Umbra Corp. said:
cptredsox said:
i really like ESS but especially for new users there should be a
whitelist for the HIPS, that would be a relief
in combination with the learning mode.
The HIPS is the main problem of ESS;
automatic mode: allow almost everything
interactive: ask you for almost everything, if you don't answer it block
policy-mode: block almost everything
learning mode: allow everything
Bold is incorrect.
Automatic mode: Follow rules, if none exist, allow automatically the operation, not almost everything.
Interactive mode: Follow rules, if none exist, ask. Failure to answer the dialog alert after a specific time will automatically allow, not block.
Policy based mode: follow rules, if no rule exist, deny process.
jamescv7 said:
Their newly HIPS is rated as classical way thus those pop ups when detected would be the rules apply and the configuration of importing rules is complicated too.
ESET has had enough time to improve their classic HIPS. Unfortunately, up to date, all they did was add 1 rule by default which was to allow drivers to load.
Configuration of rules is not difficult unless you decide to make them manually.
Also, ESET has an import/export feature for all settings.