楼主: Miostartos
收起左侧

[一般话题] WD的PUA/PUP检测可以手动打开了。

[复制链接]
EnZhSTReLniKoVa
发表于 2018-8-29 23:49:44 | 显示全部楼层
ELOHIM 发表于 2018-8-29 20:47
我感觉我被君大欺负了。哈哈。。
没听懂。。
那说明书,太长太长太长,,,看不懂。。

前2天 才给一些同事 讲解了WD的使用说明书。个人版 也能使用部分企业版功能。至于怎么开 我还是不透露了。

评分

参与人数 1人气 +1 收起 理由
驭龙 + 1

查看全部评分

ELOHIM
发表于 2018-8-30 16:39:34 | 显示全部楼层
君陌潇 发表于 2018-8-29 23:49
前2天 才给一些同事 讲解了WD的使用说明书。个人版 也能使用部分企业版功能。至于怎么开 我还是不透露了 ...

还是不要透露的好,这WD查杀率上去的同时,误报简直翻天了。
EnZhSTReLniKoVa
发表于 2018-8-30 16:46:16 | 显示全部楼层
ELOHIM 发表于 2018-8-30 16:39
还是不要透露的好,这WD查杀率上去的同时,误报简直翻天了。

误报还好, 分析后 自己会处理的
ELOHIM
发表于 2018-8-30 16:59:01 | 显示全部楼层
君陌潇 发表于 2018-8-30 16:46
误报还好, 分析后 自己会处理的

en na

最近开了好多计算机的SHARE,好怕怕。
EnZhSTReLniKoVa
发表于 2018-8-30 18:51:58 | 显示全部楼层
ELOHIM 发表于 2018-8-30 16:59
en na

最近开了好多计算机的SHARE,好怕怕。

Potentially unwanted applications
Some applications do not exhibit malicious behavior but can adversely impact the performance or use of devices. We classify these as potentially unwanted applications (PUA). For example, we noted the increased presence of legitimate cryptocurrency miners in enterprise environments. While some forms of cryptocurrency miners are not malicious, they may not be authorized in enterprise networks because they consume computing resources.

Unlike malicious software and unwanted software, potentially unwanted applications are not malware. Enterprise security administrators can use the PUA protection feature to block these potentially unwanted applications from downloading and installing on endpoints. PUA protection is enabled by default in Windows Defender ATP when managed through System Center Configuration Manager.

In March 2018, we started surfacing PUA protection definitions on VirusTotal. We have also updated our evaluation criteria page to describe the specific categories and descriptions of software that we classify as PUA. These are:

Browser advertising software: Software that displays advertisements or promotions or prompts the user to complete surveys for other products or services in software other than itself. This includes, for example, software that inserts advertisements in browser webpages.

Torrent software: Software that is used to create or download torrents or other files specifically used with peer-to-peer file-sharing technologies.

Cryptomining software: Software that uses your computer resources to mine cryptocurrencies.

Bundling software: Software that offers to install other software that is not digitally signed by the same entity. Also, software that offers to install other software that qualify as PUA based on the criteria outlined in this document.

Marketing software: Software that monitors and transmits the activities of the user to applications or services other than itself for marketing research.

Evasion software: Software that actively tries to evade detection by security products, including software that behaves differently in the presence of security products.

Poor industry reputation: Software that trusted security providers detect with their security products. The security industry is dedicated to protecting customers and improving their experiences. Microsoft and other organizations in the security industry continuously exchange knowledge about files we have analyzed to provide users with the best possible protection.

Customer protection is our top priority. Windows Defender Advanced Threat Protection (Windows Defender ATP) incorporates next-generation protection, attack surface reduction, endpoint detection and response, and automated investigation and remediation, and advanced hunting capabilities. We adjust, expand, and update our evaluation criteria based on customer feedback as well as new and emerging trends in the threat landscape. We encourage customers to help us identify new threats and other undesirable software by submitting programs that exhibit behaviors outlined in the evaluation criteria.

EnZhSTReLniKoVa
发表于 2018-8-30 18:58:03 | 显示全部楼层
ELOHIM 发表于 2018-8-30 16:59
en na

最近开了好多计算机的SHARE,好怕怕。



In Windows 10 Creators Update, the Windows Defender AV client uploads suspicious files to the cloud protection service for rapid analysis. While waiting for a verdict, the Windows Defender AV client maintains a lock on the dubious files, preventing possible malicious behavior. The Windows Defender AV client then takes action based on the verdict. For example, if the cloud protection service determines the file as malicious, it blocks the file from running, providing instant protection.

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
HEMM
发表于 2018-8-31 00:36:00 | 显示全部楼层
双击驭龙的注册表打开的我是。
并且最近调试云到高,感觉还成,没什么大变化.....
ELOHIM
发表于 2018-8-31 09:24:59 | 显示全部楼层
君陌潇 发表于 2018-8-30 18:58
In Windows 10 Creators Update, the Windows Defender AV client uploads suspicious files to the  ...


我现在用的win 7,
SCEP已经打开了PUA功能了。
EnZhSTReLniKoVa
发表于 2018-8-31 10:22:29 | 显示全部楼层
ELOHIM 发表于 2018-8-31 09:24
我现在用的win 7,
SCEP已经打开了PUA功能了。

WIN7 劝你 不要用SCEP。。。
ELOHIM
发表于 2018-8-31 10:23:33 | 显示全部楼层
君陌潇 发表于 2018-8-31 10:22
WIN7 劝你 不要用SCEP。。。

又是WHY。。

太容易过是吗???
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-23 20:08 , Processed in 0.103870 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表