- Mar 10, 2023
- 147
It seems that 3.5.1.0 is available now.
Sound like a good idea. However, with my new job I rarely have the time to test and actively participate in malware analysis or security products reviewing, unfortunately. I am still actively submitting bugs to be fixed to various software and game developers tho and reporting missing malware samples to many security vendors, but still not like in my active/prime years ten years ago. But will try my best if I have more spare time to do so.Have you thought of writing some additional rules for iDefender HIPS to make it more robust? Worth looking into. It should be tweakable with custom rules.
Sound like a good idea. However, with my new job I rarely have the time to test and actively participate in malware analysis or security products reviewing, unfortunately. I am still actively submitting bugs to be fixed to various software and game developers tho and reporting missing malware samples to many security vendors, but still not like in my active/prime years ten years ago. But will try my best if I have more spare time to do so.
I couldn’t agree more.A package of additional rules would make it stronger like the one a poster here compiled for Huorong Internet Security. A desideratum for the future.
Version 4.0 released. A lot of new features including a sandbox
Major version update, it is recommended to update
Imonitorsdk update to 4.0
Add kernel rules engine
Add file hidden support
Add sandbox support
Add RPC call process traceability
Optimize some performance
template
Add built-in rules template
Add advanced template (kernel mode) support
Add file hidden template
Add lightweight sandbox template
Add domain name query template
Enhance defense
Add analog mouse keyboard monitoring
Add access to cut plate monitoring
Add a modification system time monitoring
Add key event monitoring
Add to modify desktop background monitoring
Add disk control monitoring
Inquiry bomb frame
Add signature information display
Add event customization
The bomb box response record supports the cache (the same event is not reminded by the same event by default, you can set it in the settings)
Intercept record
Add pagination support
Trust list
Support parameter array
optimization
Optimize the rules parameter settings
The disclosure part of the expired template
Optimize kernel process list performance
Add Image Holding Protection
Enhance self -protection logic
Add remote call traceability (service creation, driver loading, task plan, user creation, DNS query, etc. can be positioned to the source)
Add kernel level rules settings
Add WMI process to create monitoring
The rules group supports the introduction of shear plates
Parameter supports drag movement position
repair
Add the compatibility of the network filter driver
Optimize HKEY_CLASSSES_ROOT to redirect
Fix the error
It seems that the new version 4.2.0 and 4.2.1 has been released, is anyone trying out the new features?Lol, this is a huge update with a lot of major changes. This version needs to be re-tested by @cruelsister and @Shadowra.
With Google Translate:
I would say it's quite easy to use. But it's still a manual hips software, so not as easy as real antivirus.It seems to be updated very frequently and has many more features, whether it is easy to use?
Does anyone sharing rules that can be used directly so that others can get protection as long as download the rules?I would say it's quite easy to use. But it's still a manual hips software, so not as easy as real antivirus.
The software includes a marketplace for rules, where you can get some.Does anyone sharing rules that can be used directly so that others can get protection as long as download the rules?
download: https://trustsing.com/publish/iDefender.exe### 4.3.0.0 Update Log
#### iMonitorSDK
- Added ICMP scan monitoring
- Added process protection
- Added shortcut parsing
- Added MoveFileEx monitoring support (delete files on reboot)
- Added more screenshot support: covering AntiTest
- Fixed issue where 8.3 short path caused rule matching to fail
- Fixed issue where SYSTEM process was being bypassed
- Fixed issue where shared file operations were not being monitored
- Fixed issue where port 445 could not be intercepted
#### Features
- Added intelligent defense rules (cloud based)
- Added support for learning mode
- Added workspace support
- Refined file operation prompts
- Display multi-line strings in registry
#### Templates
- Added commonly used template directory
- Renamed file and added suffix field for repair
- Added shortcut interception
#### Others
- Optimized interception record display
- Added built-in rules for system process spoofing
- Interception popup now supports partial sub-window interception
- Registry startup interception does not block normal installation
- Fixed issue where installation failed on some server systems
- Fixed issue where rule overrides did not clear the trust list
Event: Legitimate software that can be used by intruders to damage your computer or personal data was detected
User type: Initiator
Component: File Threat Protection
Result description: Detected
Type: Legitimate software that can be used by intruders to damage your computer or personal data
Name: not-a-virus:HEUR:Monitor.Win32.Agent.gen
Precision: Heuristic Analysis
Threat level: Low
Object type: File
Object name: iDefender.gU5hMGAX.exe.part
SHA256 of an object: BAA3F8D12047C76EC0875440C3C57D88F956D523408BDBAA3957D37E578410A0
MD5 of an object: 328DBD6EB84C731F8482570C545BE942
Reason: Machine learning
Databases release date: Today, 25/06/2024 0:16:00
Are you the owner of iDefender?Version 4.3.0.0 out