Jump to content

Hands

Members
  • Posts

    16
  • Joined

  • Last visited

Posts posted by Hands

  1. 5 minutes ago, itman said:

    Eset's API monitoring in ver. 12; part of which appears to be already implemented in 11.2.63, will put it on par with Kaspersky's System Watcher feature. I have see enough detections by Eset's advanced memory scanner(AMS) to state it is better than anything Kaspersky has.

    Also as previously commented upon, System Watcher is known for problematic behavior.

    Interesting. I’m excited to see how HIPS V12 will perform once released.

  2. 7 minutes ago, 0xDEADBEEF said:

    yes it is a behavior monitoring component (potentially combined with cloud reputation and other methods).

    The thing to keep in mind is that it is hard to distinguish malicious file modification behaviors versus legitimate ones. So to balance the detection rate and false positives, there will be weaknesses of such protection layer. And that's why multi-layer protection is important. 

    Hmmm, now I wonder how Kaspersky’s System Watcher performs so well.

  3. Well, maybe the specific module just monitors for malicious behavior directed towards the MBR. I’m just asking this because of this video I encountered where only the HIPS and Ransomware shield is being tested against various types of ransomware. ESET protects against all but Petya ransomware and lets it encrypt the Master Boot Record (MBR). I’m asking this so that the product can be improved and be better equiped to deal with this type of threat. 

     

  4. Let me be a bit more specific here: MBR encrypting ransomware like the infamous Petya variant encrypt the Master Boot Record (MBR) and gets the user to pay to unlock it. This method of ransomware encryption evades the usual tactic of just protecting/monitoring folders. Since this is a very important attack to protect against, I’m wondering if ESET has a specific module to protect against this type of attack. The image shows this type of protection module implemented in Sophos Home Premium.

    0C41E9FE-121F-4CBC-BBC2-B5D7BD316486.png

×
×
  • Create New...