The Behavioral Guard & Anti-Ransomware Component
Behavioral Guard constantly monitors files and network activity for suspicious behavior.
Behavioral Guard also parses the email (through an add-in to Microsoft Outlook) to include the details in the forensics report in the event of a malicious attack through an email.
The Anti-Ransomware creates honeypot files on client computers, and stops the attack immediately after it detects that the ransomware modified the files.
For E88.50 and later
Starting from version E88.50 and later, the Anti-Ransomware creates the honeypot files in these folders:
Drive root (C:\ , D:\ , Etc)C:\Users\Public\MusicC:\Users\<User>\Music (MyMusic)C:\Users\Public\DocumentsC:\Users\<User>\Documents (MyDocuments)C:\Users\Public\VideosC:\Users\<User>\Videos (MyVideos)C:\Users\Public\PicturesC:\Users\<User>\Pictures (MyPictures)C:\Program Files (x86)C:\ProgramDataC:\Users\<User>\AppData\RoamingC:\Users\<User>\AppData\Local
For versions prior to E88.50
For versions prior to E88.50, the Anti-Ransomware creates the honeypot files in these folders:
C:\Users\Public\MusicC:\Users\<User>\Music (MyMusic)C:\Users\Public\DocumentsC:\Users\<User>\Documents (MyDocuments)C:\Users\Public\VideosC:\Users\<User>\Videos (MyVideos)C:\Users\Public\PicturesC:\Users\<User>\Pictures (MyPictures)C:\Program Files (x86)C:\ProgramDataC:\Users\<User>\AppData\RoamingC:\Users\<User>\AppData\Local
For E88.41 and later
Starting with version E88.41 and later, folders with restricted access are identified by a lock icon next to the folder name.
For example:

For versions prior to E88.41
For versions prior to E88.41, folders with restricted access are identified by a lock icon next to the folder name.
For example:

The file names include these strings, or similar:
CP
CheckPoint
Check Point
Check-Point
Sandblast Agent
Sandblast Zero-Day
Endpoint
Before ransomware attack can encrypt files, Anti-Ransomware backs up your files to a safe location. After the attack is stopped, it deletes files involved in the attack and restores the original files from the backup location.
Prevent - The attack is remediated. Logs, alerts and a forensic report are created.
Detect - Logs, alerts and a forensic report are created.
Off - Nothing is done on the detection, a log is not created