The Behavioral Guard & Anti-Ransomware Component

Behavioral Guard constantly monitors files and network activity for suspicious behavior.

Note:

Behavioral Guard also parses the email (through an add-in to Microsoft Outlook) to include the details in the forensics report in the event of a malicious attack through an email.

The Anti-Ransomware creates honeypot files on client computers, and stops the attack immediately after it detects that the ransomware modified the files.

Starting from version E88.50 and later, the Anti-Ransomware creates the honeypot files in these folders:

  • Drive root (C:\ , D:\ , Etc)

  • C:\Users\Public\Music

  • C:\Users\<User>\Music (MyMusic)

  • C:\Users\Public\Documents

  • C:\Users\<User>\Documents (MyDocuments)

  • C:\Users\Public\Videos

  • C:\Users\<User>\Videos (MyVideos)

  • C:\Users\Public\Pictures

  • C:\Users\<User>\Pictures (MyPictures)

  • C:\Program Files (x86)

  • C:\ProgramData

  • C:\Users\<User>\AppData\Roaming

  • C:\Users\<User>\AppData\Local

For versions prior to E88.50, the Anti-Ransomware creates the honeypot files in these folders:

  • C:\Users\Public\Music

  • C:\Users\<User>\Music (MyMusic)

  • C:\Users\Public\Documents

  • C:\Users\<User>\Documents (MyDocuments)

  • C:\Users\Public\Videos

  • C:\Users\<User>\Videos (MyVideos)

  • C:\Users\Public\Pictures

  • C:\Users\<User>\Pictures (MyPictures)

  • C:\Program Files (x86)

  • C:\ProgramData

  • C:\Users\<User>\AppData\Roaming

  • C:\Users\<User>\AppData\Local

Starting with version E88.41 and later, folders with restricted access are identified by a lock icon next to the folder name.

For example:

For versions prior to E88.41, folders with restricted access are identified by a lock icon next to the folder name.

For example:

The file names include these strings, or similar:

  • CP

  • CheckPoint

  • Check Point

  • Check-Point

  • Sandblast Agent

  • Sandblast Zero-Day

  • Endpoint

Before ransomware attack can encrypt files, Anti-Ransomware backs up your files to a safe location. After the attack is stopped, it deletes files involved in the attack and restores the original files from the backup location.

  • Prevent - The attack is remediated. Logs, alerts and a forensic report are created.

  • Detect - Logs, alerts and a forensic report are created.

  • Off - Nothing is done on the detection, a log is not created