Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Trident
Participant

Highly Technical Questions About HEP

I've been using the products for a while and I am on the way to apply for the CP Partnership programme, my website is almost complete and my company's been registered. I'm sure I'll get access to loads of training but there are several technical questions and my curiosity needs satisfying.

 

So, the pre-execution threat prevention ecosystem locally, on-machine, is comprised of:

  • File-level threat emulation
  • Offline reputation
  • Online reputation
  • Anti-malware blade, CP doesn't really like to name so let's call them E1/E2
  • Static analysis for exe, dll and office files.

So first question, upon minifilter capturing a new file, what is the scan flow (sequence) of these engines and how it all comes together?

Also, if I've found the right static analysis patent, it looks like SA also performs dynamic analysis (emulating in HVE portions of the code) and binary disassembly (forgive me if this patent relates to something else). Both E1 and E2 rely heavily on dynamic analysis too. So whose dynamic analysis takes priority - CP proprietary or E1/E2?

 
 
0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events