I have an idea to protect Samba shares against the ransomwares.
My theory:
Ransomwares can access Samba shares, and they are able to rename and encrypt all files on it.
We can minimize the damage using fail2ban. If we use the known ransomware extensions (.locky, .aesir etc Complete list see : ) in context with fail2ban, we could filter the mailcious renaming and encrypting. If fail2ban detects one of them, it can ban the affected computer, and send an email to administrator.
Is it possible to realize ?

