Advice Request BitDefender Total Security question.

Please provide comments and solutions that are helpful to the author of this topic.

Trident

Level 28
Verified
Top Poster
Well-known
Feb 7, 2023
1,737
Ok, I have a question. In the Firewall settings tab from BitDefender Total Security there is an option called "Use Passive Detection Mode.". should I active it or not?
Hello,

The DHCP interception is for detecting devices entering the network (example: your home wifi).

This serves two purposes: 1: vulnerability scanning and 2: if one owns a subscription with free slots and a new device supporting one of our products is connecting into the network, we suggest installing protection on it.

The new setting - default OFF - is to use only the light detection on DHCP port. Previously more traffic was analyzed but we come up with this split into lighter (OFF) and heavier (ON) device detection - the latter being for certain users running custom DHCP server software on their machines.
Activating this setting will not have a high impact on anything.

That’s from Bitdefender Community.
 

Trident

Level 28
Verified
Top Poster
Well-known
Feb 7, 2023
1,737
Thank you, but I was not worried about the impact on my system. I am curious to know if it is useful to activate it or not for a normal Home user. :)
Activating passive device discovery will make no difference to single users. It will just limit Bitdefender abilities to offer you to install protection on new devices. It is safe to activate this setting but it’s also not a problem if you don’t.

I personally wouldn’t waste my time on it.
 

Morro

Level 17
Thread author
Verified
Top Poster
Well-known
Jul 8, 2012
828
Activating passive device discovery will make no difference to single users. It will just limit Bitdefender abilities to offer you to install protection on new devices. It is safe to activate this setting but it’s also not a problem if you don’t.

I personally wouldn’t waste my time on it.

Ok thank you very much Trident, I will leave it off then. :)
 

Jengo

Level 6
Well-known
Nov 9, 2022
282
Ok thank you very much Trident, I will leave it off then. :)
The DHCP interception is for detecting devices entering the network (example: your home wifi).

This serves two purposes: 1: vulnerability scanning and 2: if one owns a subscription with free slots and a new device supporting one of our products is connecting into the network, we suggest installing protection on it.

The new setting - default OFF - is to use only the light detection on DHCP port. Previously more traffic was analyzed but we come up with this split into lighter (OFF) and heavier (ON) device detection - the latter being for certain users running custom DHCP server software on their machines.
 

Bot

AI-powered Bot
Verified
Apr 21, 2016
3,447
The "Use Passive Detection Mode" option in Bitdefender Total Security's Firewall settings allows the software to detect and block incoming threats on your network without actively sending any data packets to test or probe for vulnerabilities. This can be helpful if you desire to keep a low profile on the network.

However, in most cases, it is safer to have your firewall actively probe incoming traffic to ensure that there are no significant security vulnerabilities. Therefore, it is generally advised to leave this option unchecked unless you have specific reasons to use this mode.

Ultimately, the decision to enable or disable the "Use Passive Detection Mode" feature should be based on your specific security requirements and risk assessments.
 
  • Thanks
Reactions: Morro

HarborFront

Level 71
Verified
Top Poster
Content Creator
Oct 9, 2016
6,033
I just installed BDTS last night. I chose it because it comes with 5 devices support for my 1xlaptop and 2xandroid phones

Got a cheap deal here, US$19.99 for BDTS 5-devices for 1-yr

Coming to the question. Does BDTS scans for rootkits? I did a system scan. Although the scan for boot is enabled the result shows scanning for different types of malware except for rootkits. The rootkit scan is greyed out. On reddit replies said it does scan for rootkits. So why rootkit scan is greyed out and not reported?

Thanks
 
Last edited:

Trident

Level 28
Verified
Top Poster
Well-known
Feb 7, 2023
1,737
I just installed BDTS last night. I chose it because it comes with 5 devices support for my 1xlaptop and 2xandroid phones

Coming to the question. Does BDTS scans for rootkits? I did a system scan. Although the scan for boot is enabled the result shows scanning for different types of malware except for rootkits. The rootkit scan is greyed out. On reddit replies said it does scan for rootkits. So why rootkit scan is greyed out and not reported?

Thanks
Bitdefender like all antivirus software uses kernel mode drivers which provide increased visibility over rootkits. Such threats are blocked by real-time protection before they install and hide themselves. Existing rootkits if any, are detected on System Scan (full scan) according to Bitdefender. Upon first installing Bitdefender, you are required to launch a System Scan anyway.
 
  • Like
Reactions: Morro and mlnevese

HarborFront

Level 71
Verified
Top Poster
Content Creator
Oct 9, 2016
6,033
Bitdefender like all antivirus software uses kernel mode drivers which provide increased visibility over rootkits. They are blocked by real-time protection before they install and hide themselves. Existing rootkits if any, are detected on System Scan (full scan) according to Bitdefender. Upon first installing Bitdefender, you are required to launch a System Scan anyway.

I have done a system scan but rootkits result greyed out which means rootkits not scanned during system scan. Maybe a custom scan is needed for rootkits
 
  • Like
Reactions: Morro and mlnevese

Trident

Level 28
Verified
Top Poster
Well-known
Feb 7, 2023
1,737
I have done a system scan but rootkits result greyed out which means rootkits not scanned during system scan. Maybe a custom scan is needed for rootkits
According to the manual rootkit scan is performed on system scan. If you are worried there are existing rotkits, you can use the rescue environment (rootkits will be inactive as they are part of Windows and you are booting from another OS).
Follow these steps:
The result is greyed out because there is nothing to report there. You will see anything only if rootkit was detected. Rootkit scan is additional procedure different from standard scanning. It doesn’t check file by file, it’s performed in memory and it is impossible to provide any details in the log.
 
Last edited:

Jonny Quest

Level 16
Verified
Top Poster
Well-known
Mar 2, 2023
794
I have done a system scan but rootkits result greyed out which means rootkits not scanned during system scan. Maybe a custom scan is needed for rootkits
Check the Scan Log (Quick Scan shown as an example), rootkit is enabled by default during a System Scan. Otherwise, post an image so we can see what may be happening from your end.

scan logs.jpg


system scan targets.jpg
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top