Which Elements of Comodo do You Use?

Elements of Comodo that You Use

  • Firewall

    Votes: 43 86.0%
  • HIPS

    Votes: 16 32.0%
  • Auto-Contain

    Votes: 37 74.0%
  • Heuristic Command-line Monitoring

    Votes: 24 48.0%
  • Cloud Lookup

    Votes: 27 54.0%
  • Viruscope

    Votes: 29 58.0%
  • Shortened (Edited) Trusted Vendors List

    Votes: 11 22.0%
  • Detect PUP Software (setting in File Rating Settings)

    Votes: 20 40.0%
  • Desktop Widget

    Votes: 10 20.0%
  • Killstart

    Votes: 12 24.0%

  • Total voters
    50
  • Poll closed .
Status
Not open for further replies.

ZeroDay

Level 30
Verified
Top Poster
Well-known
Aug 17, 2013
1,905
Just out of curiosity, what does the true "advanced user" need, in terms of security software? Assuming he is a home user with normal computer purposes.
Windows defender + WFC + OS Tweaks standard user account, group policy changes etc. a true advanced user would need very little 3rd party software, but what we need and what we like to play with security software wise are two totally different things lol.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Windows defender + WFC + OS Tweaks standard user account, group policy changes etc. a true advanced user would need very little 3rd party software, but what we need and what we like to play with security software wise are two totally different things lol.
For me, it's easier to use 3rd party security softs than it is to tweak the *** out of native Windows features and live with the resulting restrictions.
 

bribon77

Level 35
Verified
Top Poster
Well-known
Jul 6, 2017
2,392
(I do not consider myself advanced) ... But, I have spent a lot of time with the Firewall control, Exe Radar and Sandboxie and, I have not been infected.
I have also been alone with Comodo Firewall with the configuration of Cs and Sadboxie and I have not been infected.
 
Last edited:

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
(I do not consider myself advanced) ... But, I have spent a lot of time with the Firewall control, Exe Radar and Sandboxie and, I have not been infected.
I have also been alone with Comodo Firewall with the configuration of Cs and Sadboxie and I have not been infected.
If you used WFC, NVT ERP and SBIE, then you are an advanced user.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Does anyone know how to tweak Comodo HIPS registry protection, so it will only alert for critical registry areas? Ditto for file modification.
I think that most of the HIPS overkill is happening in the registry area.

I tried HIPS paranoid in Firewall config, but I was disappointed. It ruins the execution control. Once you allow a process to execute one thing, it will be allowed to execute all things.
 

klaken

Level 3
Verified
Well-known
Oct 11, 2014
112
Does anyone know how to tweak Comodo HIPS registry protection, so it will only alert for critical registry areas? Ditto for file modification.
I think that most of the HIPS overkill is happening in the registry area.

I tried HIPS paranoid in Firewall config, but I was disappointed. It ruins the execution control. Once you allow a process to execute one thing, it will be allowed to execute all things.

Hip alert of the system's cirtic things ..

Your problem is that it is so configured by the simple fact that 1 program could send you 5 to 50 alerts depending on your actions.

Believe me is frightening .. although I think that in the configurations it can be deactivated (I saw it once).
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
I have a suggestion, how about blocking wscript, ccscript, powershell and java.exe and javaw.exe + block malicious extensions (.scr, .js, .jsw,...)
block the internet connection of those processes + set the "Ask" rule of cmd.exe when it wants to connect so we can control it
I use auto-container to block powershell processes
1.PNG 2.PNG
 
Last edited:

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Hip alert of the system's cirtic things ..

Your problem is that it is so configured by the simple fact that 1 program could send you 5 to 50 alerts depending on your actions.

Believe me is frightening .. although I think that in the configurations it can be deactivated (I saw it once).
Yes, you can deactivate registry protection, and a whole list of other actions, too. I am more interested in leaving it activated, but configuring which registry areas it monitors.
 

Soulbound

Moderator
Verified
Staff Member
Well-known
Jan 14, 2015
1,761
In the days of 5.12 I would use CIS, but since v6, I stopped using it completely in my main system as I didn't like the direction it was heading.

Nevertheless, one of my systems runs CIS on default settings because is good enough for the use that the system has (youtube, twitch and steam games), so it gets Firewall and HIPS vote. Reason for CIS? cant handle McAfee Endpoint Security very well due to its specs
 
  • Like
Reactions: AtlBo and shmu26
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top