Hi!!
I found an issue with "deception-based ransomware detection". WiseVector only includes admin folders for testing it. Personally I have an admin account which I never use, since for upgraded security I use always a non-admin account, while the admin one is only intended for me knowing when something really requires UAC forcing me to introduce password.
So well, I decided to copy those test folders to my own documents folder to manually add them... Result? WiseVector triggered as ransomware behaviour!!
About ransomware rollback, wouldn't it be possible to incude every extension?
Regarding performance/detection, I guess machine learning setting is pretty much same as HIPS and firewall level? If they are same category, right now they look to be different.
Also, regarding pop-ups I have 2 suggestions: first, when you create a rule if it is for a program or/and target and there is a 2nd/3rd popup with those same things, and you click on remember rule, they shouldn't appear since you already "fixed" it with the created rule.
Also, a "close-all" notifications button would be nice to have. For example, when I install programs and they try to connect to Internet, I don't like it to connect bcs I know it is an offline installer, so the easiest option is to ignore popups so it blocks them, but then I want to close them all. A similar approach would be to have something like "block for 10 minutes".
Thank you and see you!!