nishadrox said:
Umbra Corp. said:
with WSA at beginning we are excited to use it, the disappointed by its detection rate, then after understanding how it works , we are satisfied ^^
Well how exactly does it work? Is it like CIS's approach?
Totally different approach.
They do have some zeroday protection etc, but their main feature is the rollback.
In a nutshell, a suspicious behavior will be monitored and if indeed is an infection and Webroot does have signatures, it will detect and rollback to its original state.
I have recreated this procedure via a test with an unknown infection but set to block afterward.
if you are unsure of something, you can still manually block and then re-scan and it will be detected and roll back any changes made.
2 videos at least on youtube about this feature. Mine and the official Webroot explanation.