YES..however zone alarm threat emulation is quite rotten
means a strong INET connection is required to make the upload possible to its virtual cloud
Always works when a unknown or new (hash) triggers it..likewise if a known trusted(hash, Signed Publisher) malformed can easily by pass it including Ransom- These are the observations i noted down today during testing
However if a sample by passes threat Emulation .. ZA removal rate is next to none (NIL) against executed unknown malicious exe.
When offline ZA is completely tenable to unknown / 0 day malwares ..unlike Kaspersky which has both offline and online capability
Thanks for the tests @ MoriartyOW__> Change Threat emulation settings to (Upload any exe file(Default-doc,pdf...files) and select all the directories)
View attachment 197184