# SpyShelter vs Ransim (ransomware simulator)

**URL:** https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406
**Category:** SpyShelter
**Created:** [October 6, 2025, 1:53pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406 "2025-10-06T13:53:43Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![RasheedHolland](https://forum.spyshelter.com/letter_avatar_proxy/v4/letter/r/9dc877/32.png) [@RasheedHolland](https://forum.spyshelter.com/u/RasheedHolland)
#### Post date: [October 6, 2025, 1:53pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/1 "2025-10-06T13:53:44Z")

</div>

Has anyone tested this ransomware simulator against SpyShelter?

[https://www.softpedia.com/get/Security/Security-Related/RanSim.shtml](https://www.softpedia.com/get/Security/Security-Related/RanSim.shtml)

> **[Is Your Computer Protected Against Ransomware? - Acronis](https://www.acronis.com/en/blog/posts/how-find-out-if-your-computer-protected-against-ransomware/)**
>
> Find out how to check if your computer is protected against ransomware attacks.

> **[RanSim | KnowBe4](https://www.knowbe4.com/free-cybersecurity-tools/ransim)**
>
> KnowBe4’s RanSim tests 24 different ransomware and 1 cryptomining scenario to show you if your network is vulnerable. Download now for free!

---

<div class="post-metadata">

### Author: ![RasheedHolland](https://forum.spyshelter.com/letter_avatar_proxy/v4/letter/r/9dc877/32.png) [@RasheedHolland](https://forum.spyshelter.com/u/RasheedHolland)
#### Post date: [October 6, 2025, 4:41pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/2 "2025-10-06T16:41:21Z")

</div>

To clarify, I know that SpyShelter isn’t specifically designed to protect against ransomware, but it would still be interesting to see if the behavior blocker (not the AV) would alert about certain behavior. 🙂

---

<div class="post-metadata">

### Author: ![Compound](https://forum.spyshelter.com/user_avatar/forum.spyshelter.com/compound/32/48_2.png) [@Compound](https://forum.spyshelter.com/u/Compound)
#### Post date: [October 8, 2025, 10:40am UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/3 "2025-10-08T10:40:52Z")

</div>

Did you test this yourself?

Anyway, i tried but can’t open the zip because it’s password protected… 😑

---

<div class="post-metadata">

### Author: ![SpyShelterCarl](https://forum.spyshelter.com/user_avatar/forum.spyshelter.com/spysheltercarl/32/7_2.png) [@SpyShelterCarl](https://forum.spyshelter.com/u/SpyShelterCarl)
#### Post date: [October 8, 2025, 4:13pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/4 "2025-10-08T16:13:16Z")

</div>

Please try guys (if you are familiar with testing dangerous malware and have skills to do so safely)! Let us know your results, but it’s important you are a paid user and are set to the highest security level with SpyShelter, otherwise we may not block anything at all without our highest level of security. “Paranoid”

---

<div class="post-metadata">

### Author: ![Kaliban](https://forum.spyshelter.com/user_avatar/forum.spyshelter.com/kaliban/32/29_2.png) [@Kaliban](https://forum.spyshelter.com/u/Kaliban)
#### Post date: [October 8, 2025, 4:37pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/5 "2025-10-08T16:37:24Z")

</div>

Hi Carl,

you are right to warn SpyShelter’s users but Ransim isn’t real malware, it’s a simulation test, as explained in Ransim official page, from the link posted above by RasheedHolland. I can’t test it because I don’t have SpyShelter 15, neither Free of Pro and, as far as I know, RasheedHolland has Windows 10 and SpyShelter 12 so he too can’t test it vs. SpyShelter 15

Anyway I can see that for downloading Ransim installer they ask personal datas: First Name\*, Last Name\*, Business Email\*, Company Name\*, Phone\*, Country\* and Number of Employees\* so it seems oriented to companies rather than individuals.

“ **It will test 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.**

**How RanSim works:  
100% harmless simulation of real ransomware and cryptomining infections  
Does not use any of your own files  
Tests 25 types of infection scenarios  
Just download the installer and run it  
Results in a few minutes!  
NOTE: Created for Windows-based workstations running Windows 10+. RanSim does not alter any existing files on disk. As part of the software, RanSim does enumerate all files on the local disk(s). For the purposes of encryption, simulated data files are downloaded from the Internet.**

---

<div class="post-metadata">

### Author: ![SpyShelterCarl](https://forum.spyshelter.com/user_avatar/forum.spyshelter.com/spysheltercarl/32/7_2.png) [@SpyShelterCarl](https://forum.spyshelter.com/u/SpyShelterCarl)
#### Post date: [October 8, 2025, 5:04pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/6 "2025-10-08T17:04:55Z")

</div>

I’d guess it just won’t run at all then with SpyShelter in Paranoid mode, because it probably isn’t set up to get past any security software since it’s only a “test”.

---

<div class="post-metadata">

### Author: ![Kaliban](https://forum.spyshelter.com/user_avatar/forum.spyshelter.com/kaliban/32/29_2.png) [@Kaliban](https://forum.spyshelter.com/u/Kaliban)
#### Post date: [October 8, 2025, 5:13pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/7 "2025-10-08T17:13:18Z")

</div>

It could be as you say for SpyShelter 15 but in Acronis webpage, posted above by Rasheed Holland, Ransim was tested vs Acronis Active Protection embedded in Acronis True Image 2017 New Generation and also vs a security software like Malwarebytes Premium.

Anyway it’s a simulation test so its results probably are less reliable than testing a cybersecurity software vs. real malware.

---

<div class="post-metadata">

### Author: ![Compound](https://forum.spyshelter.com/user_avatar/forum.spyshelter.com/compound/32/48_2.png) [@Compound](https://forum.spyshelter.com/u/Compound)
#### Post date: [October 8, 2025, 8:01pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/8 "2025-10-08T20:01:40Z")

</div>

There are more ransomware simulators, but the same as the one RasheedHolland posted above, they all want registration.  
I would like to test, but i don’t want to register…

---

<div class="post-metadata">

### Author: ![Compound](https://forum.spyshelter.com/user_avatar/forum.spyshelter.com/compound/32/48_2.png) [@Compound](https://forum.spyshelter.com/u/Compound)
#### Post date: [October 8, 2025, 8:06pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/9 "2025-10-08T20:06:00Z")

</div>

I found this one on github: [Releases · NextronSystems/ransomware-simulator · GitHub](https://github.com/NextronSystems/ransomware-simulator/releases)  
I don’t know if it is any good, but at least no registration 😏

AV is blocking it instantly, so it does something

[https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Ransom%3AWin64%2FGoHive.PAA!MTB&threatid=2147786531](https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Ransom%3AWin64%2FGoHive.PAA!MTB&threatid=2147786531)

can’t get past quarantine or delete, there is no option to allow somehow 🤷‍♂️

---

<div class="post-metadata">

### Author: ![Compound](https://forum.spyshelter.com/user_avatar/forum.spyshelter.com/compound/32/48_2.png) [@Compound](https://forum.spyshelter.com/u/Compound)
#### Post date: [October 8, 2025, 8:11pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/10 "2025-10-08T20:11:56Z")

</div>

> **[ShinoLocker](https://shinolocker.com/)**
>
> The safe ransomware simulator for testing/education purpose.

---

<div class="post-metadata">

### Author: ![Kaliban](https://forum.spyshelter.com/user_avatar/forum.spyshelter.com/kaliban/32/29_2.png) [@Kaliban](https://forum.spyshelter.com/u/Kaliban)
#### Post date: [October 8, 2025, 8:50pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/11 "2025-10-08T20:50:17Z")

</div>

> [@Compound](#):
>
> I would like to test, but i don’t want to register…

Hello,

Ransim is also available on the popular website MajorGeeks. In my opinion MajorGeeks is reliable but the choice is yours of course, as it’s not the official Ransim website

Here it is the link:

> **[Ransomware Simulator RanSim](https://www.majorgeeks.com/files/details/ransomware_simulator_ransim.html)**
>
> Ransomware Simulator RanSim is a vulnerability testing tool that will simulate the behavior of multiple types of ransomware to safety-check your machine for weaknesses.

Editor’s Note:  
Password is knowbe4

I guess the password is for the ZIP file

On Ransim website is available a brief manual which explains how to conduct the simulation.

[https://support.knowbe4.com/hc/en-us/articles/229040167-RanSim-Product-Manual](https://support.knowbe4.com/hc/en-us/articles/229040167-RanSim-Product-Manual)

In particular:

 ![Ransim](https://forum.spyshelter.com/uploads/default/original/1X/81fae84464652beed7be59fe3650bba0776838b9.jpeg)

So if you with to test SpyShelter 15 behavior vs. Ransim you should whitelist the above files on your antivirus.

---

<div class="post-metadata">

### Author: ![Compound](https://forum.spyshelter.com/user_avatar/forum.spyshelter.com/compound/32/48_2.png) [@Compound](https://forum.spyshelter.com/u/Compound)
#### Post date: [October 15, 2025, 10:27pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/12 "2025-10-15T22:27:22Z")

</div>

Well, i can confirm that SS definitely reacts on the simulator in para modus.  
I did not get any further then ranstart, but it was detected as a PUP and quarantined. So SS did work as expected i guess

---

<div class="post-metadata">

### Author: ![SpyShelterCarl](https://forum.spyshelter.com/user_avatar/forum.spyshelter.com/spysheltercarl/32/7_2.png) [@SpyShelterCarl](https://forum.spyshelter.com/u/SpyShelterCarl)
#### Post date: [October 16, 2025, 7:18pm UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/13 "2025-10-16T19:18:35Z")

</div>

That’s great it worked! I’m curious if our allow/deny mode will hold it also though… in cases where we did not detect it as something.

---

<div class="post-metadata">

### Author: ![RasheedHolland](https://forum.spyshelter.com/letter_avatar_proxy/v4/letter/r/9dc877/32.png) [@RasheedHolland](https://forum.spyshelter.com/u/RasheedHolland)
#### Post date: [October 27, 2025, 10:41am UTC](https://forum.spyshelter.com/t/spyshelter-vs-ransim-ransomware-simulator/406/14 "2025-10-27T10:41:33Z")

</div>

> [@Compound](#):
>
> Well, i can confirm that SS definitely reacts on the simulator in para modus.  
> I did not get any further then ranstart, but it was detected as a PUP and quarantined. So SS did work as expected i guess

> [@SpyShelterCarl](#):
>
> That’s great it worked! I’m curious if our allow/deny mode will hold it also though… in cases where we did not detect it as something.

Yes, exactly. It should be allowed to run to see if it can protect files. But now that I think of it, since SS is not designed to detect file encryption, it would be interesting to see if it can at least protect files inside protected folders like Downloads and Documents.
