<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hello, good day,  My question is oriented to the Antiramsomware module for the solution of Sandblast Agent, there would be some conflict with a solution like PGP at the time when a file is encrypted by means of PGP, that would happen with the Antirams in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hello-good-day-My-question-is-oriented-to-the-Antiramsomware/m-p/3381#M14250</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is always a context around a Ransomware attack. SBA is not looking if the file is encrypted, because Ransomware not always encrypt, so you will not be able always to restore files even when a ransom is payed. SBA looks for automated attempts to modify the files, but also needs to define if that modification was because a Ransomware attack, so it will start analyzing all activities around. Once the context is defined and the model created, the restoration can happen.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are just encrypting a file, there is no context or indicators around you to believe there is an attack and trigger analysis.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Jun 2017 15:17:24 GMT</pubDate>
    <dc:creator>Javier_Padilla</dc:creator>
    <dc:date>2017-06-06T15:17:24Z</dc:date>
    <item>
      <title>Hello, good day,  My question is oriented to the Antiramsomware module for the solution of Sandblast Agent, there would be some conflict with a solution like PGP at the time when a file is encrypted by means of PGP, that would happen with the Antiramsomwa</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hello-good-day-My-question-is-oriented-to-the-Antiramsomware/m-p/3379#M14248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, good day,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is oriented to the Antiramsomware module for the solution of Sandblast Agent, there would be some conflict with a solution like PGP at the time when a file is encrypted by means of PGP, that would happen with the Antiramsomware module, in this case would act ?? Or as required so that it is not activated under this activity.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 May 2017 17:57:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hello-good-day-My-question-is-oriented-to-the-Antiramsomware/m-p/3379#M14248</guid>
      <dc:creator>Mauricio_Andres</dc:creator>
      <dc:date>2017-05-18T17:57:08Z</dc:date>
    </item>
    <item>
      <title>Re: Hello, good day,  My question is oriented to the Antiramsomware module for the solution of Sandblast Agent, there would be some conflict with a solution like PGP at the time when a file is encrypted by means of PGP, that would happen with the Antirams</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hello-good-day-My-question-is-oriented-to-the-Antiramsomware/m-p/3380#M14249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="padding-bottom: 12px; color: #000000; font-family: HelveticaNeue, 'Helvetica Neue', sans-serif; font-size: 16px;"&gt;Sorry for the delayed response.&lt;/P&gt;&lt;P style="padding-bottom: 12px; color: #000000; font-family: HelveticaNeue, 'Helvetica Neue', sans-serif; font-size: 16px;"&gt;In general, we should not trigger if you use PGP. &lt;/P&gt;&lt;P style="padding-bottom: 12px; color: #000000; font-family: HelveticaNeue, 'Helvetica Neue', sans-serif; font-size: 16px;"&gt;Typical PGP use cases will involve encrypting a file and storing the encrypted file as a pgp file. The original file itself will not be modified. This will not trigger AR.&lt;/P&gt;&lt;P dir="ltr" style="color: #000000; font-family: HelveticaNeue, 'Helvetica Neue', sans-serif; font-size: 16px;"&gt;Even if the original file is modified it would take a lot of such files to be modified for their to be a detection.&lt;/P&gt;&lt;P dir="ltr" style="color: #000000; font-family: HelveticaNeue, 'Helvetica Neue', sans-serif; font-size: 16px;"&gt;&lt;/P&gt;&lt;P dir="ltr" style="color: #000000; font-family: HelveticaNeue, 'Helvetica Neue', sans-serif; font-size: 16px;"&gt;If you find it does, we can work the issue through support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 May 2017 16:45:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hello-good-day-My-question-is-oriented-to-the-Antiramsomware/m-p/3380#M14249</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-05-29T16:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Hello, good day,  My question is oriented to the Antiramsomware module for the solution of Sandblast Agent, there would be some conflict with a solution like PGP at the time when a file is encrypted by means of PGP, that would happen with the Antirams</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hello-good-day-My-question-is-oriented-to-the-Antiramsomware/m-p/3381#M14250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is always a context around a Ransomware attack. SBA is not looking if the file is encrypted, because Ransomware not always encrypt, so you will not be able always to restore files even when a ransom is payed. SBA looks for automated attempts to modify the files, but also needs to define if that modification was because a Ransomware attack, so it will start analyzing all activities around. Once the context is defined and the model created, the restoration can happen.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are just encrypting a file, there is no context or indicators around you to believe there is an attack and trigger analysis.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jun 2017 15:17:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hello-good-day-My-question-is-oriented-to-the-Antiramsomware/m-p/3381#M14250</guid>
      <dc:creator>Javier_Padilla</dc:creator>
      <dc:date>2017-06-06T15:17:24Z</dc:date>
    </item>
  </channel>
</rss>

