Is Kaspersky Application Control unbeatable?

RiderExpert

Level 2
Thread author
Verified
Jul 21, 2016
53
If Low and High Restricted did not expose all kinds of bugs I would say yes. Most people try to over-configure KIS. I over-configure it to find out what is broken. There is simple toggle switch. Nobody ever mentions it. So I assume nobody ever uses it - which is a shame as it is as about a simple solution as you can get. When you need to use cmd.exe or others for safe program, you don't have to contend with any breakage caused by Low or High Restricted limits placed on process; the process is the Trusted group and will work as needed. When done, just disable it again. You will find it is not annoying.

Yes. I 'm always testing fresh malware samples and goodware , changing KTS configs trying to find out what is the best setup. But in fact, changing that switch is not that hard. Awesome tip.
 
5

509322

Yes. I 'm always testing fresh malware samples and goodware , changing KTS configs trying to find out that is the best setup. But in fact, changing that switch is not that hard. Awesome tip.

All the work is in initial configuration. After you will find that you rarely need to disable something. You might have to Allow one or two processes permanently. However, since most everything else is disabled, Allowing one or two processes so things work does not introduce much risk to the system. You will see.

The biggest pain is getting to the toggle switch. Really. That's the annoying part.
 

RiderExpert

Level 2
Thread author
Verified
Jul 21, 2016
53
All the work is in initial configuration. After you will find that you rarely need to disable something. You might have to Allow one or two processes permanently. However, since most everything else is disabled, Allowing one or two processes so things work does not introduce much risk to the system. You will see.

The biggest pain is getting to the toggle switch. Really. That's the annoying part.

Yes. I've already sent Kaspersky a suggestion about shortcuts to some settings. Maybe even put some options on the context menu, but I don't think they care.
 
  • Like
Reactions: brambedkar59

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Application Control of Kaspersky uses Cloud analyzer to determine the ratings of the certain product and set depends on restriction.

The best option is put it on High Restricted or Untrusted however it does not determine full proof concept, it can generally block majority of executable attacks and new strain of fileless attacks may prone to bypass.

You need to tune up properly on how a certain component works, sometimes by customizing will work flawlessly in that certain system only.
 

RiderExpert

Level 2
Thread author
Verified
Jul 21, 2016
53
This type of behavior is a known bug on some systems (x64 ?) that K has not been able to sort out. Since it has been reported many times over the past years it just might be that K doesn't consider it a bug or that they have simply chosen not to fix it because it is only security soft geeks that report it.

Your best bet would simply be to use the Allow\Block toggle switch and set it to Block for those processes in both System32 and SysWOW64. Most programs do not use them.

Just an update

Kaspersky Password Manager extension does not work with cmd.exe disable :/
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
I also find that cmd.exe is the hardest of the common script interpreters to block. There are just too many programs/processes that need it.
For me, the easiest and most effective way to get control of these vulnerable processes is to run NVT ERP free beta in combo with Kaspersky.
 
  • Like
Reactions: Solarlynx
5

509322

I also find that cmd.exe is the hardest of the common script interpreters to block. There are just too many programs/processes that need it.
For me, the easiest and most effective way to get control of these vulnerable processes is to run NVT ERP free beta in combo with Kaspersky.

That is the rationale for those that combo AppGuard and NVT ERP; to monitor cmd.exe and rundll32.exe.

I have run both cmd.exe and rundll32.exe completely disabled on a system. There were block events, but nothing was broken. What happens when you disable those two processes depends to a large extent upon what you have installed on your system. Rundll32 is used for some Windows background activities.
 
  • Like
Reactions: shmu26
D

Deleted member 178

That is the rationale for those that combo AppGuard and NVT ERP; to monitor cmd.exe and rundll32.exe.

I have run both cmd.exe and rundll32.exe completely disabled on a system. There were block events, but nothing was broken. What happens when you disable those two processes depends to a large extent upon what you have installed on your system. Rundll32 is used for some Windows background activities.
I need cmd.exe so i run it guarded in AG. however i disabled rundll32.exe
 
  • Like
Reactions: Solarlynx

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
I need cmd.exe so i run it guarded in AG. however i disabled rundll32.exe
I assume that you need to renable rundll32 when you install a program, or run an update?

Regarding cmd, someone told me that disabling it borked their system, when a Windows update came along that needed it. So it sounds wise to me, not to disable it.
 
5

509322

I assume that you need to renable rundll32 when you install a program, or run an update?

Regarding cmd, someone told me that disabling it borked their system, when a Windows update came along that needed it. So it sounds wise to me, not to disable it.

Disabling cmd.exe will not bork a system. It might temporarily break a couple of things, and it is not permanent damage. There are Windows processes that, if disabled, will bork Windows but none of the interpreters are one of them.
 
D

Deleted member 178

I assume that you need to renable rundll32 when you install a program, or run an update?
Yes , depending the case. That is the beauty of Appguard, you block everything you want, anywhere you want, and can unblock them if needed by one click.
 
  • Like
Reactions: shmu26

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top