- Feb 7, 2023
- 2,349
Threat emulation for the same (one of the files downloaded by the inflated malware):
Last edited:
Do you access this report with ZA/ESNG or with Checkpoint Harmony, or both? (or I'm not seeing ZA reports because it has not detected any malware on my VM??)Though ZoneAlarm like any AV and specially a home one inevitably can miss malware, here is one interesting forensic report:
VT 5/71 (low detection) not sure about behavioural blocking engines.
ZoneAlarm detections:
View attachment 276034
VT 4/59
View attachment 276035
Forensic reports from ZoneAlarm are saved in C:\ProgramData\CheckPoint\DBStore\Events.Do you access this report with ZA/ESNG or with Checkpoint Harmony, or both? (or I'm not seeing ZA reports because it has not detected any malware on my VM??)
@Decopi, we seem to mostly agree. I would prefer that ZA block that sneaky 65mb stealer malware without the user having to throw a switch in firewall. That's my only point. Why do I want to install an AV with default reduced protection, and then have to tweak it for max protection? (perhaps there's something I'm missing ) I assume ZA is configuring it features to max protection as default since ZA has nothing to tweak. If it failed with that 65mb malware, ZA should fix that by default without user needing to tweak its firewall. (aside if I want to tweak a firewall, then I run CF@cs).I agree with you, but:
With regards to security software, personally I only care about protection capabilities and hardware performance... that's all.
ZA hardware performance doesn't worry me.
Therefore, I'm only focused on ZA protection capabilities.
Now and in my context, if you take the sneaky 65MB stealer malware case, and you see that a simple option in the firewall could have helped to minimize its damages, and in the other hand you see that current ZA firewall has just an ON/OFF... perhaps is time to add few simple options in ZA firewall.
When a minimized UI or any default settings are having bad protection reputation... perhaps is time for changes.
@Decopi, I would prefer that ZA block that sneaky 65mb stealer malware without the user having to throw a switch in firewall. That's my only point.
Why do I want to install an AV with default reduced protection, and then have to tweak it for max protection?
(perhaps there's something I'm missing ) I assume ZA is configuring it features to max protection as default since ZA has nothing to tweak. If it failed with that 65mb malware, ZA should fix that by default without user needing to tweak its firewall. (aside if I want to tweak a firewall, then I run CF@cs).
We disagree on a few points above: I suggest there is no need for two dimensions, at the moment ZA/ESNG seem to agree since it does not have settings, ie, one dimension, which is ok for me as long as I'm not getting infected. (no events here, yet)There is no perfect security software.
Therefore, you always will need to live in two dimensions: 1) Default settings or 2) Customized settings.
Because different users have different profiles.
For average Joe, default settings usually are enough. Hardening settings for average Joe profile will be a nightmare, because average Joes don't know how to deal with hardened settings (it blocks too much stuff for them, and they don't know how to unblock needed stuff).
Now, for users like me, I always need to harden default settings, because I use to be exposed to cyber threats, and I know how to block, unblock, allow, disable stuff.
I don't believe "default settings" are configured to maximum protection.
I believe "default settings" are configured to "average use".
There is no security software with "default settings" and "maximum security" at the same time.
Default settings is about default use, and security level is about user profile... two different things.
Missing malware is normal and doesn’t mean the software is mediocre or badly developed. Specially when we are talking about 1 samplewe seem to mostly agree. I would prefer that ZA block that sneaky 65mb stealer
It misses some malware there and some PUPs but I don’t even know where they got this version, this one doesn’t get updates since 2022 and emulation is also blocked. If you try and emulate a file it won’t work. As of March last year, it has been replaced with the NextGen.Yeah, and here is another Russian video from 3 months ago.
It misses some malware there and some PUPs but I don’t even know where they got this version, this one doesn’t get updates since 2022 and emulation is also blocked. If you try and emulate a file it won’t work.
Yeah that one from Comms TV or whatever the channel is called is a very recent one.Yeah, that's one of the reason originally I wasn't convinced to share this ruský test.
As I said, this video is totally in Russian, no texts, too long, and difficult to follow for non Russian speakers.
Also, from the beginning is possible to see the tester using a very old version of ZA.
Considering ZAESNG is under development, I think only recent test (from last 2 moths) are interesting.
Yeah that one from Comms TV or whatever the channel is called is a very recent one.
ZoneAlarm passed clean whilst others like Trend Micro and Bitdefender weren’t that fortunate.
Mine was recent as well, but was before the addition of anti-bot and was also a very difficult one, much more difficult then needed to draw valuable conclusion for home users. It was mostly for geeks.
For now we can see protection is OK but not wow and needs more work.
Harmony Endpoint depends on the reseller and number of devices but as single license is usually about £60 per year, per device. If you buy in huge bulk (something which I will have to do soon) it will be a lot cheaper. You could get Harmony Total (which includes the Email and Collaboration Suite) and everything for 150 devices for about £30 per device.@Trident how much is harmony endpoint?
Yeah, that’s very accurate. Before the addition of anti-bot I didn’t like it too much and it wasn’t ready to protect a system properly.There is no need to share ZA info before past March, because the last ZA changed in the past 3 months.
Doesn't seem that much, for example I was quoted $42 for Deepinstinct. What other cheap endpoint products do you know of?The UK government has Harmony Endpoint as well on their digital marketplace and I believe it’s their officially-recommended software as well as what the NHS uses.
Check Point Harmony Endpoint - Digital Marketplace
www.applytosupply.digitalmarketplace.service.gov.uk
They sell it for £18.00. I will Create a Check Point Harmony thread as well soon so we don’t confuse users.
It all depends on the reseller, they work for percentage. I am not aware of other cheap products tbh, I am not really interested in free and cheapDoesn't seem that much, for example I was quoted $42 for Deepinstinct. What other cheap endpoint products do you know of?
I am testing version 4 only and that incident with the inflated file was triggered by anti-bot. It means that if it was version 3 it would’ve been a miss. The one on Comms TV has been version 3 as well. @Shadowra today has tested version 4.please may i ask ? are these also version 3 instead of version 4 ? thank you
I am testing version 4 only and that incident with the inflated file was triggered by anti-bot. It means that if it was version 3 it would’ve been a miss. The one on Comms TV has been version 3 as well. @Shadowra today has tested version 4.