Advice Request Avast Hardened Mode/Aggressive -- how reliable is whitelist?

Please provide comments and solutions that are helpful to the author of this topic.
Status
Not open for further replies.

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Forum Veteran
Jul 3, 2015
8,148
1
31,237
8,388
Middle Earth
Does Avast do a good job at keeping malware, adware etc out of the whitelist that governs hardened mode/aggressive?
In addition to enabling Avast hardened mode/aggressive, I have disabled wscript and cscript.
Does this give me an effective default/deny setup?
 
Does Avast do a good job at keeping malware, adware etc out of the whitelist that governs hardened mode/aggressive?
In addition to enabling Avast hardened mode/aggressive, I have disabled wscript and cscript.
Does this give me an effective default/deny setup?
Do they have any "file intelligence" service?
Search with a hash to see the file whitelisted or not, so we can check our samples that site.

(ex. https://file-intelligence.comodo.com/ )
 
Another question, with such feature (Hardened mode).. Avast blocks files if they are not in whitelist.
We submit malwares to blackist...
How can we submit files for whitelisting? Submitting them as false positive work?
 
if there is no connection.. then all files blocked? I do not think so, there must be a local cache for this..
I guess -
1. File run offline - Allowed
2. File run online & blocked by Hardened Mode - if you run the file again offline...blocked by Hardened Mode. Guess cache is not saved i.e after system restart...1 & 2

Test & see...
 
I tested it.
It only blocks if there is internet connection.
after a reboot, it forgets that the file was once blocked, unless internet connection is renewed.
 
RejzoR,

Hardened Mode only works with .exe, right?
Any info it will work with other extensions too i.e are they working on it?
 
  • Like
Reactions: Venustus
When avast! is offline, Hardened Mode (Aggressive) still relies on digital signatures and internal whitelists that are supplied via definitions. The extent of these is not known exactly.
Do you know if Avast still has this problem(don't know if that is the correct word, since this could be what they wanted)?
Regarding the Avast Aggressive Hardened Mode
 
  • Like
Reactions: Venustus
I haven't tested Hardened Mode in such specific details, I suggest that guy talking to avast! team directly on avast! forums (or get Vlk over here).

Aggressive mode is default deny with offline exception apparently (and some problems differentiating behavior online and offline, at least back then).

Moderate mode depends heavily on file characteristics. If file looks suspicious to local recognizer, you'll get a warning, regardless whether you're online or offline. It's why Aggressive, despite the name often actually makes less unnecessary popups.
 
Status
Not open for further replies.