Kaspersky Anti-Ransomware Tool for Business (Beta)

Discussion in 'other anti-malware software' started by 3x0gR13N, Aug 10, 2016.

  1. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
    Salutations/Greetings!:)

    Tell how Kaspersky stops it that is the ransonware.

    You can jump to 240 on the video! On System Watcher!
    Also, use in Kaspersky Anti-Ransomware Tool for Business.

    https://www.youtube.com/watch?v=yLEYP8728Tg
     
  2. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    Seems to be a very nice software that will complement many security setups.

    The question is just about performance and compatibility, if it is good it will be a no-brainer solution.
     
  3. Djigi

    Djigi Registered Member

    Joined:
    Aug 13, 2012
    Posts:
    554
    Location:
    Croatia
    I think the big question is it gona be free for all or not?
     
  4. Moose World

    Moose World Registered Member

    Joined:
    Dec 19, 2013
    Posts:
    905
    Location:
    U.S. Citizen
  5. They push notes and links to Kapersky lab research blog every now and then. So it is used as a marketing tool now.
     
  6. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    I guess it would be unwise to run this alongside HMP.A?
     
  7. Yes, HPMA should cover it (although video's of Cruel Sister often show HPMA fails against ransomware).
     
  8. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    if its her original video that version is old.
     
  9. With the frequency HPMA is pushing out updates, any version is soon to be old.
     
  10. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Yep, and that's great. They are addressing threats.
     
  11. It pushes out news blurbs of Kapersky Lab research. Also notifies you of news on which you can opt out. So I do not feel spammed (until now). Would be nice when @cruelsister could throw some new ransomware variants to it.
     
  12. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    seems like CS is the go to for all the new products here and on another forum. with good reason. but I think CS is going to be too overwhelmed with requests while holding down a real job and as she has mentioned before she cant test it is conflicts with her job. we are still waiting on a few other programs but if it don't happen that she can test them so be it.
     
  13. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,093
    Location:
    Germany
    For reasons unknown she doesn't touch Kaspersky products.
     
  14. @FleischmannTV

    Thanks, so probably some legal stuff getting in the way related to her work
     
  15. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    1,649
    Location:
    Paris
    Hi Guys- Actually my reticence to test K is more moral than legal, but as I really can't discuss it I'll leave it there. However there comes a time when public good outweighs personal standards so I'll get over myself and this weekend publish Part 1 of 2 on KAR. Just have to pick the music for Part 1 so that should be good to go.

    Glad you guys like the videos.
     
  16. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    Does KAR detect and block malware, other than ransomware?
     
  17. themorpethian

    themorpethian Registered Member

    Joined:
    May 6, 2006
    Posts:
    35
    Cruel How about some Led Zepplin so I dont have turn the volume down LOL
    Always enjoy the vids though and many thanks for your efforts.
     
  18. 3x0gR13N

    3x0gR13N Registered Member

    Joined:
    May 1, 2008
    Posts:
    850
    Of course. It's a behavior blocker with rollback capability, directly from KAV/KIS.
     
  19. @3x0gR13N

    Any reason they specifically removed the anti-exploit monitoring?

    Thx
     
  20. 3x0gR13N

    3x0gR13N Registered Member

    Joined:
    May 1, 2008
    Posts:
    850
    Don't know. Disappointed to see it removed as well. It's possible that the anti-exploit works only if there are other protection components backing it up and providing necessary information about the memory operations, resources etc. used during exploiting.
     
  21. I had thought it would make more sense when they "only" kept the behavioral blocker monitoring file/disk operations and removed all other behavioral monitoring, but the I realised that ransomware also uses credentials of regular process by injecting/launching them plus ransomware tries to hide in autostart entries. For an behaviorial based anti-ransomware to be effective its scope soon ends up to cover 80% of the full behavioral blocker version.
     
  22. haakon

    haakon Guest

    https://www.youtube.com/watch?v=sS_J1UzlPGM

    Pity.
     
  23. Pity?

    Cruel Sister has punched a hole in Kapersky's marketing airbag: yes it does not stand up it promise. It fails against modified/morphed variants, but the signature based detection is excellent :thumb: Compare the results with Cruel Sister's ESET or Bitdefender video's :blink:

    So KapLab-AR is not the ultimate solution to ransomware threats, but it is a light and free addition to a vanilla Windows 10 setup. Smartscreen + WD + KapLab-AR probably outperforms most paid premium brand AV-solutions on Windows 8 and higher.
     
    Last edited by a moderator: Sep 27, 2016
  24. Complex behavioral analysis eats CPU capacity and delays startups of programs. I have put KapLab-AR on my wife's laptop (with 2010 dual core pentium) and it uses less than 0.02% of CPU and delays program startups with less than 0.1 of a second (average AV on execution check delays program startups with 0.2 to 0.5 secs on her laptop).

    After seeing CS video, my take is that behavioral monitor probably builds a local whitelist cache and checks the cloud for blacklisted objects/processes when it detects intrusions from user space folders and user land processes (e.g. monitor side by side attacks on vulnerable medium level IL processes).

    So it probably is a light behavioural monitor designed to selectively check the cloud blacklist (reduce overhead and increase compatibility). My guess is that the promised part2 of CS on KapLab-AR testing the behavioural monitor will be fun to watch.
     
    Last edited by a moderator: Sep 27, 2016
  25. Infected

    Infected Registered Member

    Joined:
    Feb 9, 2015
    Posts:
    1,138
    Even more..

    Code:
    https://www.youtube.com/watch?v=-wjSrTwEuYg
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.