New Update Smart App Control - Windows 11 22H2 feature promises significant protection from malware

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
8,130
Occasionally - I have to get Microsoft to whitelist stuff via SAC Feedback, which is not a fast process.
Indeed. I submitted an unsigned, non-prevalent app .exe and not a peep from SAC when I run it now.
The "user unfriendliness" of SAC is not nearly as bad as is stated except for those users who are prolific installers of applications and - particularly - games.
It's certainly fine for me, with my simplified setup.
Microsoft is never, ever, going to cater to those folks and M$ wants to be rid of such people except for those that purchase apps and games via the Microsoft Store.

Is that wrong? I don't think so.
I don't either. Look at how Apple does it with their strict gatekeeping. Google is even tending in that direction with Android.
 

Parkinsond

Level 18
Dec 6, 2023
877
I had a simular experience (like @Freki123) on my wife's laptop with a photobook application. Reverted back to Microsoft Defender on MAX with H_C in SWH mode also blocking sponsors. To prevent the confusing messages of MD protected folders I set it to block disk modification only and installed AVAST free ransomware protection and Avast firewall. Although early days, this setup runs perfectly since july this year.
Can Avast web protection be installed with Microsoft defender without Avast antivirus or behavioral protection to avoid conflict with defender?
 

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
8,130
The company says ... Smart App Control is a proactive antimalware solution rather than being reactive like a traditional AV. Thus the benefit is twofold according to Microsoft. Not only do users get better performance and a snappier system, but SAC can also neutralize new threats based on suspicious behavior that it can pick up based on its past machine learning and cloud data. It writes:

Smart App Control takes a proactive approach, blocking suspicious apps before they get the chance to do any harm. Traditional antivirus, however, is more reactive, responding to threats only after they've been detected on your system. This means traditional antivirus is excellent at identifying and removing known threats, but it may not catch new or sophisticated ones as quickly.
 
Sep 21, 2022
70

Andy Ful

From Hard_Configurator Tools
Thread author
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
9,040

The known issues related to MotW bypasses were patched.
Other issues are related to the simplified SAC's design:
  • Signed malware: signing malicious payloads using valid code-signing (files with fake certificates are considered unsigned).
  • Reputation hijacking: finding and repurposing apps with a good reputation to bypass the system.
  • Reputation seeding: deploying attacker-controlled binaries onto the system (e.g., an application with known vulnerabilities or malicious code that triggers only if certain conditions are met).
  • Reputation tampering: injecting malicious code in binaries without losing associated reputation.
Anyway, SAC is intended for home users and hybrid work, where the above issues are rarely exploited. Although SAC is "incredibly efficient security" at home, it cannot be considered a comprehensive protection against highly targeted attacks on Enterprises (Microsoft recommends applying App Control for Businesses).
 

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
8,130
I have no idea.
i don't trust AI in secure app, but this is my opinion of course.
??
Have anyone set it to Active and see how many false positives we get?
Yes, and no false positives, but be aware I have few 3rd party apps installed. It didn't even blink at one unsigned app written in Python that I use. I did see a FP in an app I no longer use. Also, be aware that some blocks may not render an app unusable.
 
  • Like
Reactions: piquiteco

Templarware

Level 10
Verified
Well-known
Mar 13, 2021
486
I disabled mine by accident when I was troubleshooting something, now I need to reinstall Windows, this is so stupid... Well maybe next time.l
 
Last edited:
  • Sad
Reactions: piquiteco

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
8,130
I disabled my by accident when I was troubleshooting something, now I need to reinstall Windows, this is so stupid... Well maybe next time.l
You can use the reset feature, keeping files and some settings, in Windows, if it makes a difference for you.
 
  • Like
Reactions: piquiteco

Templarware

Level 10
Verified
Well-known
Mar 13, 2021
486
You can use the reset feature, keeping files and some settings, in Windows, if it makes a difference for you.
That makes zero sense, it always had. It gives you all the work of reinstalling every program and start every session on every website, without having a fresh Windows install.
 
  • Like
Reactions: piquiteco

SeriousHoax

Level 51
Verified
Top Poster
Well-known
Mar 16, 2019
4,099
It's a bit confusing because I expect Microsoft Defender to still monitor running processes and look for malicious behavior whether they were given green light by SAC or not :unsure:
But anyway, SAC is not for me as I run a few unsigned apps and play cracked games from time to time.
 

Andy Ful

From Hard_Configurator Tools
Thread author
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
9,040
It's a bit confusing because I expect Microsoft Defender to still monitor running processes and look for malicious behavior whether they were given green light by SAC or not :unsure:

From the article, it does not follow that Microsoft Defender stops monitoring running processes (Microsoft Defender is not mentioned at all). It follows that SAC does not do it, and traditional AVs usually do. The performance advantage would be only when SAC could replace a traditional AV, but we can also read:

What’s the best antivirus for PCs?

While Windows 11 Smart App Control offers advanced, proactive protection, it is designed to complement rather than replace traditional antivirus software. For the best protection, combining both offers a comprehensive defense against a wide range of threats. Try Windows 11 today to enjoy this enhanced security setup.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top