@Umbra : I am interested in the combination "CIS + EAM". But the only thread on this issue that I can find was posted nearly four years ago. How would you configure them if you use the combination of the lastest version of CIS and EAM?
In particular, could I enable the HIPS of CIS to enhance the protection? Or should I disable it to avoid any potential conflict between CIS HIPS and EAM BB?
I would appreciate it if you could talk something more about this combination.
If you leave CIS HIPS enabled, you will get double alerts - from both EAM BB and CIS HIPS. Believe me, it's no good if you do not know how to operate CIS - and more importantly - how to handle alerts, establish exclusions in different modules, and fix problems.
Much better config for 1st-time use is EAM + Comodo Firewall; good AV\BB (quasi-HIPS) + good firewall = good security config.
The setup for this config is not difficult - just has to be done in correct order and proper exclusions set. A little time intensive.
Basically, must exclude C:\Program Files (x86)\Emsisoft Anti-Malware and C:\Program Files\Comodo from monitoring each other.
Comodo HIPS should be left off - since - Emsisoft
Ltd is currently not in the Comodo TVL; turn on HIPS and it will detect every Emsisoft Ltd digitally signed module as Unrecognized and subsequently auto-sandbox them... will drive you bonkers - but you can easily fix it by adding the entire EAM folder to the CFW Trusted file list.
Emsisoft GmbH is in the Comodo TVL... but Christian Mairoll - Emsi CEO - moved company base of operation from Austria to New Zealand. So now, Emsisoft GmbH has been changed to Emsisoft Ltd. This slight difference will make CIS detect Emsi Ltd as Unrecognized... auto-sandboxes everything right now - until Emsi Ltd gets added to TVL.
Exclude the Comodo folder in EAM from File Guard, Behavior Blocker and AV scans.
Then turn on HIPS after excluding Emsi folder and adding all folder items to Trusted file list.
It might not work on some systems... and has caused BSOD. You won't know until you try.
That guide from 4 years ago for EAM + CIS still applies...
As you see,
@Umbra is very fast...