not sure. Attackers plan around backups now — it's why they hunt the backup server on the way in, and why yours should live somewhere a compromised network can't reach.

Cyber Alamo's core plan puts EDR on every machine, a 24/7 SOC behind every alert, and restore-tested backups behind everything — $189–$229 per endpoint per month, flat. If your current answer to what's protecting your computers is some antivirus, book the free assessment and we'll tell you, in plain English, exactly what would happen to you at step two.

Want this handled for you?

Free assessment. Straight price. One accountable team.

Book it

Ready to stop
worrying about IT?

We manage it properly so you don't have to. Start with a free, no-obligation assessment of your current setup.

One team. One bill. Everything managed.

AlmaCyber Alamo — AI front desk
Online
Hi! I'm Alma, Cyber Alamo's AI front desk. Ask me about pricing, what's included, or whether we cover your city — or I can point you to a free assessment.
Book a free assessment →