Advice Request CIS 10 Config: Default or Proactive?

Please provide comments and solutions that are helpful to the author of this topic.

Status
Not open for further replies.

vivid

Level 5
Verified
Dec 8, 2014
206
the explanations offered were a bit cryptic, but the consensus seems to be that proactive config has some nice security features
Nevertheless, many users are happy with firewall config.
So at the end of the day, it's a matter of personal choice.
Not really that cryptic (to me). If you have any other question, I'll try to answer. I can also prove what I write.
 

Rengar

Level 17
Thread author
Verified
Top Poster
Well-known
Jan 6, 2017
835
Not really that cryptic (to me). If you have any other question, I'll try to answer. I can also prove what I write.
I have a question @vivid : i downloaded CIS version 4 on a VM and i run some ransomwares. Also the product couldnt take updates due to the fact that is pretty old. Apparently the auto sandbox blocked all the malware. How do you explain that?
 

Davidov

Level 10
Verified
Well-known
Sep 9, 2012
470
I have a question @vivid : i downloaded CIS version 4 on a VM and i run some ransomwares. Also the product couldnt take updates due to the fact that is pretty old. Apparently the auto sandbox blocked all the malware. How do you explain that?[/QUOTE cis 4 or 10 AutoSandbox works just the same and unknown things start up in the sandbox because it is also a zero day protection. In this case sandboxed cryptolocker it's still just a program code.
cis 4 or 10 AutoSandbox works just the same and unknown things start up in the sandbox because it is also a zero day protection. In this case sandboxed cryptolocker it's still just a program code.
 

vivid

Level 5
Verified
Dec 8, 2014
206
If I remember correctly, (with version 4) Sandbox is focused on restriction and not virtualization. I'm not surprised that version 4 is decent. However, version 10 is better from prevention of view. This discussion is similar to why protection scores are better with HIPS and protection scores are lower with Sandbox.
Another point (which is probably an advantage compared to version 10) is that older versions employ execution control. That way, you have HIPS capabilities designed for insecure DLL loading and other examples. This feature was removed with newer versions along with buffer overflow prevention (not really removed but design was changed significantly and it doesn't do what users expect; it should be renamed in my opinion). Given explanation on why they removed is that it caused trouble. Execution control was really nice for HIPS power users.
 
Last edited:

Rengar

Level 17
Thread author
Verified
Top Poster
Well-known
Jan 6, 2017
835
Version 10 is way superior compared to version 4 in terms of auto-sandboxing.
Of course, it is better to get the new version is optimized for the new systems and corrected some old bugs
Thanks and of course i will dont download and older version, i download version 4 on VM just for testing nothing more :)
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
the autosandbox function does not need updated sigs to work. It will block by default anything that does not appear on the whitelist, no matter how old the whitelist may be.

Only the AV component needs updated sigs in order to work right.
 

cruelsister

Level 43
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
Shmu- About the configuration difference between Firewall Security and Proactive Security: it's kinda-sorta both complicated and boring to get into, but as a rule of thumb if you use the default Firewall Security config you MUST keep the HIPS on, even with the sandbox at the max. With Proactive this is not the case.

I'll be (finally) releasing a CF10 setup video on the 28th and have included a malware file that I coded which should make this point rather clearly.
 

radek178

Level 1
Apr 29, 2016
7
T The really important thing to do is enable the sandbox at either the Restricted or Untrusted (if you are an old hand) level. If you really want to have an AV, go with something like Qihoo or Avast for local scans.

I have a question. My English is not good, I am sorry. I have win 10 64b, CF 10 and I use settings for sandboxed files as UNTRUSTED. How difference is between RESTRICTED and UNTRUSTED? I have HIPS ON.

And another question is about AV. I want use some AV solutions. I used Avast with CF 8 and I had some problems. I switched to Quihoo but there are other problems - Quihoo does not work properly under user account. I need some AV for my Win with CF 10.

And latest question is about possible conflict between HIPS from CF and Avast. Will be work without problem or how settings can I use?
 

Davidov

Level 10
Verified
Well-known
Sep 9, 2012
470
Shmu- About the configuration difference between Firewall Security and Proactive Security: it's kinda-sorta both complicated and boring to get into, but as a rule of thumb if you use the default Firewall Security config you MUST keep the HIPS on, even with the sandbox at the max. With Proactive this is not the case.

I'll be (finally) releasing a CF10 setup video on the 28th and have included a malware file that I coded which should make this point rather clearly.
Already it's waiting .-)) (Perhaps there will be some configuration that we forget good day.)
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Shmu- About the configuration difference between Firewall Security and Proactive Security: it's kinda-sorta both complicated and boring to get into, but as a rule of thumb if you use the default Firewall Security config you MUST keep the HIPS on, even with the sandbox at the max. With Proactive this is not the case.

I'll be (finally) releasing a CF10 setup video on the 28th and have included a malware file that I coded which should make this point rather clearly.
looking forward to it, too. You could add the boring and complicated stuff as an addendum named "boring and complicated", so as not to spoil your drama movie...
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top