CFW/cs - No Alerts but Actions?

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Unrecognized just when I see a number in the GUI.
This part is a bit puzzling to me. In your setup, which is based on CruelComodo, all unrecognized files should be autocontained. Indeed, you will find that file as a number in the GUI, but the first thing you should see is the program window with a green frame.
So after scratching my head for a minute, I guess you are talking about processes that don't have a visible program window, and/or processes that can't display their program window due to the restrictions of autocontainment. For them, all you will see is a number in the GUI, and you would rather see an alert of some kind.
If I got the story right, you could change the rule for unrecognized files: instead of containing them, block them. Then you should get a Windows error message, and also find a number in the GUI.
 

SearchLight

Level 13
Thread author
Verified
Top Poster
Well-known
Jul 3, 2017
626
This part is a bit puzzling to me. In your setup, which is based on CruelComodo, all unrecognized files should be autocontained. Indeed, you will find that file as a number in the GUI, but the first thing you should see is the program window with a green frame.
So after scratching my head for a minute, I guess you are talking about processes that don't have a visible program window, and/or processes that can't display their program window due to the restrictions of autocontainment. For them, all you will see is a number in the GUI, and you would rather see an alert of some kind.
If I got the story right, you could change the rule for unrecognized files: instead of containing them, block them. Then you should get a Windows error message, and also find a number in the GUI.

Ok just changed the rule in Auto-Containment for Unrecognized Files from Run Virtually to Block. I will let you know what happens. Thanks again for your support:).
 

Attachments

  • Snap 2019-07-23 at 01.02.46.png
    Snap 2019-07-23 at 01.02.46.png
    39.6 KB · Views: 333
  • Snap 2019-07-23 at 01.03.23.png
    Snap 2019-07-23 at 01.03.23.png
    7.1 KB · Views: 321

SearchLight

Level 13
Thread author
Verified
Top Poster
Well-known
Jul 3, 2017
626
How did things go with the changed settings?

Blocking was more apparent by Windows error messages upon execution but after careful consideration of the tweaking to get it right, I decided to go with another suite that I could leave on Auto and know it's working. For me, it's BDTS 2019. For the Advanced Tweakophile, CF is a dream. For less inclined, something else might be more practical.
 

SearchLight

Level 13
Thread author
Verified
Top Poster
Well-known
Jul 3, 2017
626
Yes, but for those unable to identify specific Windows processes easily it is not. This was the main reason I quit using it. It is an effective app in capable hands.

Took me a while but I totally agree with you. I miss the old Zone Alarm days, simple but effective but I am oversimplyfing a little.

For those who like, and can handle the CF challenge, I say go for it. Knowledge is power:).
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top