Serious Discussion Decoding the Trend Micro Components and Protection Model

TuxTalk

Level 12
Verified
Top Poster
Well-known
Nov 9, 2022
576
I’ve uninstalled Trend Micro, as last night I performed a quick test again with 4-5 pieces of malware. All of them were a total miss (hypersensitive mode). Yes, Trend Micro did say “files are suspicious”, but upon second attempt to run them, there was a way to ignore this warning. When ran, all malware was actively working, without any warning from TM.

One of these files is ransomware “8base” with VT 67/74!!!

Here are the threats, all picked up by Check Point Harmony.

View attachment 284184
threats-jpeg.284183
This result is very much inline with all previous test results I’ve been getting from this product.
Very weird , all the malware i throw at it, instant hit n block.
Never missed any file.

Fot me this is for me something , Not being Gen Digital, Kaspersky, Eset.
I will have my trust in TM
 

Trident

Level 34
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
Interesting, VT shows TM identifying 2 of the 5 hashes including the 8base ransomware as they're part of that 67/74.
Maybe they identify them after telemetry that was received when I executed them.

that "suspicious file blocked" message comes up dozen times and it comes out as being a top tier product. But had they done as you did and run anyway TM could've very well tanked.
Yes, this message is default-deny, I compiled a very simple executable and it was marked suspicious.
But I am disappointed behavioural blocking and predictive machine learning didn’t cover these threats.
 

Mahesh Sudula

Level 17
Verified
Top Poster
Well-known
Sep 3, 2017
825
Trend works this way. It does have good behavior monitoring modules. They somehow able to intelligently manage default-deny alongside behavior monitoring.
Any rare files (unknown, have less prevalence in TM cloud), will be blocked by default as same as how malicious files are blocked by TM.

This is the problem. We do not really understand how and why TM is blocking them. Most of the blocks are instant indicating default-deny. Logs doesn't indicate much information either.
Trend shines in the execution phase, even best (in fact total block out) once it switches to hypersensitive mode automatically. This mode is engaged automatically by TM if there are multiple suspicious file blocks back to back. AV testing scenarios fit well in this scenario and explain "its illegal" but intelligent way for such clean sheet
 
Last edited:

Trident

Level 34
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
They call it “New Program Warning” this default deny. It is effective, but Trend displays it very often which leads to alert fatigue. At one point, this warning doesn’t mean anything to the users.

A security system that can’t take a decision but is relying on warning and prompts is not the best one.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top