App Review COMODO Internet Security Pro 2027

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
Shadowra
Yes, however, I do not recall if we noticed at that time that other rules can remove the file age dependence from some delivery scenarios, such as files downloaded from the Internet, Intranet, etc. In the end only some scenarios can depend on the file age.
What do you mean? I'm unsure, but I think the "File Age" rule should work in all scenarios; you can either add the file age criteria to the rules in the Internet Security config, or you can keep the "All Applications—Unrecognized—3 days" rule and disable the below rules.
 
What do you mean? I'm unsure, but I think the "File Age" rule should work in all scenarios;

This is a general rule for all files. The next rules modify it because they are more specific (valid for some groups of files).
As you can see in the test for BAT files from my previous post, the BAT file on the flash drive was still contained even 3 days after creation.
 
This is a general rule for all files. The next rules modify it because they are more specific (valid for some groups of files).
As you can see in the test for BAT files from my previous post, the BAT file on the flash drive was still contained even 3 days after creation.
I meant Comodo should allow the file in all scenarios if you add the file age criteria to the containment rule/s. For example, Comodo should allow the BAT file on the flash drive after 3 days. Does editing the rule/s work, i.e., allow the BAT file on the flash drive?
 
I meant Comodo should allow the file in all scenarios if you add the file age criteria to the containment rule/s.

This works if there are no other more specific rules

For example, Comodo should allow the BAT file on the flash drive after 3 days. Does editing the rule/s work, i.e., allow the BAT file on the flash drive?

You can remove the "Removable Media" group from the rule below:

1786227499702.png


As you can see, the file age for this rule is unlimited.
The File Age rule in the CIS default configuration works for all supported file types, not only for BAT files. In my test, I used BAT files because they can be easily created.
 
@Andy Ful, I tested the BAT file scenarios (#Post97) using the default Internet Security config and kept the "All Applications—Unrecognized—1 hour(s)" rule while disabling the rules listed below.
With the default Internet Security config, after 1 hour, the test1 file runs outside the container, but both the test2 files run inside, as per KillSwitch.
With the edited config, after 1 hour, all files run outside the container, as per KillSwitch.
 
Last edited:
@Andy Ful, I tested the BAT file scenarios (#Post97) using the default Internet Security config and kept the "All Applications—Unrecognized—1 hour(s)" rule while disabling the rules listed below.
With the default Internet Security config, after 1 hour, the test1 file runs outside the container, but both the test2 files run inside, as per KillSwitch.
With the edited config, after 1 hour, all files run outside the container, as per KillSwitch.

So the File Age works, with one difference.(y)
It is interesting because I repeated this test several times with consistent results.
Did you test this on fresh installed new CIS version? There must be some difference in the settings or environment.
My test was conducted in VirtualBox.

Edit.
Damn, I got a strange result. It seems that CIS works differently in VirtualBox and on a real machine.
I repeated the test on a real machine, and the test file downloaded from the same flash drive was still contained, even after the isolation time limit.
In the same test in VirtualBox, the file is not contained.
So one can be cautious when testing CIS in a virtual machine. It looks like in some nonstandard environments CIS may have trouble determining the origin of a downloaded file.

The good news is that such problems can hardly affect most users. (y)
 
Last edited:
If we skip the exotic issue related to VirtualBox or similar nonstandard environments, we are left with files created directly on the hard disk. Even if some malware could use this to bypass CIS, it would first have to bypass CIS in another way, for example, by exploiting a Trusted process/application. In my opinion, this could be possible only in highly targeted attacks.
Anyway, one should be cautious when testing CIS in a virtual machine.