5
509322
Thread author
Additionally, if a macro surreptitiously downloaded a typical malicious file from the internet, upon its launch AppGuard would block it.
go for it!Awesome share hj*** I mean Jeff
Seriously though, thanks to you I am starting to take AppGuard seriously.
VS and AppGuard are looking like they may overlap some, but for me running
a Sigless Windows build, this may be worth looking at combining the powers of
the two. I think it would make for a dynamic duo
Thanks Jeff
It's working perfectly fine from my side, maybe just a problem on your side. Unless the website has difficulties earlier but was fixed already.I am getting server not found for the website
Blue Ridge Networks | Home
Any prob with the website or prob is on my side?
Maybe this can help: Video Review - AppGuard on Windows 10- An Unconventional UseHi
Can I know whether AppGuard protects during boot-time? What if a malware loads before AppGuard loads?
Thanks
HiMaybe this can help: Video Review - AppGuard on Windows 10- An Unconventional Use
Disclaimer:Hi
Thanks. So AppGuard does offers boot-time protection with limitation as given by you
Ok, thanks for the reply.Disclaimer:
About the "limitation", that was just my assumption. I'm not actually certain if what I said in that post can actually be done and that AppGuard can't prevent it.
This video surprises me because it shows the sample has been locked by the policy restrictions of AppGuard, but not because it really is 0day for what I can ascertain and the video wants to demonstrateSince AppGuard does not rely on signature detection or behavior blocker, I think that regardless of whether a file is zero-day malware or not, what the video still shows is how AppGuard prevents the infection from happening.
That's because Office files are automatically guarded (default). And so, when the files were launched, AppGuard blocked other operations that were unnecessary for these documents to do.This video surprises me because it shows the sample has been locked by the policy restrictions of AppGuard, but not because it really is 0day for what I can ascertain and the video wants to demonstrate
By the way, in the video, VT example for zeroday detection of 3rd party AV is ok to know the detection by multiple AVs BUT doesn't shows 3rd party AVs real/true/full protection mechanism result.