- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
What is the meaning of "HEUR":Exploit.Signature in the signature detection phase?
Does this mean it's some kind of heuristic signature?
For example:
On ThreatWiki | Check Point Software i need to search for Exploit.Msoffice.Cve-2017-0199.ex
However in the detection alert i have:
HEUR:Exploit.Msoffice.Cve-2017-0199.ex
That seems a logical answer - which values apart from HEUR: are else displayed in the signature detection phase?
I can see some more values:
UDS
not-a-virus
Are those values explained somewhere? The pink console of R80.20 SmartConsole and the yellowish traditional R77.30 SmartEndpoint make for a good blend of windows, but the fact is we have no clear explanation of what we are seeing. And combined with the fact that the logging is borderline dysfunctional for search purposes (see discussion here Endpoint Logging - Events ) i have the clear feeling we are doing Empirical Security here. We have a good hunch as to what is happening but we can't know for sure - i mean, we should go for the well known Check Point Sandblast Mobile approach where there's one Button saying "OK" or one button "NOT OK" and leave the investigations for support or something like that.
Am i missing some kind of documentation? I've checked Admin Guides and support center. Found some reference here in sk131312 but this one only states how to create an exception but does not list all protections.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY