Question What types of attacks or files a hardened kaspersky application control can protect against?

Please provide comments and solutions that are helpful to the author of this topic.

Xeno1234

Level 14
Jun 12, 2023
699
Can it block scripts or filetypes protected by simple windows hardening, malicious drivers or execution of lolbins?
@harlan4096 what's your knowledge on this.
Application Control can be configured to block untrusted files from running, or have restrictions on them.

The best hardening would be to make it where they can’t run, this includes scripts. Anything not signed by something super popular (assuming your following Harlan’s configuration), cannot start unless you manually put it into the trusted group.

So, it could technically block malware from using lol bins as it couldn’t start. If it’s signed by windows though or a popular signed vendor, the hardening will do nothing.
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,346
Forgetting signatures and stuff Kaspersky mostly aims to stop the first step of an infection which is usually a script/application etc running with the application control module. If that somehow whitelists an infected file as trusted then no protection can happen. You should harden Kaspersky following the guides found on this site by @harlan4096 and it should be fine for most cases.
Now if you are really paranoid and you want to minimise the danger of lolbins then it's a lot easier to use Hard Configurator by @Andy Ful and click a few times to disable everything without thinking too much.
 

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,672
Windows LOLBins are considered Trusted by KSN, since Microsoft digitally signs them. But We can move them manually to UnTrusted group, K. will warn You about this movement as You are moving a Windows legit file to UnTrusted, but it will allow You to do so.

Scripts of course can be blocked, dlls and other executable file files...
 

Xeno1234

Level 14
Jun 12, 2023
699
Forgetting signatures and stuff Kaspersky mostly aims to stop the first step of an infection which is usually a script/application etc running with the application control module. If that somehow whitelists an infected file as trusted then no protection can happen. You should harden Kaspersky following the guides found on this site by @harlan4096 and it should be fine for most cases.
Now if you are really paranoid and you want to minimise the danger of lolbins then it's a lot easier to use Hard Configurator by @Andy Ful and click a few times to disable everything without thinking too much.
If it’s placed in trusted Kaspersky still monitors it. By default signed files are placed in trusted and Kaspersky detects signed malware - I’d be extremely disappointed if it whitelists it.
 
  • Like
Reactions: JB007

Azazel

Level 5
Thread author
Jun 15, 2023
226
I don't know, since I haven't tested CyberLock lately, I ran some malware tests in Malware Hub some years ago with VodoShield...
Other than reputation-based application blocking like WDAC with ISG, does application control have an automatic Intrusion Prevention System or HIPS?
 
  • Like
Reactions: harlan4096

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,672
is there a resource where I can learn more on how this module works?
There is no K. specific resource about to learn it, but You can check some sticky threads with K. tweaks posted in recent years, there You can find how to find the resources and how to adjust them :)

1711620833045.png



Also:

 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top