Serious Discussion Harmony Endpoint by Check Point

simmerskool

Level 31
Verified
Top Poster
Well-known
Apr 16, 2017
2,076
I’ve not deployed full disk encryption... Compliance and FDE are not necessary to a home user.
fwiw, ditto that was my initial thought, have not deployed full disk encryption, I'd like to have (develop) a deeper understanding of 4 defaults + firewall before going beyond.
fwiw2, yesterday or last night I noticed my cpu chugging along at 46% & 33%, and it was Harmony forensics. Not sure what it was doing, but it was doing it for awhile without any input from me.
PS when when I say Harmony feels light at keyboard, I mean the system is snappy responsive, no sense of slowdown or delay.
PS2 have not spent much time with reports yet at deployed +2.5 days, not aware of any events :) but maybe report would explain the forensics cpu load :unsure:
 

Trident

Level 28
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
1,760
@Trident Which engine did you choose between Kaspersky and Sophos?
I’ve chosen Sophos due to the reduced disk activity. Sophos divides their database in 2 parts. One part is about 250 MB and that’s modified only once a month. For the remaining 30 days it operates with 2-3 MB (copying the old one and creating a new one). It’s a very smart update mechanism. It also has cleaner detection names than Kaspersky.

It’s important to mention that Sophos engine has a very broad coverage of threats so it’s a good idea to remove the tick from “Skip archives and non-executables”.
 

simmerskool

Level 31
Verified
Top Poster
Well-known
Apr 16, 2017
2,076
I’ve chosen Sophos due to the reduced disk activity. Sophos divides their database in 2 parts. One part is about 250 MB and that’s modified only once a month. For the remaining 30 days it operates with 2-3 MB (copying the old one and creating a new one). It’s a very smart update mechanism. It also has cleaner detection names than Kaspersky.

It’s important to mention that Sophos engine has a very broad coverage of threats so it’s a good idea to remove the tick from “Skip archives and non-executables”.
A reason to tweak. Where's Waldo? I'm trying to imagine where to find that "tick" in the Infinity portal ;) Don't tell me, I need a challenge today :ROFLMAO: If I don't find it in 10 hours or so, I'll howler for help. And maybe I'll surprise myself and find it in a minute or 2... :ROFLMAO::ROFLMAO:
 

Trident

Level 28
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
1,760
Their Quantum product for the corporate environment is impressive! We can see the trickle down benefit of new security innovation to the endpoint user where small businesses and individuals will be protected from emerging zero day threats in a timely and cost-effective manner.
This innovation affects harmony as well. For example the new AI engine that blocks machine-generated domains and DNS tunnelling attacks is on the ThreatCloud, so we benefit from that as well. The Zero-Phishing is getting implemented on Quantum now but it was available prior to that on Harmony and ZoneAlarm.
 

NormanF

Level 8
Verified
Jan 11, 2018
370
This innovation affects harmony as well. For example the new AI engine that blocks machine-generated domains and DNS tunnelling attacks is on the ThreatCloud, so we benefit from that as well. The Zero-Phishing is getting implemented on Quantum now but it was available prior to that on Harmony and ZoneAlarm.

Like the new browser extension. It does two things: figure out a threat and block it and perform secure downloads. If the file allowed however, exceeds a certain size, that will be handled by your normal browser download window. I'd like to see the limitation resolved in a future update.
 

Trident

Level 28
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
1,760
Like the new browser extension. It does two things: figure out a threat and block it and perform secure downloads. If the file allowed however, exceeds a certain size, that will be handled by your normal browser download window. I'd like to see the limitation resolved in a future update.
The limitation of 50 MB was recently raised, it used to be 15. They may raise again in the future, but apart from the cloud emulation, there is a local one as well. Also, even files not downloaded through the browser or extension are sent for emulation as well.

The extension also cleans up documents from executable content, but even without the extension, they will be cleaned up as well.
 

NormanF

Level 8
Verified
Jan 11, 2018
370
The limitation of 50 MB was recently raised, it used to be 15. They may raise again in the future, but apart from the cloud emulation, there is a local one as well. Also, even files not downloaded through the browser or extension are sent for emulation as well.

The extension also cleans up documents from executable content, but even without the extension, they will be cleaned up as well.

Downloads of more than 50 MB can't be securely handled and these are usually software downloads. For example, Checkpoint's own customised software packages are in the region of 800-900 MB.
 

Trident

Level 28
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
1,760
Downloads of more than 50 MB can't be securely handled and these are usually software downloads. For example, Checkpoint's own customised software packages are in the region of 800-900 MB.
These will be handled by other components later on if they are malware. For example PrivateLoader which is inflated seems not to be a problem for CheckPoint. It is a problem for Norton, Defender and many others.
 
  • Like
Reactions: simmerskool

likeastar20

Level 8
Verified
Mar 24, 2016
373
The biggest feed provider is Kaspersky (McAfee for their business products is subscribed to Kaspersky too), second biggest is Cisco Talos (many vendors are subscribed to Cisco). Many other vendors supply certain sort of feeds, like Avast for example supplies code signatures blacklist. Other vendors provide spam emails. It’s a lot of external data in ThreatCloud.
Interesting. And for their sandbox?(You mentioned BitDefender, what else?)
 
  • Like
Reactions: Trident

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top