in ransomware/artifact.lua [3276:3294]
function Ransomware:CanaryCheck(eventData, processData)
if true == globals.Lua_CanaryCheck(eventData) then
table.insert(processData.events, eventData)
if self.diagnosticMode then
processData.beta_alert = true
end
processData.canary_alert = true
alert.RaiseFileAlertMetric(eventData, 'CANARY_ACTIVITY')
globals.UpdateExtensionTables(eventData, processData)
alert.GenerateAlert(processData, self.diagnosticMode)
return true
end
return false
end