ESET Endpoint Antivirus for Linux – Table of Contents

Protections

Protections guard against malicious system attacks by controlling files, devices and internet communications. For example, remediation will start if an object classified as malware is detected. Protections can eliminate it by blocking it and then cleaning, deleting or moving it to quarantine.

Detection responses

You can configure Reporting and Protection levels of the following categories:

Category

Description

Malware detections (powered by machine learning)

Malware (malicious software) is used as an umbrella term to cover all forms of malicious code. Malware detection is performed by the detection engine module combined with the machine learning component.

Potentially unwanted applications

A broad category of software, whose intent is not as unequivocally malicious as with other types of malware, such as viruses or trojan horses. However, it could install additional unwanted software, change the behavior of the digital device, or perform activities not approved or expected by the user.

Suspicious applications

Suspicious applications include programs compressed with packers or protectors. These types of protectors are often exploited by malware authors to evade detection.

Potentially unsafe applications

Legitimate commercial software that has the potential to be misused for malicious purposes. Examples include remote access tools, password-cracking applications, and keyloggers.

Reporting

Reporting is performed by the detection engine and machine learning component. You can customize the reporting threshold to fit your environment and needs. We recommend that you monitor the behavior within your environment and decide whether a different Reporting setting is more suitable. These reporting settings do not influence blocking, cleaning or deleting objects.

Aggressive

Reporting configured to maximum sensitivity. More detections are reported. The Aggressive setting can falsely identify objects as malicious, and action will be taken with such objects (depending on Protection settings).

Balanced

This setting is an optimal balance between performance and accuracy of detection rates and the number of falsely reported objects.

Cautious

Reporting configured to minimize falsely identified objects while maintaining a sufficient level of protection. Objects are reported only when the probability is evident and matches malicious behavior.

Off

Reporting is not active. Detections are not found, reported or cleaned.

Off is not available for malware reporting and it is default value for potentially unwanted and unsafe applications.

Protection

If an object is reported, the application blocks the object and then cleans, deletes or moves it to the Quarantine.

Aggressive

Reported aggressive (or lower) level detections are blocked, and automatic remediation (i.e., cleaning) is started. This setting is recommended when all endpoints have been scanned with aggressive settings and falsely reported objects have been added to detection exclusions.

Balanced

 

Reported balanced (or lower) level detections are blocked, and automatic remediation (i.e., cleaning) is started.

Cautious

Reported cautious level detections are blocked, and automatic remediation (i.e., cleaning) is started.

Off

Useful to identify and exclude falsely reported objects.

Off is not available for malware protection and it is default value for potentially unwanted and unsafe applications.