NoVirusThanks OSArmor

Deletedmessiah

Level 25
Verified
Top Poster
Content Creator
Well-known
Jan 16, 2017
1,469
If you use ReHIPS as intended, there is no reason to use another HIPS along with it. Maybe it will conflict, and maybe not, but it is surely unnecessary.

Deletedmessiah Rehips HIPS is very light and don't cover many operations While Eset HIPS is a very paranoid tool.:notworthy: the time I was using them together Eset couldn't monitor the command lines but I asked this feature and they added this to Hips module!now Eset can monitor commands(only monitor).
The good thing with Eset is they listen to their users(but also ignore you:D)
I don't need Rehips anymore but if you want a sandbox then Rehips can works with Eset without any problem.

Thanks for the replies! (y)
I was just curious. Personally I couldn't handle a single HIPS at a time, let alone two :LOL:
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Deletedmessiah Rehips HIPS is very light and don't cover many operations While Eset HIPS is a very paranoid tool.:notworthy: the time I was using them together Eset couldn't monitor the command lines but I asked this feature and they added this to Hips module!now Eset can monitor commands(only monitor).
The good thing with Eset is they listen to their users(but also ignore you:D)
I don't need Rehips anymore but if you want a sandbox then Rehips can works with Eset without any problem.
Could you explain more about "monitor commands"? What do you mean by "only monitor"?
 

codswollip

Level 23
Content Creator
Well-known
Jan 29, 2017
1,201
Voodooshield includes anti-exe, so that makes it very different from OSA.
OSA rules are highly customizable, so that makes it a little bit different from Voodoo.
Agree. I went from VS/Armor to ERP/Armor as VS is just too chatty on my system — and particularly for software installs and upgrades. ERP handles those with much less fuss. I also appreciate that ERP allows me to permit executables to run once, without adding then to a whitelist.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Agree. I went from VS/Armor to ERP/Armor as VS is just too chatty on my system — and particularly for software installs and upgrades. ERP handles those with much less fuss. I also appreciate that ERP allows me to permit executables to run once, without adding then to a whitelist.
ERP/Armor sounds good
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Hi wonder if Osarmor/NVT ERP would be a good combinatio nto try instead of OSarmor/VS ,getting alot of FP from VS.?
It is a good combo, but you might get a lot of FPs from ERP, too. Depends a lot on your usage habits.
When I install ERP, I put it in training mode right away, and go through a couple reboots and signing in and out of all my user accounts. This helps to whitelist the boot process, so you don't get stuck in the middle of a boot, when you can't do anything about it. But only do training mode on a clean machine, of course.
 

Peter2150

Level 7
Verified
Oct 24, 2015
280
What I did when I first install ERP, I knew my system was clean so I:

1. White listed all the windows folder
2. Whitelisted Program Files
3 Whitelisted Program Files (x86)
4. Then I built up my Vulnerable files list
6 Slowly whitelisted my command lines.

ERP is thus quite but alert for new and changed stuff. And it plays nicely with OSArmor
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Thanks shmu and Peter I put it in learning mode ,it is not a clean install but a new machine ,6-7 weeks old.By end of week I'll put it back in alert mode.
Umm, be careful with learning mode. Everything that happens on your system will be whitelisted, including possible malware events, so next time they happen, they will not be blocked. I would not leave it in learning mode for long.
 

AMD1

Level 5
Verified
Aug 21, 2012
210
What I did when I first install ERP, I knew my system was clean so I:

1. White listed all the windows folder
2. Whitelisted Program Files
3 Whitelisted Program Files (x86)
4. Then I built up my Vulnerable files list
6 Slowly whitelisted my command lines.

ERP is thus quite but alert for new and changed stuff. And it plays nicely with OSArmor

I recently got ERP but there is no help info available. How does one determine the Vulnerable files list and whitelisting of command lines ? I have followed your item 1-3 and at the moment there are some vulnerable files and command lines there but not put there by me !
 
  • Like
Reactions: AtlBo

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
I recently got ERP but there is no help info available. How does one determine the Vulnerable files list and whitelisting of command lines ? I have followed your item 1-3 and at the moment there are some vulnerable files and command lines there but not put there by me !
ERP beta 3 comes with the basic vulns that you really need. If you want to add to the list, go right ahead. It also comes with certain basic command lines that Windows needs to run.
So basically, you are ready to go. Install it on a clean system, put it in training mode, reboot a couple times, and then put it in alert mode.
 
  • Like
Reactions: AtlBo

AMD1

Level 5
Verified
Aug 21, 2012
210
ERP beta 3 comes with the basic vulns that you really need. If you want to add to the list, go right ahead. It also comes with certain basic command lines that Windows needs to run.
So basically, you are ready to go. Install it on a clean system, put it in training mode, reboot a couple times, and then put it in alert mode.

Should i whitelist Windows, Program files and Program Files (X86) ?
 
  • Like
Reactions: AtlBo and shmu26

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
I put it back on alert mode after an hour on learning,where is training mode?
Learning/training, it is all the same thing. Different apps call it by different names, I got the name mixed up. It's the same thing.
 
  • Like
Reactions: AtlBo

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Should i whitelist Windows, Program files and Program Files (X86) ?
If you leave ERP at close to default settings, you don't need to whitelist them.
If you are planning on unticking those folders, in settings, so that they will not automatically be allowed, then it might be a good idea to whitelist them. But only if you are absolutely sure there are no malware remnants. It is recommended to do this after a clean installation.
 
  • Like
Reactions: AtlBo

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top