I’ll never get why it’s always such a mess whenever people talk about comodo...
Comodo is a dinosaur among other products. Some people like to discuss dinosaurs.
I’ll never get why it’s always such a mess whenever people talk about comodo...
It does. Still none of those default containment rules have a set time limit but agreed, default Internet security used to have much more default blocking years ago. It's always optimal to use Proactive configuration. Below are the Internet Security Auto-Containment defaults for reference.Default CIS settings use Internet Security configuration, which uses different Auto-containment rules.
It does. Still none of those default containment rules have a set time limit ...
That's confusing. I mean it was my 2nd screenshot and while it's dealing with unknown files newer than 3 days so I get that older than 3 days since last modified or copied to the system by other means not covered by the other auto containment rules, it wouldn't be sandboxed? I guess if you ran a trusted executable that launched a dormant previously not detected piece of malware that was added to the system when protections were disabled that it would then not sandbox it and it would be down to the other protection layers to catch the malware on the system but I'm presuming that script protection would still pick this up. It still doesn't quite make sense how Limit Program Execution Time would be altered in these instances. I'll have to do some more research I think.You missed this one:
View attachment 299226
This general rule can be modified by other rules, which usually remove the isolation time limit for specific popular scenarios.
Any scenario that is not included in other rules necessarily has an isolation time limit of 3 days.
Lots of talk on MT regarding Comodo, seems out of proportion to the amount of people who use it though, who actually uses it as a main AV solution though.on MT, I would find the answer intresting??
@Shadowra allowed HIPS alerts; did this permit those specific actions, affecting the test results? Does Comodo behave differently with HIPS enabled compared to disabled when auto-containment is active? For instance, I use Ant Download Manager along with its browser extension. With HIPS enabled, I see a "cmd (safe) is trying to access antch (unknown)" alert when I start a browser. The extension functions properly if I allow this alert; no auto-containment alert for antch. With HIPS disabled, I see an auto-containment alert for antch when I start a browser; the extension cannot function.
Comodo... the unbeatable dinosaur—the T-Rex of innovation!Comodo is a dinosaur among other products. Some people like to discuss dinosaurs.![]()