We propose monotonic classification with selection of monotonic features as a defense against evasion attacks on classifiers for malware detection. The monotonicity property of our classifier ensures that an adversary will not be able to evade the classifier by adding more features. We train and test our classifier on over one million executables collected from VirusTotal. Microsoft implemented our proposed mechanism in its Defender ATP, and the technique was key in stopping the LockerGoga ransomware. The coverage links provide more information.