HitmanPro.Alert BETA

Discussion in 'other anti-malware software' started by erikloman, May 30, 2017.

  1. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I am also running Emisoft and Appguard and I have the Credential Protection on witihout Sam with no problems.
     
  2. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    636
    Location:
    Planet Earth
    I'm sorry haven't scrolled back to the posts, but just Credential theft protection on it's own (don't enable SAM) should run fine and protects you from e.g. mimikatz from stealing your Windows credentials from memory.
    But if one of the others cover that then it's redundant.
     
  3. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
    Okay thanks may enable again sometime.
     
  4. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    +1
     
  5. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Well, I would like a feature to load microcode updates to protect against side channel attacks. A lot of manufacturers don't provide them, though MS is making them available but only for Windows 10. I don't know however if HMP.A is able to do this early enough in the boot process for it to be effective.
    Some smaller points:
    -Exclusions from realtime protection(afaik already on roadmap)
    -Notification of expiring license(also already on roadmap)
    -Improve HMP.A's original functionality, the browser protection. It failed against the Event Tracing for Windows -CLI method: hxxps://www.mrg-effitas.com/wp-content/uploads/2018/06/MRG-Effitas-2018Q1-Online-Banking.pdf
     
  6. guest

    guest Guest

    - an option in tray icon to disable all mitigation and risk reductions; and to exit the GUI.
    - the option to scroll applications (in Mitigation) vertically instead of horizontally.
    - a separate tab for exclusions in Mitigation. (example: Applications, Running Applications, Excluded Applications)
    - an exclude button on the alert popup.
     
  7. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I second all of these.
     
  8. feerf56

    feerf56 Registered Member

    Joined:
    Feb 24, 2015
    Posts:
    324
    False alarm (Windows 10 v.1803 64bit, Firefox Firefox 61.0.1 (64 bites)):

    Snap26.jpg Snap27.jpg Snap28.jpg
     
  9. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,549
    +1
     
  10. Adric

    Adric Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    1,762
    +1
     
  11. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    I would also vote for a more informative tray icon, for instance displaying license status and update availability.
     
  12. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    :thumb:
     
  13. HempOil

    HempOil Registered Member

    Joined:
    Jun 15, 2015
    Posts:
    225
    Location:
    Canada
    Rebooted my system to 3.7.8 build 750 via automatic update. No issues to report.

    As for suggestions for the next version, I don't know how feasible it is, but any measures that can be taken to help protect against the CPU vulnerabilities would be nice. I understand that they tend to be firmware fixes, however, the ChromeZero plugin for Chrome would seem to indicate that software measures can be taken as well.
     
  14. Libraman

    Libraman Registered Member

    Joined:
    Apr 26, 2016
    Posts:
    201

    Attached Files:

    • hpa.jpg
      hpa.jpg
      File size:
      64.9 KB
      Views:
      13
  15. Libraman

    Libraman Registered Member

    Joined:
    Apr 26, 2016
    Posts:
    201
    Always when Firefox has an update (x32/x64)
    'Mitigation Exploit' Off on Firefox and 'Mitigation Exploit' ON again. Restart and work well (normally)
     
  16. Secure_Guy

    Secure_Guy Registered Member

    Joined:
    May 4, 2016
    Posts:
    49
    I have found an issue whereby the Anti-Malware warnings are not shown if back to back infected files are run. I have included a video which shows the issue very easily: https://uploadfiles.io/cjiyd

    The version used is the latest: HitmanPro.Alert 3.7.8.750

    This issue has been happening ever since the Anti-Malware module was added to HitmanPro.Alert, even the first betas.

    I had written about this then, but no-one bothered to fix it, so when I tested the latest build and found the issue still present, I decided to make a video to show exactly what the issue is, and to show how easily its happening. In fact, I'm very surprised this sort of simple bug has been hanging around for so long. I'd have caught this the first time I tested the feature.
     
    Last edited by a moderator: Jul 11, 2018
  17. RonnyT

    RonnyT QA Engineer

    Joined:
    Aug 9, 2016
    Posts:
    636
    Location:
    Planet Earth
    Hi feerf56,
    We need the magic behind the "Technical details" link to see why it determined that firefox was under attack.
    Can check "Number of alerts" and copy/past the text from the Windows Eventlog for this occasion?
     
  18. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    2,865
    Location:
    the Netherlands
    Thanks. I have no idea why this was never noticed.
    Let me include the links to your earlier posts in which you reported the issue:
    June 10, 2017, #202 and #203.
     
  19. Secure_Guy

    Secure_Guy Registered Member

    Joined:
    May 4, 2016
    Posts:
    49
    Thank you.
    I appreciate that you also looked into my earlier posts and linked to those.

    I also agree with the earlier posts that asked for a right click and disable and quit the Hitman.P

    ~ Off Topic Remarks Removed ~
     
    Last edited by a moderator: Jul 12, 2018
  20. feerf56

    feerf56 Registered Member

    Joined:
    Feb 24, 2015
    Posts:
    324
    Hi RonnyT!

    Excuse me! Here you are!
     

    Attached Files:

    Last edited: Jul 13, 2018
  21. feerf56

    feerf56 Registered Member

    Joined:
    Feb 24, 2015
    Posts:
    324
    Again...

    2018-07-14_184128.jpg
     

    Attached Files:

  22. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,549
    I tried it out myself, and yes, it seems that HMPA is compatible with Core isolation.
     
  23. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,549
    And what about the Attack Surface Reduction rules, especially the ones for MS Office?
    Could they potentially conflict with HMPA? It looks like some of the ASR rules are trying to do the same thing as some of the HMPA protections/mitigations.
     
  24. shmu26

    shmu26 Registered Member

    Joined:
    Jul 9, 2015
    Posts:
    1,549
    Feature request: ability to make exceptions for folders.

    Let's say I want to make exceptions for my AV, but it keeps all its executables in a subfolder with the version number in the folder name. If I am able to exclude the main folder of the AV from HMPA protection, then my exclusions will survive a program update.
     
  25. Secure_Guy

    Secure_Guy Registered Member

    Joined:
    May 4, 2016
    Posts:
    49
    I was scanning my computer using the Microsoft Safety Scanner, and this issue cropped up.
    I hope it can be fixed.
    PS: No bad stuff was found during the scan, the message appeared while the scan was happening.
    https://imgur.com/a/x7kUXn6
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.