Serious Discussion Harmony Endpoint by Check Point

I've already told him several times what I thought of him.
And that these tests are clearly nonsense...

Basically, it launches a script that will bombard the antivirus with file executions. Except that an engine can't handle everything at once, and may clumsily authorize the launch of malware it knows about (as we see in his video on AgentTesla detection, Kaspersky calls it Agentla ... this also happens with the Expiro virus).
This "gang-band" behavior is not an antivirus test worthy of the name.
Yeah but still, both were tested this way and one won. 😀
 
I've already told him several times what I thought of him.
And that these tests are clearly nonsense...

Basically, it launches a script that will bombard the antivirus with file executions. Except that an engine can't handle everything at once, and may clumsily authorize the launch of malware it knows about (as we see in his video on AgentTesla detection, Kaspersky calls it Agentla ... this also happens with the Expiro virus).
This "gang-band" behavior is not an antivirus test worthy of the name.
I like the method where you scan the folder and after you execute what is left. BTW, there is a script on github similar to the one in the video: GitHub - bun39/MalTester-2.0: Test your malware samples against antimalware solutions, similar to malex.py
 
  • Like
Reactions: Shadowra
Checkpoint can use Kaspersky's engine right?

There's a version with Kaspersky and one with Sophos.
It also uses its own flow engines, those of Cisco Talos and those of Kaspersky (for emulation).
And I think ZoneAlarm also has them in NextGen. Yesterday I managed to reproduce the same emulation as Harmony.
 
There's a version with Kaspersky and one with Sophos.
It also uses its own flow engines, those of Cisco Talos and those of Kaspersky (for emulation).
And I think ZoneAlarm also has them in NextGen. Yesterday I managed to reproduce the same emulation as Harmony.
Where do you get the version with Kaspersky, cause I assume its better, right?
 
Where do you get the version with Kaspersky, cause I assume its better, right?

When I picked up my version of Harmony, I got it straight away.
You can switch to Sophos in the Harmony console, but I'm not interested. I trust Kaspersky more than Sophos.
 
There's a version with Kaspersky and one with Sophos.
It also uses its own flow engines, those of Cisco Talos and those of Kaspersky (for emulation).
And I think ZoneAlarm also has them in NextGen. Yesterday I managed to reproduce the same emulation as Harmony.
Local anti-malware can be Kaspersky or Sophos.
It uses its own engines + feeds from Kaspersky and Cisco Talos.
Yes, ZoneAlarm is just a rebrand of Harmony Endpoint, majority of the program code is the same. However, Harmony emulates files up to 50 MB and ZoneAlarm emulates files up to 15 MB.
 
Last edited:
Am going to start a trial for Harmony later tonight, I've been playing around with ZoneAlarm nextgen in a VM, might as well play with Harmony more setting to play around with :).


Any recommendations on setting to change from the default config
 
Am going to start a trial for Harmony later tonight, I've been playing around with ZoneAlarm nextgen in a VM, might as well play with Harmony more setting to play around with :).


Any recommendations on setting to change from the default config
I set it to Strict config its just a quick little button press on the management page it just turns on more detection modules
 
Am going to start a trial for Harmony later tonight, I've been playing around with ZoneAlarm nextgen in a VM, might as well play with Harmony more setting to play around with :).


Any recommendations on setting to change from the default config
i think reasonable settings were shared on previous pages. take a look.
 
1687994141702.png

How do I do this too lol
 
Local anti-malware can be Kaspersky or Sophos.
It uses its own engines + feeds from Kaspersky and Cisco Talos.
Yes, ZoneAlarm is just a rebrand of Harmony Endpoint, majority of the program code is the same. However, Harmony emulates files up to 50 MB and ZoneAlarm emulates files up to 15 MB.
What do you mean by Local Malware Engine, is it both signatures and also their scanning technology and behavior blocker?