- Jan 6, 2022
- 520
Yes indeed.Have you verified/tested that Kaspersky does handle and stop exploits?
Yes indeed.Have you verified/tested that Kaspersky does handle and stop exploits?
Hitman pro is now outdated/obsolete.Hi @Kongo ,
As I remember it, HitmanPro Alert does not have any options to add other programs to be protected, it only protects the few things it has built in, mainly browsers. But I may be wrong.
Since im curious: Do you have any examples of what it's blocked?Won't catch everything but it will catch exploits from your team.
Have you verified/tested that Kaspersky does handle and stop exploits?
It's great to be in your shoes.I've setup windows xp laptops for fun and still red teams were rage quitting
Advice isn't free. I hope you succeed in your project.Hi @Sandbox Breaker ,
It's great to be in your shoes.
Unfortunately my red team don't know the word 'quit'.
Since we are talking about firewalls, what do you think of this config: Setup Idea - Default Deny Windows Firewall setup How To
There Are other layers in my defenses. But the whole point of this test is to test the abilities of OpenEDR and it's included Comodo Internet Security. I don't like Comodo's firewlall policy and have replaced with the above and added MalwareBytes' Anti-exploit. But I have kept their other protections. And their sales person is pitching me to upgrade to their 'advanced' package. I queried their support about the ability to detect and stop Metasploit's shell Meterpreter on friday, they have kicked the query to the advanced team, but they haven't responded yet.
Well, I look at it this way - at my age, if you don't teach, you are going to take it to your grave, or forget half of it after you retire. You just take walks with your dog and watch TV. Unless you plan to go back to school and get that Masters degree to keep your mind young. That's should not be taken to mean that my advice is always the best approach.Advice isn't free
I don't know your age. I'm sure others will help.Well, I look at it this way - at my age, if you don't teach, you are going to take it to your grave, or forget half of it after you retire. You just take walks with your dog and watch TV. Unless you plan to go back to school and get that Masters degree to keep your mind young. That's should not be taken to mean that my advice is always the best approach.
Business protection (besides Adaptive Anomaly Control) doesnt differ from the home protection - according to someone who I talked to understands K alot.Hi @Rita , That was an interesting video. Thanks.
However, it shows the Kaspersky for Server edition. I have heard different things about protections offered by different editions of a product. Some say that the same protection is available in all editions. Some say you have to specifically buy a certain edition to get a certain protection feature. I tend to believe the latter. What does everybody have to say about that?
In my case, I have Kaspersky Premium.
Anyways, the red team test their tools against common AV's before deploying them. So the chances are great that Kaspersky will fail.
Hi @Victor MHi @Rita , That was an interesting video. Thanks.
However, it shows the Kaspersky for Server edition. I have heard different things about protections offered by different editions of a product. Some say that the same protection is available in all editions. Some say you have to specifically buy a certain edition to get a certain protection feature. I tend to believe the latter. What does everybody have to say about that?
In my case, I have Kaspersky Premium.
Anyways, the red team test their tools against common AV's before deploying them. So the chances are great that Kaspersky will fail.
You probably already know this, but please make sure you disable the option "Automatically deactivate after 10 minutes of system idle" in CyberLock Settings / Basic tab prior to the red team testing. CyberLock is designed to protect the endpoint while the user is engaging in risky activities, so we left this option on by default. We should probably automatically disable this option after 2-4 weeks, or prompt the user to see if they would like to disable this option at that time. Also, please remember when testing CyberLock, to reset the whitelist when retesting a certain attack.Hi @SpyNetGirl ,
We meet again. My other layers of protection currently on that box is some hardened/disabled services, SRP, and some group policy items. The main defenses are Comodo's Internet Security which is packaged and free from OpenEDR, and Cyber Lock. This configuration is deployed because I want to test out the recommended configuration of OpenEDR. The Cyber Lock piece is a protection that I always deploy so I left it on.
I tried to deploy MS Security Baseline also but it conflicts with Comodo - system won't boot. I think it is due to one group policy item which disallows turning off Windows Defender. I will try again tomorrow and disable that item and see if that works.
Does it take a long time to understand how to use your hardening?