Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Ransomware protection
#1
Macrium reflect uses Image Guardian to lock images so nothing can change the image files. I don’t know how it works, if it requires a driver, how much system resources it uses, or if it’s actually needed for images stored on external disconnected ssd drive.
Are HBS backup images locked in a similar way?
Reply
#2
@zx81,

Thank you for your interest in the backup image security of Hasleo Backup Suite.

Macrium Reflect Image Guardian achieves its protection by using a kernel-mode driver to intercept application access to image files. Obviously, this does consume a small amount of system resources, but compared to the security benefits it brings, this overhead is generally negligible.

We plan to officially introduce the "Backup Image Protection" feature in the next major version of Hasleo Backup Suite. This feature will provide protection similar to Macrium Reflect Image Guardian, preventing unauthorized processes (including ransomware) from tampering with or encrypting your backup files.

If you have any further questions, please feel free to ask.

Have a nice day!

Best regards,
Reply
#3
Thank you for this information. 
How secure are these locked/protected files?
Would it be possible for someone malicious who knew what they were doing to bypass? 

I assume because it’s a driver the protection only works on the computer it’s installed on?
Locked backup images stored on an external usb SSD drive would not be protected if the drive connected to a different computer, which maybe running an O/S other than Windows.  I know that’s why backups should be encrypted, but that doesn’t stop ransomware being transferred unknowingly and the encrypted backup image being maliciously re-encrypted. Or am I just being overly paranoid as I don’t even know how prevalent ransomware actually is. Wink

How far off being released is the next major version you mentioned?
Reply
#4
@zx81,

Driver based image protection can effectively block unauthorized modifications. However, no protection is completely unbypassable in theory. For example, if an attacker gains administrator privileges, they could stop or even uninstall the driver entirely.

You are absolutely right that the driver protection only works on Windows systems where our driver is installed. When the backup drive is connected to another computer, the driver protection will not be active. For this reason, it is essential to enable encryption for important data and to physically disconnect the device once the backup is complete.

Regarding the new version, we are actively developing it, but we do not have a confirmed release date yet. This feature involves core driver development and rigorous security testing, and we must ensure it is stable and reliable.

Thanks.

Best regards,
Reply
#5
@admin,

This is great news!  I knew this feature was on the "Road Map," but I didn't realize it was being accorded priority.  This will be a very welcome enhancement to HBS by many of us. 👍

Have a great day.

Regards,
Phil
Reply
#6
@garioch7,

Yes, we have been making progress on it recently. This is our first time writing a driver, so it may take a little more time.

As I have always said, we have always been dedicating our main effort to the implementation and improvement of core features. As a result, some finer details may not yet meet everyone's expectations, which is largely due to the size of our current team.

We hope everyone can understand and bear with us.

Have a nice day!

Best regards,
Reply
#7
(08-01-2026, 10:59 AM)admin Wrote: @garioch7,

Yes, we have been making progress on it recently. This is our first time writing a driver, so it may take a little more time.

As I have always said, we have always been dedicating our main effort to the implementation and improvement of core features. As a result, some finer details may not yet meet everyone's expectations, which is largely due to the size of our current team.

We hope everyone can understand and bear with us.

Have a nice day!

Best regards,

I can understand and will certainly 'bear with you'. Nothing to 'bear' in that sense - HBS has been spectacularly good.
Reply
#8
(08-01-2026, 11:59 PM)Epictetus Wrote:
(08-01-2026, 10:59 AM)admin Wrote: @garioch7,

Yes, we have been making progress on it recently. This is our first time writing a driver, so it may take a little more time.

As I have always said, we have always been dedicating our main effort to the implementation and improvement of core features. As a result, some finer details may not yet meet everyone's expectations, which is largely due to the size of our current team.

We hope everyone can understand and bear with us.

Have a nice day!

Best regards,

I can understand and will certainly 'bear with you'. Nothing to 'bear' in that sense - HBS has been spectacularly good.

Thank you for your understanding and affirmation! The fact that HBS has earned your recognition is a great encouragement to us.
Reply
#9
(07-31-2026, 09:25 AM)admin Wrote: We plan to officially introduce the "Backup Image Protection" feature in the next major version of Hasleo Backup Suite. This feature will provide protection similar to Macrium Reflect Image Guardian, preventing unauthorized processes (including ransomware) from tampering with or encrypting your backup files.

I hope that this will be an optional install during setup like Macrium does.

I will not use this so prefer not to install the driver.

[Image: CUFx3wx.jpg]
Reply
#10
I agree that it needs to be an option as it will not be used/installed on my PC's.

If I recall correctly, when it was enabled in MR, the driver was not only installed on the source PC but if the target of a backup was on another PC the driver would be installed there as well to protect those backup files. Turning it off on the source PC did not disable it on the other. It took a while to figure this out.
Reply


Forum Jump:


Users browsing this thread: 2 Guest(s)