ESET Online Help

Search English
Select the topic

Detection engine

Detection engine guards against malicious system attacks by controlling file, email and internet communication. For example, if an object classified as malware is detected, remediation will start. The detection engine can eliminate it by first blocking it and then cleaning, deleting or moving it to quarantine.

To configure the detection engine settings in detail, click Advanced Setup or press F5.

In this section:


note

Starting in version 7.2, the Detection engine section no longer provides ON/OFF switches as for version 7.1 and below. ON/OFF buttons are replaced with four thresholds - Aggressive, Balanced, Cautious and Off.


 

Real-time & Machine learning protection categories

Real-time & Machine learning protection for all protection modules (for example, Real-time file system protection, Web access protection, ...) allows you to configure reporting and protection levels of the following categories:

  • Malware – A computer virus is a piece of malicious code that is prepended or appended to existing files on your computer. However, the term “virus” is often misused. "Malware” (malicious software) is a more accurate term. Malware detection is performed by the detection engine module combined with the machine learning component.
    Read more about these types of applications in the Glossary.
  • Potentially unwanted applications Grayware or Potentially Unwanted Applications (PUAs) is a broad category of software, whose intent is not as unequivocally malicious as with other types of malware, such as viruses or trojan horses. However, it could install additional unwanted software, change the behavior of the digital device, or perform activities not approved or expected by the user.
    Read more about these types of applications in the Glossary.
  • Potentially unsafe applications – Refers to legitimate commercial software that has the potential to be misused for malicious purposes. Examples of potentially unsafe applications (PUAs) include remote access tools, password-cracking applications, and keyloggers (programs recording each keystroke typed by a user).
    Read more about these types of applications in the Glossary.
  • Suspicious applications include programs compressed with packers or protectors. These types of protectors are often exploited by malware authors to evade detection.

CONFIG_SCANNER


note

Advanced machine learning is now a part of detection engine as an advanced layer of protection which improves detection based on machine learning. Read more about this type of protection in the Glossary.


 

Malware scans

Scanner settings can be configured separately for the real-time scanner and the on-demand scanner. By default, Use real-time protection settings is enabled. When enabled, relevant On-demand scan settings are inherited from the Real-time & Machine Learning protection section.


 

Reporting setup

When a detection occurs (e.g., a threat is found and classified as malware), information is recorded to the Detections log, and Desktop notifications occur if configured in ESET Endpoint Antivirus.

Reporting threshold is configured for each category (referred to as "CATEGORY"):

  1. Malware
  2. Potentially unwanted applications
  3. Potentially unsafe
  4. Suspicious applications

Reporting performed with the detection engine, including the machine learning component. It is possible to set a higher reporting threshold than the current protection threshold. These reporting settings do not influence blocking, cleaning or deleting objects.

Read the following before modifying a threshold (or level) for CATEGORY reporting:

Threshold

Explanation

Aggressive

CATEGORY reporting configured to maximum sensitivity. More detections are reported. The Aggressive setting can falsely identify objects as CATEGORY.

Balanced

CATEGORY reporting configured as balanced. This setting is optimized to balance the performance and accuracy of detection rates and the number of falsely reported objects.

Cautious

CATEGORY reporting configured to minimize falsely identified objects while maintaining a sufficient level of protection. Objects are reported only when the probability is evident and matches CATEGORY behavior.

Off

Reporting for CATEGORY is not active, and detections of this type are not found, reported or cleaned. As a result, this setting disables protection from this detection type.
Off is not available for malware reporting and it is default value for potentially unsafe applications.

hmtoggle_plus0 Availability of ESET Endpoint Antivirus protection modules

hmtoggle_plus0 Determine product version, program module versions and build dates

Keynotes

Several keynotes when setting up an appropriate threshold for your environment:

  • The Balanced threshold is recommended for most of the setups.
  • The Cautious threshold represents a comparable level of protection from previous versions of ESET Endpoint Antivirus (7.1 and below). This is recommended for environments where the priority focuses on minimizing false identified objects by security software.
  • The higher reporting threshold, the higher detection rate but a higher chance of falsely identified objects.
  • From the real-world perspective, there is no guaranty of a 100% detection rate as well as a 0% chance to avoid incorrect categorization of clean objects as malware.
  • Keep ESET Endpoint Antivirus and its modules up-to-date to maximize the balance between performance and accuracy of detection rates and the number of falsely reported objects.

 

Protection setup

If an object classified as CATEGORY is reported, the program blocks the object and then cleans, deletes or moves it to Quarantine.

Read the following before modifying a threshold (or level) for CATEGORY protection:

Threshold

Explanation

Aggressive

Reported aggressive (or lower) level detections are blocked, and automatic remediation (i.e., cleaning) is started. This setting is recommended when all endpoints have been scanned with aggressive settings and falsely reported objects have been added to detection exclusions.

Balanced

Reported balanced (or lower) level detections are blocked, and automatic remediation (i.e., cleaning) is started.

Cautious

Reported cautious level detections are blocked, and automatic remediation (i.e., cleaning) is started.

Off

Useful to identify and exclude falsely reported objects.
Off is not available for malware protection and it is default value for potentially unsafe applications.

hmtoggle_plus0 ESET PROTECT policy conversion table for ESET Endpoint Antivirus 7.1 and below


 

Best practices

UNMANAGED (Individual client workstation)

Keep the default recommended values as is.

MANAGED ENVIRONMENT

These settings are usually applied to workstations via a policy.

1. Initial phase

This phase might take up to a week.

  • Set up all Reporting thresholds to Balanced.
    NOTE: If needed, set up to Aggressive.
  • Set up or keep Protection for malware as Balanced.
  • Set up Protection for other CATEGORIES to Cautious.
    NOTE: It is not recommended to set up the Protection threshold to Aggressive in this phase because all found detections would be remediated, including the falsely identified ones.
  • Identify falsely identified objects from Detections log and add them to Detection exclusions first.

2. Transition phase

  • Implement the "Production phase" to some of the workstations as a test (not for all workstations on the network).

3. Production phase

  • Set up all Protection thresholds to Balanced.
  • When managed remotely, use an appropriate antivirus pre-defined policy for ESET Endpoint Antivirus.
  • Aggressive protection threshold can be set if the highest detection rates are required and falsely identified objects are accepted.
  • Check Detection log or ESET PROTECT reports for possible missing detections.