NoVirusThanks OSArmor

NoVirusThanks

From NoVirusThanks
Verified
Developer
Well-known
Aug 23, 2012
292
We've released OSArmor v1.6.8:

Here is the changelog:

Code:
+ Fixed all reported false positives
+ Fixed some false positives on Windows Server 2016
+ Added more signers to Trusted Vendors list
+ Added Block execution of any process related to Python
+ Added Block any process related to Jernej Simončič (wget & netcat signed)
+ Added Block execution of wget.exe
+ Include process and parent process file size in blocked-process events
+ Improved monitoring of processes with large file size (e.g 50+ MB)
+ Improved internal rules to block suspicious behaviors
+ Improved detection of malformed/obfuscated command-lines
+ Improved installer and uninstaller scripts
+ Minor improvements

If you find false positives or issues please let me know.

// Everyone

If you are running the test builds please update to this final version.
 

plat

Level 29
Top Poster
Sep 13, 2018
1,793
Interesting....there is more fallout from the latest NVIDIA hacking incident where the group stole a LOT of important data--incl. a certificate which can then be used to sign malware. And it seems this has already happened.

Good to know OSA can block this malicious process, provided the proper setting/s are enabled.

 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566
Here is a pre-release test 1 for OSArmor Personal v1.6.9:
This is the changelog so far:

+ Fixed all reported false positives
+ Added new internal rules to block suspicious behaviors
+ Improved the pre-filled text of exclusion rule when button "Exclude" is clicked
+ Updated NVT License Manager with latest version
+ Added more signers to Trusted Vendors list
+ Minor improvements

Please let me know if you find issues or FPs.

Thanks guys!
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566
Here is a pre-release test 2 for OSArmor Personal v1.6.9:

I updated the notification window when a process is blocked, here is a screenshot:

1647850071628.png

Please let me know if you find issues or FPs.
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566
Here is a pre-release test 5 for OSArmor Personal v1.6.9:
+ Added support for a dark theme if Windows Dark Mode is enabled

Screenshot of OSA when Windows Dark Mode is enabled:
1648238230862.png

* To test the dark theme, exit OSA GUI via OSA system tray icon -> Exit GUI -> Confirm action
* Now enable Windows Dark Mode and then start OSArmor UI
* In shorts, OSA GUI needs to be restarted

Please let me know if you find issues or FPs.

Thanks guys!
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566
Here is a pre-release test 7 for OSArmor Personal v1.6.9:
This new test version fixes the issue reported by itman.
This issue:
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566
We've released OSArmor v1.6.9:
Download OSArmor for Windows 7, 8, 10, 11 (32 & 64-bit) | OSArmor

Here is the changelog:
:
+ Fixed all reported false positives
+ Added new internal rules to block suspicious behaviors
+ Improved the pre-filled text of exclusion rule when button "Exclude" is clicked
+ Updated NVT License Manager with latest version
+ Added more signers to Trusted Vendors list
+ Added support for a dark theme if Windows Dark Mode is enabled
+ Minor improvements

If you find false positives or issues please let me know.

// Everyone

If you are running the test builds please update to this final version.
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566
Here is a pre-release test 1 for OSArmor Personal v1.7.0:


This is the changelog so far:
+ Fixed all reported false positives
+ Added new internal rules to block suspicious behaviors
+ Improved installer and uninstaller scripts
+ Minor improvements

Let me know if you find issues or FPs.
 

Trooper

Level 16
Verified
Top Poster
Well-known
Aug 28, 2015
772

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566
Here is a pre-release test 10 for OSArmor Personal v1.7.0:

This is the changelog so far:
+ Fixed all reported false positives
+ Added Block system processes on user space
+ Added new internal rules to block suspicious behaviors
+ Added more signers to Trusted Vendors list
+ Allow to use wildcards on IgnoredNotifications.db
+ Added Copy to Clipboard popup option on Manage Ignored Notifications
+ Improved installer and uninstaller scripts
+ Minor improvements
Let me know if you find any issues.

This rule "Block system processes on user space" is mostly oriented to companies and blocks system processes found in user space (i.e WerFault.exe copied to a user-writable folder and used to load wer.dll -malicious- in the same folder).

In my tests it didn't generate any alerts of legit behaviors, but it may depend on how you utilize the PC.

The rule needs to be enabled manually, it is not enabled in any protection profile at the moment.
We'll start working on SysHardener this week.

Currently SH works fine on W10 and W11, we're going to make it simpler and add new OS hardening tweaks.
 

NoVirusThanks

From NoVirusThanks
Verified
Developer
Well-known
Aug 23, 2012
292
We've released OSArmor v1.7.0:

Here is the changelog:

Code:
+ Fixed all reported false positives
+ Added Block system processes on user space
+ Added new internal rules to block suspicious behaviors
+ Added more signers to Trusted Vendors list
+ Allow to use wildcards on IgnoredNotifications.db
+ Added Copy to Clipboard popup option on Manage Ignored Notifications
+ Improved installer and uninstaller scripts
+ Minor improvements

If you find false positives or issues please let me know.

// Everyone

If you are running the test builds please update to this final version.
 

Mops21

Level 34
Verified
Honorary Member
Content Creator
Oct 25, 2014
2,368
We've released OSArmor v1.7.1:

Fixed all reported false positives
Added new internal rules to block suspicious behaviors
Minor improvements



With best Regards
Mops21
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566
Here is a pre-release test 1 version of OSArmor PERSONAL v1.7.2:

Here is the changelog so far:
+ Fixed all reported false positives
+ Added "Protection Option" button on Configurator GUI
+ Added new internal rules to block suspicious behaviors
+ Improved blocking of malicious .ISO files behaviors
+ Minor improvements

Let me know if you find any issue or FP.

@plat1098 @LoneWolf

"Now that you mention it, it would be nice if the Protection Modes were somehow placed into the main body of the Configurator"

Good point, added the button "Protection Options" in the "Protections" tab that should make things easier to select protection profiles:
osa-configurator.png
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566
Here is a pre-release test 5 version of OSArmor PERSONAL v1.7.2:


Let me know if you find issues or FPs.
We are discussing about enabling the following protection options in the Extreme Protection profile:

Block signers not present in Trusted Vendors List
Block processes signed with an expired certificate
Block unsigned processes on user space
Block system processes on user space
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566
Here is a pre-release test 6 version of OSArmor PERSONAL v1.7.2:


Here is what changed:
+ Block execution of curl is now enabled on Basic Protection profile
+ Improved blocking of processes with fake file extension
+ Improved many internal rules to block suspicious behaviors

Let me know if you find issues or FPs.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top