New Update Defender Hardening Console Executable

This is one of the cases where Helios will help.

Example: malicious HTA file is not detected by Defender.
Hash: 24ef77b150ff7ebc30d8cb7234fd2cec8a15a58128e8e2441e259b7d3de1e66c

Defender alone would not handle this malware.

Protections: MSHTA is blocked from accessing the web anyway, through Deep Firewall Control.

The script sets persistence.

Response:
View attachment 294617


Remediation terminates the process, deletes the persistence and the initial script (I will update the UI so it doesn't display "Quarantine" but "Process" and displays information what will happen on remediation.

Helios combines expertise in fileless and evasive malware detection with reputation from different providers on executables.

I allowed access to the more common applications. Better you need them than find out you can't run them. Ideally, the console would allow you to enable them as needed on a case by case basis. All or nothing isn't an acceptable default. I priortise convenience over security.
 
Hey @Trident! 👋

Just checking in — hope you're doing well! It's been a while since your last update, so I was wondering: is the project still alive and kicking?

No pressure at all, just curious. Thanks for all your work! 🙏

Best regards,

Bruno Eduardo
Well, I can tell you he’s alive he was active on social media not too long ago. I’ve known him personally for years, and it’s normal for him to disappear and then pop back up every now and then. Just so everyone knows, he’s okay and has been active. I understand why people might feel worried; he is a valuable part of the community.
 
Trident is valuable. He is just hibernating.
Sorry I could not help it

Trident-Cinnamon-14Sticks-12-33-50-70221008642.jpg