Based Security Flashcards
are two different types of programs that mitigate exposure to viruses and other types of malicious software. As we already know, all viruses are malware, but not all malware is a virus. This is an important fact, because these programs perform different things
Anti-virus and Anti-malware
is software utility that is designed to specifically defend AGAINST viruses, and prevents viruses from infecting corrupting the system. Antivirus software will frequently scan the system that it is installed on in search of viruses that may have infected it. If any viruses are identified by the antivirus software, it will then take action by quarantining the virus and removing it from the system.
Anti-virus
software however, is VERY similar to antivirus software, though as the name suggests it’s main goal is to defend against ALL MALWARE, this includes viruses, as well as trojans, rootkits, bots, spyware, ransomware, etc.
Anti-malware
McAfee Internet Security (Anti-Malware Software)
- McAfee provides continuous protection against threats like viruses, ransomware, and even phishing attacks (more accurately, some of the malware that the exists within the links and attachments of phishing emails).
- We can use common processes that are associated with McAfee, in order to identify when it is running on a targeted device.
are indicators of McAfee running on a targeted device: Processes
- McScript.exe
- UpdaterUI.exe/UdateUI.exe
- naPrsMgr.exe
- FrameworkService.exe
- Cleanup.exe
- CmdAgent.exe
- McScrip_InUse.exe
- McTray.exe
are indicators of McAfee running on a targeted device: Registry Keys
HKLM\SOFTWARE\McAfee
are indicators of McAfee running on a targeted device: DIR structures / Associated Ports
Directory Structures Associated Ports
C:\Program Files\McAfee\ Port 6646
C:\Program Files\Common Files\McAfeeData Port 8081 (Open if sending
logs to ePO server)
C:\Program Files\Common Files\McAfee
is an anti-malware and firewall solution, designed specifically for servers and workstations
Symantec Endpoint Protection (SEP)
The main goal for ________ is to reduce attack surfaces, prevent attacks and breaches, as well as detect and respond to attacks
Symantec Endpoint Protection
_______ provides flexibility through the ability to be configured as a cloud-based, on-premise or hybrid implementation
Symantec Endpoint Protection
______________ provides intrusion prevention, file behavior monitoring and defends servers and workstations against malware, to include Zero-Day Attacks
Symantec Endpoint Protection
indicators of SEP (Anti-Malware Software) running on a targeted device: Processes
- SymCorpUI.exe
- Semsvc.exe
- ccSvcHst.exe
- ccApp.exe
- LUALL.exe
- SMC.exe
- SMCgui.exe
- Rtvscan.exe
- LuComServer.exe
- ProtectionUtilSurrogate.exe
SEP DIR structures / Registry Key
Directory Structures :
C:\Program Files\Common Files\Symantec Endpoint
Registry Key :
HKLM\SOFTWARE\Symantec\Symantec Endpoint
_______ opens various ports depending on enabled features, making it difficult to ID via port scan
SEP
_______________ is endpoint security software developed by Kaspersky Lab, that protects against viruses, trojans, works, rootkits, keyloggers, man-in-the-middle attacks, sophisticated botnets and other threats to endpoint devices
Kaspersky Internet Security
_____________ provides proactive detection through frequent scanning, blocks threats before they occur and if it detects an immediate threat, it will then quarantine and remove it from the system. __________________ also prevents email spam, phishing attempts and data leaks
Kaspersky Internet Security
indicators of Kaspersky Internet Security (Anti-Malware Software) running on a targeted device: Processes
Processes:
avp.exe
Kaspersky Internet Security is known to open a port listener on:
Port 1110
indicators of Kaspersky Internet Security (Anti-Malware Software) running on a targeted device: Directory / Registry Keys
Directory Structure:
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security
Registry Keys:
HKLM\SOFTWARE\KasperskyLab
indicators of Kaspersky Internet Security (Anti-Malware Software) running on a targeted device: Internet Security is known to open a port listener on _____
Port 1110
What type of software protects against viruses, rootkits, trojans, worms and other harmful software?
Anti-Malware