@SwiftOnSecurity we stoppped ransomware mostly by not allowing things to run in temp except whitelisted by group policy. We did it 10 years ago… was a pain in the beginning but so worth it! I left that company, I wonder if they are still doing it… probably not because it broke things and we documented the process but it was probably to hard for future IT folks.