@Trident
Harmony’s BB seems to be effective, but does it actually consistently prevent malware from damaging or exfiltrating data? Some of the reports I’ve seen consist of possible damage done - woukd other security solutions have the same issue?
Hi
@Cosmic1764,
The Harmony Endpoint Behavioural Guard like many other behavioural-based analysis systems, applies virtualisation around the full process chain, as soon as the “dodgy behaviour” has been spotted. This doesn’t happen with all signatures, it happens with some signatures and profiles that are marked as “Audit”.
Behavioural Guard has several other types of signatures and profiles, both local and offline. Some of them simply terminate the process as soon as possible, others terminate and clean.
Having damage done by actively running malware though is nothing new and to be edpected! Not only with HEP, but with any other security software.
For this reason, other components, like the emulation, should be configured to run properly.