Protections
Protections guard against malicious system attacks by controlling files, devices and internet communications. For example, remediation will start if an object classified as malware is detected. Protections can eliminate it by blocking it and then cleaning, deleting or moving it to quarantine.
Detection responses
You can configure Reporting and Protection levels of the following categories:
Category |
Description |
|---|---|
Malware (malicious software) is used as an umbrella term to cover all forms of malicious code. Malware detection is performed by the detection engine module combined with the machine learning component. |
|
A broad category of software, whose intent is not as unequivocally malicious as with other types of malware, such as viruses or trojan horses. However, it could install additional unwanted software, change the behavior of the digital device, or perform activities not approved or expected by the user. |
|
Suspicious applications include programs compressed with packers or protectors. These types of protectors are often exploited by malware authors to evade detection. |
|
Legitimate commercial software that has the potential to be misused for malicious purposes. Examples include remote access tools, password-cracking applications, and keyloggers. |
Reporting
Reporting is performed by the detection engine and machine learning component. You can customize the reporting threshold to fit your environment and needs. We recommend that you monitor the behavior within your environment and decide whether a different Reporting setting is more suitable. These reporting settings do not influence blocking, cleaning or deleting objects.
Aggressive |
Reporting configured to maximum sensitivity. More detections are reported. The Aggressive setting can falsely identify objects as malicious, and action will be taken with such objects (depending on Protection settings). |
Balanced |
This setting is an optimal balance between performance and accuracy of detection rates and the number of falsely reported objects. |
Cautious |
Reporting configured to minimize falsely identified objects while maintaining a sufficient level of protection. Objects are reported only when the probability is evident and matches malicious behavior. |
Off |
Reporting is not active. Detections are not found, reported or cleaned. Off is not available for malware reporting and it is default value for potentially unwanted and unsafe applications. |
Protection
If an object is reported, the application blocks the object and then cleans, deletes or moves it to the Quarantine.
Aggressive |
Reported aggressive (or lower) level detections are blocked, and automatic remediation (i.e., cleaning) is started. This setting is recommended when all endpoints have been scanned with aggressive settings and falsely reported objects have been added to detection exclusions. |
Balanced |
Reported balanced (or lower) level detections are blocked, and automatic remediation (i.e., cleaning) is started. |
Cautious |
Reported cautious level detections are blocked, and automatic remediation (i.e., cleaning) is started. |
Off |
Useful to identify and exclude falsely reported objects. Off is not available for malware protection and it is default value for potentially unwanted and unsafe applications. |