Im an teenager im 17 years old and i know about cybersecurityAre you a child?
Im an teenager im 17 years old and i know about cybersecurityAre you a child?
Try with tdss killer to launch a dll file that's unknown and you will see it's possible to bypass containmentWhen a file is sandboxed i submit it to Xcitium for analysis and i get a verdict in less then 1 hour
Unknown executables might use something that is trusted to destroy the system but even that will get contained
Probably a language barrierAre you a child?
Well every AV is bypassable just so you knowWe talk about the opposite. Trusted executables can use something unknown to destroy the system and avoid containment.
Im an teenager im 17 years old and i know about cybersecurity
Well every AV is bypassable just so you know
It is a good choice.No AV is perfect and it will never be but AVs are Good and i choosed Xcitium to protect my pc from zero-day malware i also know sources of where to get samples from
I Submit samples on a daily basis to Xcitium
100% but we are trying to figure out all kinds of different setups , solutions to get that so hard that it will take more then a skid and a malicious dll mod to infect a system yet be enough user friendly (low false positives) for users to useWe talk about the opposite. Trusted executables can use something unknown to destroy the system and avoid containment.
The Comodo team was unable to fix the sandbox, the POC was able to bypass the CIS.For most Childrens Xcitium is really good it will sandbox or block anything unknown
Even sandbox is bypassable yes but still Xcitium does a pretty good job against unknown zero day malwareThe Comodo team was unable to fix the sandbox, the POC was able to bypass the CIS.
What they did was a workaround.
The Comodo team was unable to fix the sandbox, the POC was able to bypass the CIS.
What they did was a workaround.
It doesn't block it, there are several malwares that pass, according to the tests I do here.Comodo blocks many malwares with its Cloud as either .UnclassifiedMalware@1 or Trojan or whatever
Also you have to have a really good internet connection for fast verdicts for XcitiumIt doesn't block it, there are several malwares that pass, according to the tests I do here.
The method used to bypass comodo is used by skids to put malware in mods .dll (game exe is trusted)Even sandbox is bypassable yes but still Xcitium does a pretty good job against unknown zero day malware
I tried again, and yes, Comodo blocked the unknown files from Program Files.The below list includes three applications currently blocked (but allowed with 1-day time limit and ignored *.tmp files). The executables are parts of applications installed via UniGetUI.
Example of the block for the uninstall.exe included in the Plex installation Folder in Program FIles.
Yes, one should use the "ignore" option for troublesome software or issues.What is the difference between applying an "Ignore" action to the application and not doing this?
When Comodo Auto-containment is set to "Ignore" a particular application, all its actions are ignored too (including possible exploits, *.tmp files, etc.). This is very usable, but not always safe.
On our kids' system, I simply use Comodo Firewall proactive security with the containment/firewall set to block unknown programs.Not anything, but most of the unknowns.
Which configuration do you propose?
It does not contain/block the unknown DLLs loaded by applications (except for some LOLBins included in the Script Analysis panel).
However, the main problem is with Comodo's alerts. Most children should not be allowed to interact with containment alerts, because they tend to bypass the restrictions.
It is hard to configure CIS/Xcitium to be silent and very strong, without problems with software.
So yes, CIS/Xcitium can be really good for children, but not optimal for parents who must solve problems with silently blocked/contained software.
@cruelsister has often recommended this combo in the past.defender is a good combination to comodo and since comodo itself can block majority of malware (those not launched by a trusted process ) it should boost the security of the system a lot
Pretty sure she has defender enabled on her system@cruelsister has often recommended this combo in the past.