App Review Kaspersky Security Cloud Free vs Ransominator (default settings)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
As far as I know Kaspersky 2021 won't have TAM anymore. :)
yes, fortunately, we can still make Kaspersky perform like TAM by changing 2 options in Application Control. Harlan showed it here. I can confirm it. It works exactly the same. Even with faster speed.
 

MacDefender

Level 16
Verified
Top Poster
Oct 13, 2019
784
FWIW I just tried my TrojanZipperPOC against KTS2020 this morning.

KTS dynamically detected it as "PDM:Trojan.Win32.Generic", offered to disinfect and reboot. Unfortunately, in that process, it did not trigger a System Watcher Rollback. This process left about a third of the files encrypted but it stopped the rest. Overall an okay result. I believe this is still the same behavior that was previously seen when this test was done.

1588096685413.png
 

miguelang611

Level 2
Apr 13, 2020
99
Thanks to application control custom rules, document files were protected in my test.

Advanced disinfection starts, restart the system and all things rolled back.

Cloud Detection:

View attachment 238190
Hi!
Thanks for the info. May I knowh what are you settings for app control custom rules?
Sorry, if they're somewhere else, I didn't see them.
Personally I have a custom rule as harlan4096 suggest: whole C:\* with maximum restriction, just read allowed, just charges the KSN rules, doesn't allow if not known on KSN but digitally signed. Do you go even further?
Thanks!
 

fabiobr

Level 12
Verified
Top Poster
Well-known
Mar 28, 2019
569
Hi!
Thanks for the info. May I knowh what are you settings for app control custom rules?
Sorry, if they're somewhere else, I didn't see them.
Personally I have a custom rule as harlan4096 suggest: whole C:\* with maximum restriction, just read allowed, just charges the KSN rules, doesn't allow if not known on KSN but digitally signed. Do you go even further?
Thanks!
The same, but only protect my important folders, not all C:\
 

MacDefender

Level 16
Verified
Top Poster
Oct 13, 2019
784
Thanks to application control custom rules, document files were protected in my test.

Advanced disinfection starts, restart the system and all things rolled back.

Cloud Detection:

View attachment 238190

After getting several of my samples blocked by KSN across my test and development machines, I did a bit of searching and found this:

UDS = Urgent Detection System -- roughly put, if the behavior blocker finds suspicious behavior in an unknown binary, that gets reported back up to the cloud and it immediately results in a cloud signature blocking this for other clients too.

This leads to interesting behavior like when I try to test a custom-built malware sample in a VM and it triggers Kaspersky, often times it also results in my host development machine's Kaspersky removing the .EXE from the Build directory as well.

SONAR claims to do the same thing but I've never seen it react as quickly as KSN -- this is like 5 minutes from triggering KSW to having the EXE be blocked by other machines running Kaspersky on my network. As Kaspersky says:
Less than a minute after first threat detection, all KSN-connected computers are protected from it.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top