# Crowdsec workflow against ransomeare or file hash integrity detection

**URL:** <https://discourse.crowdsec.net/t/crowdsec-workflow-against-ransomeare-or-file-hash-integrity-detection/616>\
**Category:** crowdsec\
**Created:** [February 12, 2022, 7:15pm UTC](https://discourse.crowdsec.net/t/crowdsec-workflow-against-ransomeare-or-file-hash-integrity-detection/616 "2022-02-12T19:15:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tbaror](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/tbaror/32/291_2.png) [@tbaror](https://discourse.crowdsec.net/u/tbaror)\
**Post date:** [February 12, 2022, 7:15pm UTC](https://discourse.crowdsec.net/t/crowdsec-workflow-against-ransomeare-or-file-hash-integrity-detection/616/1 "2022-02-12T19:15:45Z")

</div>

Hello,

I wonder if its possible to implement ransomeware or file integrity hash modification added check etc… workflow detection, if such scenario is possible with Crowdsec?

Thanks

---

<div class="post-metadata">

**Author:** ![klausagnoletti](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/klausagnoletti/32/201_2.png) [@klausagnoletti](https://discourse.crowdsec.net/u/klausagnoletti)\
**Post date:** [February 15, 2022, 9:00pm UTC](https://discourse.crowdsec.net/t/crowdsec-workflow-against-ransomeare-or-file-hash-integrity-detection/616/2 "2022-02-15T21:00:48Z")

</div>

For clarity, this was also asked on Discord 🙂 But to repeat: Right now it’s not supported. It’s a bit far from the original idea (which is reading and parsing logs) so if it comes it’s not going to happen anytime soon.
