Advanced Behavioral Guard & Anti-Ransomware Settings

Enable network share protection - Enables the protection of shared folders on the network. All shared folders are protected, regardless of the protocol. Remote devices are not protected.

Block Volume Encryption tools (BitLocker and Similar Tools): As many ransomwares use volume encryption software, such as BitLocker to encrypt drives.

Note:

This feature is supported with the Endpoint Security Client version E86.30 with the default client mode as Detect. With the Endpoint Security Client version E86.50 and higher, the default client mode is Prevent.

You can block such programs from:

  • Encrypting unencrypted drives

  • Modifying the encryption of encrypted drives (such as changing password)

If you want to encrypt your drive with BitLocker or a similar software:

  • Encrypt the drive before you install the Endpoint Security Client, or

  • Disable this protection, encrypt and resume this protection

Allow extensive data collection: Allow Endpoint Security to collect extended information from endpoints.

Note:

This may increase the resources used.

Low memory mode:

This setting reduces memory usage by loading a carefully selected subset of threat signatures, optimized for protection effectiveness and minimal memory footprint. While this can help improve performance on devices with limited memory, it may slightly reduce detection coverage in some scenarios.

Check Point recommends to enable this mode only on systems with low memory capacity, where resource constraints justify the trade-off.

Note:

The Low memory mode setting is supported starting with Endpoint Security Client version E87.30 and above.

Backup Settings

When Anti-Ransomware is enabled, it constantly monitors files and processes for unusual activity. Before a ransomware attack can encrypt files,Anti-Ransomware backs up your files to a safe location. After the attack is stopped, it deletes files involved in the attack and restores the original files from the backup location.

  • Restore to selected location - By default, files are restored to their original location. To restore files to a different location, select this option and enter the location to which you want to restore the files in the Choose location field. Each time files are automatically restored, they will be put in the selected location.

  • Anti-Ransomware maximum backup size on disk - Set the maximum amount of storage for Anti-Ransomware backups. The default value is 1 GB.

  • Backup time interval - Within this time interval, each file is only backed up one time, even if it is changed multiple times. The default value is 60 minutes.

  • Backup Settings - Change default types to be backed up - Click this to see a list of file types that are included in the Anti-Ransomware backup files. You can add or remove file types from the list and change the Maximum Size of files that are backed up.

    Note:
    • By default, the maximum file size for back up is 25 MB. To change the maximum file size, edit the Maximum Size (MB).

    • For information on the Endpoint Security folder, see sk147454.

  • Disk Usage - By default, Forensics uses up to 1 GB of disk space on the client computer for data.