> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/keeperpam/jp/endpoint-privilege-manager/policies/policy-examples/anti-ransomware-policies/gate-3-recovery-destruction.md).

# ゲート3: 復旧破壊

<figure><img src="/files/uKhk2TznNhmG7K5FGmO7" alt=""><figcaption></figcaption></figure>

**対象:** 多層のKeeper EPMランサムウェア対策ベースラインを展開するWindows管理者向けです。

***

多層ランサムウェア対策モデルの概要と、このゲートの位置づけは[ランサムウェア対策ポリシー](/keeperpam/jp/endpoint-privilege-manager/policies/policy-examples/anti-ransomware-policies.md)をご参照ください。

本ポリシーは、Windows上で多層展開するKeeper EPMランサムウェア対策における**復旧破壊ゲート**です。Conti、LockBit、BlackCat、Royal、Akira系などのランサムウェアファミリーがシャドウコピー削除、バックアップ破壊、ブート復旧の無効化、フォレンジック証拠の消去に使う代表的な破壊ユーティリティ (`vssadmin.exe`、`wbadmin.exe`、`bcdedit.exe`、`wevtutil.exe`、`fsutil.exe`、`cipher.exe`) の実行を拒否します。実行ファイル自体を標的にすることで、ディスク上の起動場所、ユーザー、対象マシンを問わずこれらのユーティリティをブロックします。

## 手順: ポリシーの作成 <a href="#step-by-step-create-the-policy" id="step-by-step-create-the-policy"></a>

{% stepper %}
{% step %}

### アプリケーションコレクションの作成

ポリシー作成前に、破壊ユーティリティをアプリケーションコレクションにまとめます。ファイル名のみのリソースは、ディスク上の場所に関係なく実行ファイルに一致し、本ポリシーの「パス非依存」の挙動を実現します。

1. Keeper管理コンソールで **\[エンドポイント特権マネージャー]** → **\[コレクション]** → **\[アプリケーション]** に移動します。
2. **\[新しいコレクション]** をクリックします。
3. **\[新しいコレクション]** モーダルで以下を設定します。
   * **タイプ**: `Applications`
   * **名前**: `Ransomware Destructive Utilities (Windows)`
   * **\[次へ]** をクリックします。
4. **\[コレクションへのアイテム追加]** モーダルで **\[リソースを手動で定義する]** にチェックを入れ、各ユーティリティをカスタムリソースとして追加します。
5. 以下を1件ずつ追加し、都度 **\[追加]** をクリックします。
   1. `vssadmin.exe`
   2. `wbadmin.exe`
   3. `bcdedit.exe`
   4. `wevtutil.exe`
   5. `fsutil.exe`
   6. `cipher.exe`
6. コレクションを保存します。コレクションのUIDを控えておきます。ポリシーJSONのインポート時に `ApplicationCheck` で参照するか、UIでポリシーを作成するときにピッカーから選択します。

<figure><img src="/files/Y0iyiEaO6V62aUH4c2su" alt="" width="235"><figcaption></figcaption></figure>

{% hint style="info" %}
`vssadmin.exe` (パスなし) として登録すると、`C:\Windows\System32`、`%TEMP%` 下にステージングしたコピー、リネームしたフォルダのドロッパー、USBメモリなど、起動場所を問わず一致します。`C:\Windows\System32\vssadmin.exe` のように登録すると、その1パスだけに一致し、ステージングされたコピーを見逃します。
{% endhint %}
{% endstep %}

{% step %}

### ポリシーの作成

1. **\[エンドポイント特権マネージャー]** → **\[ポリシー]** に移動し、**\[ポリシーの作成]** をクリックします。
2. ポリシー詳細を入力します。
   * **ポリシー名**: `Deny Ransomware Recovery Destruction (Windows)`
   * **ポリシータイプ**: `File Access`
   * **ステータス**: 初期パイロットは `Monitor`。正当な管理またはバックアップツールが一致しないことを確認したら `Enforce` に切り替えます。
     {% endstep %}

{% step %}

### DENY コントロールの追加

1. **\[コントロールを追加]** をクリックします。
2. **\[拒否]** を選択します。

<figure><img src="/files/rQWLlgsr0OrU9O7Sy9YC" alt="" width="316"><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### フィルターの設定

1. **ユーザーグループ**: **\[すべてのユーザーとグループ]** (ワイルドカード) を選択します。
2. **マシンコレクション**: Windowsマシンコレクションを選択します。特定の許可ポリシーが上書きできるベースラインにするなら **\[すべて選択]** のまま。特定ポリシー優先にするなら、名前付きWindowsマシンコレクションを指定します。
3. **アプリケーション**: 手順1の `Ransomware Destructive Utilities (Windows)` コレクションを選択します。
4. **日時範囲**は未設定のままにします。破壊的なランサムウェア活動は時間帯を問いません。

<figure><img src="/files/mOTq5UwmWePjx6qaqrWu" alt="" width="315"><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Advanced Modeでの通知設定

1. **通知メッセージ**: `This action has been blocked by Keeper EPM. The requested utility is restricted because it is commonly used to destroy backup and recovery data. Contact your administrator if you have a legitimate business need.`
   {% endstep %}

{% step %}

### 保存とパイロット

1. **\[保存]** をクリックします。ポリシーは約30分以内に適用範囲内のすべてのエンドポイントへ配布されます。影響を受けるエンドポイントのユーザーは、Keeperエージェントの **\[ポリシーを更新]** で即時同期できます。
2. **\[監視]** モードで7〜14日間運用します。**\[エンドポイント特権マネージャー]** → **\[ダッシュボード]** の監査ログで、正当な管理またはバックアップワークフローとの一致がないか確認します。
3. 監視結果に問題がなければ、**\[ステータス]** を `Enforce` に変更します。
   {% endstep %}
   {% endstepper %}

## 参考: ポリシーJSON <a href="#reference-policy-json" id="reference-policy-json"></a>

以下は完成したポリシーのエクスポート形式です。`<generated-policy-uid>` と `<uid-of-Ransomware-Destructive-Utilities-collection>` のプレースホルダーは、管理コンソールでポリシーとコレクションを作成すると自動で埋まります。

```json
{
	"PolicyName": "Deny Ransomware Recovery Destruction (Windows)",
	"PolicyType": "FileAccess",
	"PolicyId": "<generated-policy-uid>",
	"Status": "enforce",
	"Actions": {
		"OnSuccess": {
			"Controls": [
				"DENY"
			]
		},
		"OnFailure": {
			"Command": ""
		}
	},
	"NotificationMessage": "This action has been blocked by Keeper EPM. The requested utility is restricted because it is commonly used to destroy backup and recovery data. Contact your administrator if you have a legitimate business need.",
	"NotificationRequiresAcknowledge": false,
	"RiskLevel": 95,
	"Operator": "And",
	"Rules": [
		{
			"RuleName": "UserCheck",
			"ErrorMessage": "This user is not included in this policy",
			"RuleExpressionType": "BuiltInAction",
			"Expression": "CheckUser()"
		},
		{
			"RuleName": "MachineCheck",
			"ErrorMessage": "This Machine is not included in this policy",
			"RuleExpressionType": "BuiltInAction",
			"Expression": "CheckMachine()"
		},
		{
			"RuleName": "ApplicationCheck",
			"ErrorMessage": "This application is not included in this policy",
			"RuleExpressionType": "BuiltInAction",
			"Expression": "CheckFile(false)"
		},
		{
			"RuleName": "DateCheck",
			"ErrorMessage": "Current date is not covered by this policy",
			"RuleExpressionType": "BuiltInAction",
			"Expression": "CheckDate()"
		},
		{
			"RuleName": "TimeCheck",
			"ErrorMessage": "Current time is not covered by this policy",
			"RuleExpressionType": "BuiltInAction",
			"Expression": "CheckTime()"
		},
		{
			"RuleName": "DayCheck",
			"ErrorMessage": "Today is not included in this policy",
			"RuleExpressionType": "BuiltInAction",
			"Expression": "CheckDay()"
		},
		{
			"RuleName": "CertificateCheck",
			"ErrorMessage": "Certificate hash is not included in this policy",
			"RuleExpressionType": "BuiltInAction",
			"Expression": "CheckCertificate()"
		}
	],
	"UserCheck": [
		"*"
	],
	"MachineCheck": [
		"*"
	],
	"ApplicationCheck": [
		"<uid-of-Ransomware-Destructive-Utilities-collection>"
	],
	"DayCheck": [],
	"DateCheck": [],
	"TimeCheck": [],
	"CertificationCheck": [],
	"Extension": {}
}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/keeperpam/jp/endpoint-privilege-manager/policies/policy-examples/anti-ransomware-policies/gate-3-recovery-destruction.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
