iDefender (new HIPS for Windows)

Discussion in 'other anti-malware software' started by Rasheed187, Sep 20, 2025.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,596
    Location:
    The Netherlands
    To clarify, I have been using HIPS for the last 20 years, and ''rules per process'' is a standard feature. Obviously, most of the rules are made for semi-trusted processes, because you're not going to make rules for malware, those are simply terminated.

    To be honest, I'm not sure what you mean with ''scenario-based'' rule model, because I suppose iDefender will always alert when a single behavior is triggered, or will it only alert when multiple rules are triggered? That's not the impression that I get from the screenshots though.
     
  2. Trustsing

    Trustsing Specialist

    Joined:
    Jul 23, 2025
    Posts:
    16
    Location:
    China
    Yes, almost all HIPS are process-based as the main entity ("rules per process"). However, this approach has limited scalability and flexibility. The core of HIPS revolves around processes and behaviors, whereas iDefender adopts the opposite logic by using behaviors as the main entity for rule configuration. For instance, to prohibit the launch of certain processes, you only need to set a few process parameters. Similarly, to protect files from being accessed, simply specify the files to be protected and the trusted parameters. iDefender has streamlined various common usage scenarios into templates, allowing users to complete rule setup with just a few parameters, thereby simplifying the complexity of custom rule creation. Many users have previously expressed a desire for process-based rules, but after getting accustomed to behavior-based methods, they found the latter's rule management to be simpler and more flexible. Meanwhile, they have also utilized Folder and Param Group to create their own sets of rules managed by process.
    This is an AI translation, so it might not be the clearest explanation. You could try exploring on your own — once you get familiar with how it works, you’ll probably understand it better.

    The process-based rule template is under development and slated for release in the second upcoming version, in response to demand from the Team version.

    Currently, custom rules only support a single behavior. Some multi-step behaviors are available in the built-in IOA rules.
     
  3. Nastrahl

    Nastrahl Registered Member

    Joined:
    Feb 8, 2017
    Posts:
    27
    Location:
    Paris
    Hello

    Where can I ask for a feature request ?

    I would like to ask if you can let the user to be prompted for rules for which their actions are 'block' only at the moment.

    Thanks
     
  4. Trustsing

    Trustsing Specialist

    Joined:
    Jul 23, 2025
    Posts:
    16
    Location:
    China
    It can be requested via email (support@trustsing.com) or Github issue.
    However, if the action of a rule is only 'block', it generally falls under configuration-type rules or kernel rules (too frequent) and does not support prompts. If there is a specific use case, you can provide a detailed description and later add a rule template to support it, after which a rule that supports prompts can be added.
     
  5. Serphis

    Serphis Registered Member

    Joined:
    Nov 24, 2018
    Posts:
    185
    Location:
    Italy
    Last edited: Nov 25, 2025 at 3:07 AM
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.