Serious Discussion Deep Instinct | Deep Learning AI Cybersecurity Platform

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,505
:ROFLMAO: of course you are correct! factoid, downloading that file and trying to manually install it on computer where Di is already installed results in update failure. The only way to get update is to change the policy in console to automatically update ENABLE (or so I'm told by support tech). Did that and ..14 is now installed on first, one more to go. Do you recall: is that feature default setting enabled or disabled, I just don't recall changing it if default is Enabled (& I take notes too)
I think it was disabled
 

Xeno1234

Level 14
Jun 12, 2023
699
Can DI work with Kaspersky?

would not do this.. They might interfere with each other
In the event i use them together, Kaspersky would be disabled except for Web Protection, it has good web protection and DI has none.
Also, when does DI detect things. I have downloaded files that it typically detects with Static Analysis yet i can fully execute them. Is there any reason as to why this is?

like it executes and asks for privilege escalations and u choose yes or no? If so, yeah it will still block it after saying yes either way . Or i think your talking about sometimes its delaying idek man
And also... just use bitdefender trafficlight or netcraft or malwarebytes browser guard. Kaspersky web protection isnt the best its good tho. using a entire antivirus on the side for purely web sheild isnt really worth it.
I might try Bitdefender Traffic Light but Kaspersky is very good.

yeah, kaspersky is good lol. But stil running a whole AV just for the web protection seems excessive to me. Get harmony browse and Bitdefender Trafficlight and your good.
What is Harmony Browse?

ok I am going to setup deep instinct.

checkpoint, you can trial it for 30 days. Its just the chrome extension. Same one as that one you auto get from downloading the full harmony package. If im not wrong, cyren supplies phishing data for checkpoint i think.
Checkpoint utilizes a unique Phishing AI in which it compares the webpage to similar webpages and if its similar enough, its detected as phishing.

I also must ask, how's DI fair with Malicious Jars? I know Kaspersky is very, very good at dealing with those - take Fractueiser for Example, the only AV to statically detect the attack before it reaches the final payload.

Not sure. I am sure that if it is based on a exe and then executes a script like a jar, it will block that but as all ngav's have a weakness, In this case its the script sheild
Atleast its better than Sentinel One..... Sentinel one is so bad likes its not even good... misses EASY malware that any av would detect. this is also why reddit sucks. But in the policies it lets u configure it to block certain scripts. Look at kongo's post in the first part of this thread.
I dont really run scripts, at all. Is their script coverage as good as lets say Kaspersky?

not sure, you can configure in policies to edit the script control. But of course its a ngav... its not as good as kaspersky.
But still deep instinct script protection is good not GREAT but good enough since scripts are pretty rare to even execute
Isn’t kaspersky also technically a NGAV? It just uses more than just AI.
 
  • Like
Reactions: [correlate]

Sandbox Breaker

Level 9
Verified
Well-known
Jan 6, 2022
435
Checkpoint utilizes a unique Phishing AI in which it compares the webpage to similar webpages and if its similar enough, its detected as phishing.
There is ZERO solutions like their "Zero Phishing". I test it always when I get a SEG bypass. The ML catches all of the Popular phishing pages (365, Banks, Google, Social Media). It is really bad when it comes to not so popular banks and services.

NO, it's not an NGAV. NGAV means signatureless and purely machine learning and AI. No Kaspersky isn't a NGAV.
This isn't a question... You don't even know what NGAV means.... Behavior blocking isnt an AI. Kaspersky system watcher is a BB not ML or AI...
Kaspersky is a NGAV as well as Traditional AV.
Their ML even catches Exploits/Mal PDF's and slew of other malware + Scripts. Its not always a local DL model that makes a NGAV. DL can be used in many ways.

Kaspersky meets the requirements to be considered as a NGAV. Their BB does not only use sigs. It uses true ML in making determinations. HUER detections are Sig based whilst PDM ones are pure ML. Im sure alot will concur the same conclusion.


hmm ok guess i was wrong
The more wrong you are the more you learn and get better :)
 
  • Like
Reactions: simmerskool

Xeno1234

Level 14
Jun 12, 2023
699
Kaspersky meets the requirements to be considered as a NGAV. Their BB does not only use sigs. It uses true ML in making determinations. HUER detections are Sig based whilst PDM ones are pure ML. Im sure alot will concur the same conclusion.

Kasperskys PDM uses Execution Heuristics, ML, and Behavioral Stream Signatures. It’s not just ML

Their File AV utilizes ML, Signatures, Expert Rules, DNA, and Local Emulation, along with Heuristics and cloud protection. Kaspersky has very deep protection.
 

Xeno1234

Level 14
Jun 12, 2023
699
There is ZERO solutions like their "Zero Phishing". I test it always when I get a SEG bypass. The ML catches all of the Popular phishing pages (365, Banks, Google, Social Media). It is really bad when it comes to not so popular banks and services.
Are you claiming that it is good? Or that it is bad?
 

Xeno1234

Level 14
Jun 12, 2023
699
That its really good. But on the downside it is bad for unpopular services since their models weren't trained against all services.
My mom has a lot of phishing things happening for them - it’s a lot of stuff with teams and Microsoft applications. Could checkpoint protect against that? I’m curious

Well, the full scan has false positived, alot. Its flagged Xbox, tons of Windows Hardening tools, Fall Guys, Battle-eye Anti-Cheat, and alot of other things too.
 

simmerskool

Level 31
Verified
Top Poster
Well-known
Apr 16, 2017
2,094
Well, the full scan has false positived, alot. Its flagged Xbox, tons of Windows Hardening tools, Fall Guys, Battle-eye Anti-Cheat, and alot of other things too.
Di on its first scan here only blocked 1 file, ie 1 false+, but seeing the reason Di blocked it, I easily understood why, and I created a limited narrow exception in Di management for that file and all fixed. I've been running Di for 3.5 months and this was my only false+. Perhaps others, @Kongo has more experience...
 

Xeno1234

Level 14
Jun 12, 2023
699
Di on its first scan here only blocked 1 file, ie 1 false+, but seeing the reason Di blocked it, I easily understood why, and I created a limited narrow exception in Di management for that file and all fixed. I've been running Di for 3.5 months and this was my only false+. Perhaps others, @Kongo has more experience...
Can you disable full scan apon install?
 
  • Like
Reactions: [correlate]

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Are you asking ".. made.?" or sharing your opinion regarding DeepInstinct?

Which other NGAV platforms have you used?
 
  • Like
Reactions: simmerskool

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top