App Review ZoneAlarm Extreme Security Next Gen 2024 - With Malware Tests

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Product name
ZoneAlarm Extreme Security Next Gen 2024
Installation (rating)
5.00 star(s)
User interface (rating)
5.00 star(s)
Accessibility notes
ZoneAlarm emulation detects stuff like phishing pdf documents, simple PowerShell keyloggers and many others. Stuff that nobody else would detect. At the same time, anti-phishing with real time analysis blocks more pages than big brands like Norton ever will.

Components like Anti-Bot and Behavioural Guard block advanced attacks, the behavioural blocking is based around Mitre tactics and techniques and not just around profiles, like SONAR or ATD (Bitdefender). The level of cleanup after a threat is amazing too, if you have a look at the forensic reports.
Performance (rating)
5.00 star(s)
Core Protection (rating)
5.00 star(s)
Proactive protection (rating)
5.00 star(s)
Additional Protection notes
After alot of testing this is one of the toughest, most realiable AV i ever used.
Browser protection (rating)
5.00 star(s)
Positives
    • Many features
    • Minimal setup required
    • Low impact on system resources
    • Lightning fast scans
    • Easy to use
    • Simple and non-intrusive
    • Ransomware protection
    • Strong and reliable protection
    • Detects or blocks in the wild malware
    • Consistently high test scores
    • Accurate results and reliable antivirus engine
    • Effective malicious URL blocking
    • Virus signatures are updated daily
    • Great value for money
    • Effective malware removal
    • Well designed, clear and easy to use interface
    • Multi-layer protection approach
Negatives
    • Can be costly to run
Time spent using product
Reviewed between 1 to 7 days
Computer specs


System Manufacturer Dazen
System Model Dazen Laptop X86
System Type x64-based PC
Processor Intel(R) Celeron(R) N5095 @ 2.00GHz, 1997 Mhz, 4 Core(s), 4 Logical Processor(s)
BIOS Version/Date American Megatrends International, LLC. 5.19, 3/23/2022
Installed Physical Memory (RAM) 12.0 GB
Recommended for
  1. All types of users
Overall rating
5.00 star(s)

TuxTalk

Level 12
Thread author
Verified
Top Poster
Well-known
Nov 9, 2022
576
1720862978935.png


ZoneAlarm emulation detects stuff like phishing pdf documents, simple PowerShell keyloggers and many others. Stuff that nobody else would detect. At the same time, anti-phishing with real time analysis blocks more pages than big brands like Norton ever will.

Components like Anti-Bot and Behavioural Guard block advanced attacks, the behavioural blocking is based around Mitre tactics and techniques and not just around profiles, like SONAR or ATD (Bitdefender). The level of cleanup after a threat is amazing too, if you have a look at the forensic reports.

All in all, awesome product and all the advanced technology is dressed in a very simple UI with no muss and fuss, unlike Eset for example, with 1000 settings and potential configurations, tweaks and then upon failure, they will turn around and say you don’t understand the software.

1720863087170.png

1720863106318.png

1720863149602.png

1720863128225.png
 

TuxTalk

Level 12
Thread author
Verified
Top Poster
Well-known
Nov 9, 2022
576
Latest QuasarRAT dll file

Screenshot 2024-07-12 105803.png


Low Detection on VT
Screenshot 2024-07-12 105655.png


Blocked by ZoneAlarm by FileReputation !
Screenshot 2024-07-12 105718.png



Another awesome Job by ZA.
 
  • Like
Reactions: Trident

Moonhorse

Level 38
Verified
Top Poster
Content Creator
Well-known
May 29, 2018
2,728
Does zonealarm still use kaspersky engine? and it seems license of 2 years costs like 50eur wich is reasonable, but its 60% off , are you able to grab this ''cheap'' license after the 2 year license expires or how often ZonAlarm is on sale usually?

Not buying it anytime soon, but interested of the future of zonealarm indeed, sadly the free version is poor and should not even exist
 

TuxTalk

Level 12
Thread author
Verified
Top Poster
Well-known
Nov 9, 2022
576
Does zonealarm still use kaspersky engine? and it seems license of 2 years costs like 50eur wich is reasonable, but its 60% off , are you able to grab this ''cheap'' license after the 2 year license expires or how often ZonAlarm is on sale usually?

Not buying it anytime soon, but interested of the future of zonealarm indeed, sadly the free version is poor and should not even exist
Bought one year for now made a deal as soon as it expires they give me a good renewal deal. To be honest @Moonhorse Trend can not compete against ZoneAlarm.
According to @Trident its most on the time " on Sale "
 

BSONE

Level 2
Feb 17, 2024
71
I gave Trend Micro Total Security a try last week without incident. Time to change again. I might give the man with the Spear an opportunity to advise before the final in Berlin:):)
 
  • Like
Reactions: TuxTalk

gery79

Level 12
Verified
Top Poster
Well-known
Jun 21, 2011
583
Does zonealarm still use kaspersky engine? and it seems license of 2 years costs like 50eur wich is reasonable, but its 60% off , are you able to grab this ''cheap'' license after the 2 year license expires or how often ZonAlarm is on sale usually?

Not buying it anytime soon, but interested of the future of zonealarm indeed, sadly the free version is poor and should not even exist
my question too
 

Trident

Level 34
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
my question too
No, ZoneAlarm and Check Point use Sophos engine now, which is there just to provide local signatures (something Check Point does not do in software products, just in their Next Gen Firewall). The Sophos engine is very unimportant in the whole mix and runs with dynamic analysis (in-memory emulation) off, according to my communication with the company.

At the heart of Check Point products is proprietary technology, like Threat Cloud, which is a collection of 60+ engines and growing, Endpoint Forensics and Behavioural Guard, Anti-Bot and NGAV (Deep Learning antivirus) that covers executables, modules and office files. The Check Point NGAV also performs dynamic analysis and binary disassembly.

For an even better experience, Harmony Endpoint is available, but ZoneAlarm Extreme Security NextGen is also not bad at all.
 

Trident

Level 34
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
How "light on resources" is it really ?

I take it then that the free version only has the Sophos sigs and none of the next gen stuff.

Regards Eck :)
It is not light on memory usage, it is the Bitdefender level in terms of memory. But it is light on everything else. That being said, CPU usage will be a bit higher than Norton let’s say, because trusted processes are not excluded from behavioural monitoring and recording (Trend Micro is another software that doesn’t monitor anything digitally signed). The only thing that is excluded from monitoring is wuaclt.exe (Windows Update Modules Install Worker).

Another thing that needs to be known about anti-ransomware is, it does not allow third-party software to delete volume shadow copies, or mess with settings such as Bitlocker, secure boot and others. Any software that attempts to do that is treated as malware and even the desktop shortcut will be purged.
 

Behold Eck

Level 18
Verified
Top Poster
Well-known
Jun 22, 2014
864
It is not light on memory usage, it is the Bitdefender level in terms of memory. But it is light on everything else. That being said, CPU usage will be a bit higher than Norton let’s say, because trusted processes are not excluded from behavioural monitoring and recording (Trend Micro is another software that doesn’t monitor anything digitally signed). The only thing that is excluded from monitoring is wuaclt.exe (Windows Update Modules Install Worker).

Another thing that needs to be known about anti-ransomware is, it does not allow third-party software to delete volume shadow copies, or mess with settings such as Bitlocker, secure boot and others. Any software that attempts to do that is treated as malware and even the desktop shortcut will be purged.
Thanks for the detailed heads up.

Regards Eck :)
 

Trident

Level 34
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
The behavioural blocking and forensics is divided in 5 "branches". Screenshots captured from Harmony Endpoint, but ZoneAlarm is a rebrand, it uses the same EFR engine. It even generates the same report, but it is not easily accessible.
The report is enriched with MalwareDNA and VirusTotal Lookups.
1720887066009.png


Branch 1: EFR (detects Mitre tactics and techniques, does not wait for a full chain of events to be performed, captured and classified). This type is based entirely on offline machine learning and definitions updated daily.
Example:
1720885103139.png


Branch 2: Policy Enforcement: Does not allow stuff like PowerShell obfuscation, script interpreters connecting to websites like pastebin and others. This is based on local signatures as well.
Example:
1720885307362.png
1720885333862.png


Branch 3: Behavioural profiles: Detects threats based on specific behavioural profile. This is based on online machine learning and deep learning (AI).
Example:
1720885427397.png
1720886208076.png


Branch 4: Anti-Bot: Detects bots based on traffic signatures saved locally (somewhat similar to an IPS), online repository with bots/botnets command and control servers, and bot-like behaviour. Once a bot is detected, everything related to the incident is deleted and activity is reversed, as much as possible. Also detects attempts for usage of vulnerabilities/exploits, much like IPS.
Example:
1720885638355.png
1720888652534.png


Branch 5: Anti-ransomware: Detects ransomware based on honeypots, behavioural profiling, policy enforcement. Includes local and online machine learning models.
Example:
1720885808790.png
1720885834785.png
 
Last edited:

Trident

Level 34
Verified
Top Poster
Well-known
Feb 7, 2023
2,351
It doesn't seem possible to delete a quarantined file. There is also no way to manually check for updates.
Not allowed normally, quarantine management is coming soon, but as a workaround, one can open C:/Program Files (X86)/Check Point/Endpoint Security/Remediation and use the quarantine manager there, in that folder.

There is nothing to update, the Sophos engine receives push updates (usually 1-2 files, kilobytes in size daily). Behavioural guard is updated once a day and updates are delivered when you turn your PC on. Anti-bot traffic signatures are delivered when needed, usually every 2 weeks. The rest is updated only when there is a program update. This is what the NextGen concept is, usage of technologies that don't need update every 2 hours to work.
 
Last edited:

likeastar20

Level 9
Verified
Mar 24, 2016
419
Not allowed normally, quarantine management is coming soon, but as a workaround, one can open C:/Program Files (X86)/Check Point/Endpoint Security/Remediation and use the quarantine manager there, in that folder.

There is nothing to update, the Sophos engine receives push updates (usually 1-2 files, kilobytes in size daily). Behavioural guard is updated once a day and updates are delivered when you turn your PC on. Anti-bot traffic signatures are delivered when needed, usually every 2 weeks. The rest is updated only when there is a program update. This is what the NextGen concept is, usage of technologies that don't need update every 2 hours to work.
pressing Permanently Delete doesn't actually do anything
Capture.PNG
 
  • Like
Reactions: shobhita.ratheesh1

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top