Advanced Behavioral Guard & Anti-Ransomware Settings
Block Volume Encryption tools (BitLocker and Similar Tools): As many ransomwares use volume encryption software, such as BitLocker to encrypt drives.
This feature is supported with the Endpoint Security Client version E86.30 with the default client mode as Detect. With the Endpoint Security Client version E86.50 and higher, the default client mode is Prevent.
You can block such programs from:
-
Encrypting unencrypted drives
-
Modifying the encryption of encrypted drives (such as changing password)
If you want to encrypt your drive with BitLocker or a similar software:
-
Encrypt the drive before you install the Endpoint Security Client, or
-
Disable this protection, encrypt and resume this protection
Allow extensive data collection: Allow Endpoint Security to collect extended information from endpoints.
This may increase the resources used.
Low memory mode:
This setting reduces memory usage by loading a carefully selected subset of threat signatures, optimized for protection effectiveness and minimal memory footprint. While this can help improve performance on devices with limited memory, it may slightly reduce detection coverage in some scenarios.
Check Point recommends to enable this mode only on systems with low memory capacity, where resource constraints justify the trade-off.
The Low memory mode setting is supported starting with Endpoint Security Client version E87.30 and above.