Advice Request Best behavior blocker/0 day

Please provide comments and solutions that are helpful to the author of this topic.

ScandinavianFish

Level 7
Verified
Dec 12, 2021
317
Kaspersky's System Watcher.

Also, antiviruses does not need to monitor the behavior of an application to detect new malware, pretty much all AV's use static machine learning, Windows Defender for example use 7 different machine learning models, both local and in the cloud, to detect zero days.
 

Soulbound

Level 29
Verified
Well-known
Jan 14, 2015
1,761
Kaspersky is the most easier to use in my opinion (granted you are using KIS and up).
ESET HIPS if you decide to take some time to do some configuration, works wonders, although basic rules are decent enough for average joe.
Norton also works out of the box.
VoodooShield also has its fair share of popularity

since this thread is not just about BB but also Zero Day solutions, above 4 are my main goto's
 

Anthony Qian

Level 10
Verified
Well-known
Apr 17, 2021
453
First tier: Bitdefender ATD, Kaspersky SW

Second tier: Norton SONAR (bad protection against ransomware and some stealer), Emsisoft (no rollback), Avast IDP (inadequate protection against ransomware)

Third tier: F-Secure DG (relatively high FPs, no rollback), McAfee RP (bad protection against script, depends on Cloud)

Fourth tier: ESET DBI and RS (insensitive), Trend Micro (high FPs in hypersensitive mode, not sensitive in normal mode), Avira Sentry (insensitive to malware, produce FPs in my testing)
 

plat

Level 29
Top Poster
Sep 13, 2018
1,793
I think "behavior blocker" and HIPS (host intrusion prevention system) get confused sometimes.

I'm still evaluating real-time software that functions alongside Defender but has a tiny footprint. NVT OS Armor and VoodooShield are the two I have currently (each on a separate drive). The recent Follina episode spurred both and some others to take a closer look and make improvements.
 

Moonhorse

Level 38
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,728
I think "behavior blocker" and HIPS (host intrusion prevention system) get confused sometimes.

I'm still evaluating real-time software that functions alongside Defender but has a tiny footprint. NVT OS Armor and VoodooShield are the two I have currently (each on a separate drive). The recent Follina episode spurred both and some others to take a closer look and make improvements.


checkmall apparently uploading new videos :unsure: but i dont think that is what you are looking for
 

SeriousHoax

Level 49
Verified
Top Poster
Well-known
Mar 16, 2019
3,862
First tier: Bitdefender ATD, Kaspersky SW

Second tier: Norton SONAR (bad protection against ransomware and some stealer), Emsisoft (no rollback), Avast IDP (inadequate protection against ransomware)

Third tier: F-Secure DG (relatively high FPs, no rollback), McAfee RP (bad protection against script, depends on Cloud)

Fourth tier: ESET DBI and RS (insensitive), Trend Micro (high FPs in hypersensitive mode, not sensitive in normal mode), Avira Sentry (insensitive to malware, produce FPs in my testing)
This summed it up perfectly. Don't think anyone would disagree with this.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top