- Sep 26, 2014
- 2,973
@Mahesh Sudula you last 2 lines of your latest post summits it all
i would love to see a detailed guide on how to tune it to maximum protection and hell even test it with those settings.@I.Unknown if you still considering ESET ( i know i would ) you can ask instructions
to tweak it and make it stronger from @PathFinder and @Sunshine-boy.
Both of them have very good knowledge of ESET
Totally agree i also wish to see a guide especially for Policy Mode.i would love to see a detailed guide on how to tune it to maximum protection and hell even test it with those settings.
Yes, you have to manually enter the rules. In Advanced you can also enable "log all blocked operations" so that the blocked operations will be written to the HIPS log.
Any time you use restriction policies, you need to be careful what you are adding. It is a trial and error with each different system and its applications.What about bouncer list? an ask/block rule for these processes/places:
https://excubits.com/content/files/blacklist.txt
I don't know much about registry!there are registry keys that we need to protect them! which one? i don't know
I do not use Policy mode either, as I am on a shared system. It is the only system we have and maintain. Even if this was not a shared system, I would like you, use interactive mode for the same reasons. I was merely pointing out that interactive mode is not the strongest HIPS setting, and that you could seriously limit what is crawling around on your machine with it.I don't use policy mode because I believe it generates errors and crashes(learning mode is also broken cuz it auto allow everything for a process).I prefer interactive mode which is much better than policy mode.but there is a bug in Eset hips that auto allows the operation if you don't answer the alert fast(around 45 sec).they also don't want to change the way it works!Btw Eset Hips can work as an Anti-Exe (or other executable formats).There were a lot of bugs in this hips but they fixed it and still fixing.
Eset hips is very powerfull