Frequently Asked Questions (FAQ)
Specifications & Settings
They are currently available for the Windows OS versions as follows: Windows 11, Windows 10, Windows 8.1, Windows 8, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2025 Datacenter Azure Edition, Windows Server 2025 Datacenter Edition (arm64), Windows Server 2025 Datacenter Edition, Windows Server 2025 Essentials Edition, and Windows Server 2025 Standard Edition.
Anti-Ransomware currently supports only the Windows operating system.
Malware Protection Plus's Malware Protection offers offline native protection, allowing devices to be continuously monitored even when they are not connected to the network. This is possible since Malware Protection is not cloud dependent, and unlike traditional antivirus solutions, there is no need to update signature files on a regular basis. Refer here for more information.
Malware Protection definitions are updated on a weekly basis for behavior rules and on a monthly basis for the ML malware engine model.
Next-Gen Antivirus
To generate the first detection in NGAV, kindly follow the steps listed in this page. Also, navigate to the Settings tab and locate the "Notification Settings". Within this section, enable the "User Device Alert Notification" option to receive real-time notifications in the endpoints regarding security events.
Anti-Ransomware
Kindly follow the steps given on this page to run the Ransomware Simulator.
Decoy files protect endpoints against ransomware and add a layer of protection. A set of decoy files is present on all managed endpoints to serve as bait, and in the event of any suspicious activity, such as encryption of the decoy files, an immediate alert is issued, indicating a potential ransomware attack. Upon studying ransomware attacks, we have strategically placed these files in various folders across all managed endpoints. This proactive measure ensures that if the decoy files are encrypted, timely alerts are sent to the administrator for prompt response and mitigation. The bait files' names are "database.docx", "ME.txt", and "screenshoot.jpg".
Decoy/Bait file based detection is one of the several detection methods used by Anti-Ransomware. The core engine of detection is the behavior-based ransomware motive detection along with four accuracy improvement patented layers. For more information, kindly refer to this page.
File-less attacks are particularly difficult to detect since they leave little or no trace on the system. However, Anti-Ransomware's patented ML-assisted behavior detection technique makes it possible to detect file-less attacks on the network.
No, Anti-Ransomware does not scan the systems periodically. Rather, it conducts a real-time analysis of the systems, continuously monitoring them in order to detect and report a ransomware attack as quickly as possible.
The network bandwidth consumption of Anti-Ransomware is nil. This distinguishes Anti-Ransomware from other cloud-based EDR and Anti-Virus solutions because there is no need to often fetch signature database files, which cuts network traffic.
Anti-Ransomware employs anti-hook and anti-kill methods to keep users from killing the agent.
The administrator can stop the agent from the server console by disabling Anti-Ransomware.
Microsoft's Volume Shadow Copy Service (VSS) is utilized to obtain shadow copies of the data stored on your device, every three hours. As a rest, the recovered file is from the most recent backup cycle, which could be 3 hours old.
The backup files are stored on the hard-disk of the endpoint itself. These files are protected by a patented tamper-proof technology.
By default, 10% of the disk space is used by the Windows VSS Service for backup functions.
When the Shadow Storage reaches its capacity, the oldest shadow copy will be deleted to accommodate the new one and optimize storage usage.
No major conflicts are expected. It is designed to coexist with other VSS-based applications, including backup solutions. The only enforced restriction is that other applications cannot reduce the VSS storage allocation below 10% on protected volumes.
The files encrypted by ransomware can be restored as long as backup is available, even if the incident was not raised as an alert.