Serious Discussion [Extension] Symantec browser protection(Symantec intelligence)

Vitali Ortzi

Level 23
Thread author
Verified
Top Poster
Well-known
Dec 12, 2016
1,290
seems like it uses web pulse( you can verify by seeing every link and script etc inside the page being sent to https://ent-shasta-rrs.symantec.com/webpulse/* by a GET request ) and to modify defaults to add more categories or set threat by changing (category_ids), (threat_level)

the defaults are basically using only catagory based detection and set to malware , pishing only and they used these defaults to have the lowest amount of false positives possible on their end
but if anyone has time to modify the extension i would recommend setting threat_level to between 10-8

here you can read about risk threat Categories Are Useful, But It Is Time For Risk Levels and here is a whitepaper about the tech used in webpulse https://docs.broadcom.com/doc/webpulse-en
 
  • Like
Reactions: simmerskool

Vitali Ortzi

Level 23
Thread author
Verified
Top Poster
Well-known
Dec 12, 2016
1,290
blocks sites undetected by norton
Capture.PNG
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top