Xeno1234
Level 14
- Jun 12, 2023
- 684
Harmony uses Kaspersky's engine for everything by default right, or is it sophos?Detected by Harmony with Kaspersky : HEUR:Trojan-Downloader.Script.Generic
View attachment 276703View attachment 276702
Harmony uses Kaspersky's engine for everything by default right, or is it sophos?Detected by Harmony with Kaspersky : HEUR:Trojan-Downloader.Script.Generic
View attachment 276703View attachment 276702
This is ESET Endpoint trial version.Since when does LiveGuard have such an UI?
PDM is System Watcher.At first I only saw PDM sig. Which is their ML.
Yes it is, you will only see the PDM prefix for System Watcher detections.
BSS is not a prefix they use for detections, when an item is detected by System Watcher it will always begin with "PDM:". BSS is how System Watcher works, and not a detection prefix.BSS would be system watcher. Behavioural Stream SignaturesmAbout System Watcher
support.kaspersky.com
Who cares lol. At least they block it at many layers.BSS is not a prefix they use for detections, when an item is detected by System Watcher it will always begin with "PDM:".
Doesn't that mean that Kaspersky added a signature after it was detected by System Watcher? And the signature however is available for Harmony as it's using the Kaspersky engine and therefor its signatures? I doubt that it can dynamically analyze malware with Kaspersky's behavioural and AI components.Who cares lol. At least they block it at many layers.
This also means Check Point Harmony has system watcher.
The PDM module runs locally. I've seen these seen these detections locally in Harmony before.Doesn't that mean that Kaspersky added a signature after it was detected by System Watcher? And the signature however is available for Harmony as it's using the Kaspersky engine?
PDM can be seen in @Shadowra's test here so it is in Harmony. I am using it with Sophos, hence it reached the behavioural guard layer, where it was instantly annihilated. PDM is probably system watcher's telemetry based. Kaspersky has multiple signatures that can detect the threat.Detected by Harmony with Kaspersky : HEUR:Trojan-Downloader.Script.Generic
View attachment 276703View attachment 276702
Yes sir.PDM can be seen in @Shadowra's test here so it is in Harmony. I am using it with Sophos, hence it reached the behavioural guard layer, where it was instantly annihilated. PDM is probably system watcher's telemetry based. Kaspersky has multiple signatures that can detect the threat.
Harmony is the best value and so superior. I'm also using their mobile solutions. Cloud sandboxes are included with harmony Mobile.Yes sir.
So there is absolutely no delay in Kaspersky detections and Harmony with Kaspersky engine? And while all AVs with Bitdefender engine only get its signatures, Harmony actually also has access to other Kaspersky components?PDM can be seen in @Shadowra's test here so it is in Harmony. I am using it with Sophos, hence it reached the behavioural guard layer, where it was instantly annihilated. PDM is probably system watcher's telemetry based. Kaspersky has multiple signatures that can detect the threat.
It has access to the UDS (Urgent Detection System) which means they use the full sdk. They also use their feeds even if you choose to deploy with Sophos. Upon downloading files from any format, they will be looked up in ThreatCloud where Kaspersky and proprietary telemetry may contain the hash. On files already downloaded, executables reputation is checked in ThreatCloud.So there is absolutely no delay in Kaspersky detections and Harmony with Kaspersky engine? And while all AVs with Bitdefender engine only get its signatures, Harmony actually also has access to other Kaspersky components?
None. they have two Kaspersky update servers. One from CP and the other from Kaspersky for redundancy. There is a delay with VT thouSo there is absolutely no delay in Kaspersky detections and Harmony with Kaspersky engine? And while all AVs with Bitdefender engine only get its signatures, Harmony actually also has access to other Kaspersky components?
It has access to the UDS (Urgent Detection System) which means they use the full sdk. They also use their feeds even if you choose to deploy with Sophos. Upon downloading files from any format, they will be looked up in ThreatCloud where Kaspersky and proprietary telemetry may contain the hash. On files already downloaded, executables reputation is checked in ThreatCloud.
Not fully. Your missing some of their Tech.So even if I choose Sophos, I'll be protected by Kaspersky?
You are protected by Kaspersky but Kaspersky feeds malicious hashes to ThreatCloud. Once the hash changes, it will not be detected anymore (until Kaspersky sees it and feeds the new hash). But then you have Sophos and NGAV. An attacker will need to escape from all that, plus the emulation.So even if I choose Sophos, I'll be protected by Kaspersky?
It has access to the UDS (Urgent Detection System) which means they use the full sdk. They also use their feeds even if you choose to deploy with Sophos. Upon downloading files from any format, they will be looked up in ThreatCloud where Kaspersky and proprietary telemetry may contain the hash. On files already downloaded, executables reputation is checked in ThreatCloud.
Thanks guys for the explanation. I should really look more into Harmony... Even if I was a little sceptical it now seems like a well thought-through solution to me.None. they have two Kaspersky update servers. One from CP and the other from Kaspersky for redundancy. There is a delay with VT thou
It's truely amazingThanks guys for the explanation. I should really look more into Harmony... Even if I was a little sceptical it now seems like a well thought-through solution to me.