Hi Vikram Singh
FSRM’s default pattern matching logic only looks at the last extension segment, so .pdf.crypto slips through because it treats .crypto as the only extension. To tighten this up, you can switch to custom pattern matching using wildcards or regex‑style filters. For example, adding patterns like *.pdf.*crypto or *.*crypto helps catch chained extensions. Also, make sure your file screen templates are updated and applied at the correct scope (volume or path level), since older templates sometimes don’t refresh properly after edits.
If you’re running this on Server 2019 or later, you can combine FSRM with Antimalware Scan Interface (AMSI) or Defender’s controlled folder access for deeper inspection that’s usually more reliable for ransomware‑style naming tricks.
Don't forget to share your experience with "Accept the answer" . That others in community with similar issues can benefit from the guidance. Thank you!