App Review Christmas Special Test of ThreatFire 4.7 (6 years old behavior blocker!)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

RejZoR

Level 15
Thread author
Verified
Top Poster
Well-known
Nov 26, 2016
699


Born as CyberHawk, risen as ThreatFire (PCTools) and was crucified by Symantec (Norton). And yet it's still so effective even after all these years of not being maintained or updated at all.

I know it missed many recent samples, but it was still detecting plenty. And what shocked me the most was the last part of the test with ransomware. I'm pretty sure it'll shock you as well! :D

This is why I love behavior blockers and why they fascinate me so much.
 
5

509322

This is why someone, somewhere needs to develop a free True behavior blocker that works and is not bundled with something else (firewall, ect)

Please, I'm begging, and have been for years :D

Emsisoft used to have Mamutu. There were other standalone behavior blockers, but I suspect sales were not enough to support continued development or the products were purchased. I know they were not widely popular back then and there is no reason to suspect today would be any different.
 
D

Deleted member 178

Mamutu was the best BB ever made. Emsisoft was a geek vendor "all hail Online Armor ! "; best AV, best BB, Best FW/HIPS (the only FW that surpassed Comodo), and they decided to take the simplistic road with a suite to get more "average Joe" users... sadly for me , good for their finances :D
 

Antimalware18

Level 11
Verified
Top Poster
Well-known
Jan 17, 2014
503
Emsisoft used to have Mamutu. There were other standalone behavior blockers, but I suspect sales were not enough to support continued development or the products were purchased. I know they were not widely popular back then and there is no reason to suspect today would be any different.

I really wish they would. Pipe dream most likely but one can hope!

@RejZoR

I acctualy Lol'd when it caught the first few ransomwares

oh and "Holy poop" that one made me LOL as well :D

+1 from me all day long.
 

Av Gurus

Level 29
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Sep 22, 2014
1,767
I got one version and it didn't work on x64, now i find new one and it work in Win 10 x64 :)

Clipboard01.jpg
 

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,142
Hi

That was great video. Thanks

I wonder if someone can gather a few anti-ransomware software (like BD, RansomFree, MWB v3, ZAL, SBGuard etc) and do a thorough test on a broad range of ransomware with ThreatFire as an anti-ransomware. HMPA & Kaspersky would not be suitable as they only target the cryptomalware family of ransomware.

That will be great as well.

Thanks
 

Nightwalker

Level 24
Verified
Honorary Member
Top Poster
Content Creator
Well-known
May 26, 2014
1,339
Mamutu was the best BB ever made. Emsisoft was a geek vendor "all hail Online Armor ! "; best AV, best BB, Best FW/HIPS (the only FW that surpassed Comodo), and they decided to take the simplistic road with a suite to get more "average Joe" users... sadly for me , good for their finances :D

It was a necessary and a very important long time choice, if Emsisoft didnt do that they would join others vendors like TallEmu Online Armor, Ghost Security, System Safety Monitor, Geswall and finally Malware Defender.

Unfortunately BBs, third party firewalls and classical HIPS are "toys" for geeks and security enthusiasts; the majority of windows users dont care and dont want to care about those.
 

conceptualclarity

Level 21
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 23, 2013
1,076


Born as CyberHawk, risen as ThreatFire (PCTools) and was crucified by Symantec (Norton). And yet it's still so effective even after all these years of not being maintained or updated at all.

I know it missed many recent samples, but it was still detecting plenty. And what shocked me the most was the last part of the test with ransomware. I'm pretty sure it'll shock you as well! :D

This is why I love behavior blockers and why they fascinate me so much.


I have the setup file for the last ThreatFire. I'm thinking of running it on my next system.

How resource-intensive is it?

This is why someone, somewhere needs to develop a free True behavior blocker that works and is not bundled with something else (firewall, ect)

Seems like I remember a couple of years ago McAfee put out a freeware freestanding behavior blocker, but I haven't heard about it since then. Maybe it was just beta.
 

RejZoR

Level 15
Thread author
Verified
Top Poster
Well-known
Nov 26, 2016
699
Oh man, seeing this rules creator reminded me how easy it would be for avast! to create ransomware protection which they have never done...

IF application tries to WRITE access any *.jpg file (or any other file affected by ransomware) and APPLICATION X is NOT on TRUSTED LIST (which would be harnessed from their Hardened mode whitelist), BLOCK request and WARN the user.

Granted, you can hijack other processes and use them, but surely they could track if UNTRUSTED app tried to use TRUSTED app to do a specific task.

I also realized the problem here is that this trusted list isn't being updated anymore for ThreatFire which is probably the reason why its protection isn't as good as it should be.
 

Behold Eck

Level 18
Verified
Top Poster
Well-known
Jun 22, 2014
864
Everything was left at default settings.

If I remember correctly the advanced settings let you add protection for hosts,registry etc ? Plus letting it run on your system for a while before testing might give an even better result ?

Still good results from an old codger on default settings,imo.

That was a Christmas treat, thanks.;)

Regards Eck:)
 
  • Like
Reactions: Solarquest

Windows_Security

Level 24
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Mar 13, 2016
1,298

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top