Skip to main content

Restore data from ONTAP ARP snapshots after a ransomware attack

Contributors netapp-dbagwell netapp-ahibbard netapp-aherbin netapp-aaron-holt

Autonomous Ransomware Protection (ARP) creates snapshots named Anti_ransomware_backup when it detects a potential ransomware threat. You can use one of these ARP snapshots or another snapshot of your volume to restore data.

About this task

If the volume has SnapMirror relationships, manually replicate all mirror copies of the volume immediately after you restore from a snapshot. Not doing so can result in unusable mirror copies that must be deleted and recreated.

To restore from a snapshot other than the Anti_ransomware_backup snapshot after a system attack was identified, you must first release the ARP snapshot.

If no system attack was reported, you must first restore from the Anti_ransomware_backup snapshot then complete a subsequent restoration of the volume from the snapshot of your choosing.

Steps

You can use System Manager or the ONTAP CLI to restore your data.

Restore after a system attack
  1. To restore from the ARP snapshot, skip to step two. To restore from an earlier snapshot, you must first release the lock on the ARP snapshot.

    1. Select Storage > Volumes.

    2. Select Security then View Suspected File Types.

    3. Mark the files as "Potential ransomware attack".

    4. Select Update and Clear Suspect File Types.

  2. Display the snapshots in volumes:

    Select Storage > Volumes, then select the volume and Snapshot Copies.

  3. Select Menu options icon next to the snapshot you want to restore then Restore.

Restore if a system attack was not identified
  1. Display the snapshots in volumes:

    Select Storage > Volumes, then select the volume and Snapshot Copies.

  2. Select Menu options icon them choose the Anti_ransomware_backup snapshot.

  3. Select Restore.

  4. Return to the Snapshot Copies menu, then choose the snapshot you want to use. Select Restore.