Protection policy

Prev Next

The Protection policy uses malware detection and quarantine to secure your Windows endpoints. You can configure different malware scanning engines, define on-demand and event-based scans, and set quarantine actions for infected files.

Protection

Option

Definition

Signature and Heuristic Detection

Combines signature-based detections of Bitdefender for known threats and heuristic detection for unknown threats. The first Bitdefender update occurs within 1 to 7200 seconds of installation, with subsequent updates downloaded every two hours.

Note

The content update interval from Bitdefender cannot be customized.

Malware Guard Detection

Provides advanced detection against zero-day threats using the Malware Guard Engine, which receives threat updates from DTI.

Cloud lookup

Uses Bitdefender’s cloud-based verification system to identify malware authenticity.

Note

The malware protection service is not enabled by default when the EDRF is deployed.

Malware Detection Options

Option

Definition

Scan network files

To use Malware Detection Options, enable the Scan network files option. The scan options include:

  • Scan on file read only: Scans occur when a file is read from a network location.

  • Scan on file write only: Scans occur when a file is written to a network location.

  • Scan on both file read and write: Provides the most comprehensive scanning for network files.

Enable archive file scan

Allows the scanner to check for malware in compressed files like .zip or .rar. This feature lets you specify the number of nested layers to scan.

Default: 4

On-Demand Malware Scans

On-demand malware scan actively inspects endpoint files, memory, and system areas for malicious software. Its primary purpose is to proactively find dormant or hidden threats that may not be actively running on the endpoint. You can define the scan depth and configure options to allow users to cancel or pause scans. Alerts from these scans are visible in the Forensics workspace or in ePO Threat Events.

Option

Definition

Scan on Install

Triggers an on-demand malware scan when new malware signatures are installed or updated on the endpoint.

User cancelled scans

Allows users to terminate a running scan.

User paused scans

Allows users to pause a running scan; the pause duration and limit are customizable.

Pause duration

Specifies the duration, in minutes, for which a paused scan remains suspended.

Default: 60 minutes

Pause limit(per scan)

Specifies the maximum number of times a single scan can be paused.

Default: 10 times

While some features are available in the Forensics workspace, scheduling time-based and event-based scans is supported only through ePO.

To schedule an On-Demand Malware Scan:

  1. In ePO, go to MenuSystemsSystem Tree.

  2. Select a system or a group.

  3. Navigate to Assigned Policies and select New Client Task Assignment.

  4. Enter the details pertaining to the task and click Save.

Event-Based Scan

Triggers a targeted malware scan when a specific event occurs, rather than on a fixed schedule. Scans can be triggered by a signature content update, an endpoint boot, or a USB insertion.

Option

Definition

Event-Based Scan

Available scan types include :

  • Full Scan — Scans the entire endpoint disk.

  • Quick Scan — Scans a predefined set of folders.

  • Active memory Scan — Scans the system's live memory for threats.

    Note

    An in-memory cache for Malware Guard helps reduce full scan times.

Protection Exclusions

Exclude specific files, folders, MD5 hashes, or processes from malware scanning. By using these exclusions, you can install and run another antivirus or third-party security product alongside the current one without causing conflicts or performance issues.

Option

Definition

Exclude process(es) by full path from malware scanning

Excludes specific processes from being scanned based on their full file path.

Exclude files or folders from malware scanning

Excludes specific files or folders from being scanned.

Exclude hashes from malware scanning

Excludes files with a specific MD5 hash from being scanned, regardless of their name or location.

Quarantine

Quarantine isolates infected files to stop threats from spreading. Cleaned files can be restored, while the files that cannot be cleaned are deleted.

The ProRem service manages quarantine actions on Windows endpoints. This service is not enabled by default but runs continuously once both Signature and Heuristic Quarantine and Malware Quarantine are enabled. To enable the service, select the Enable Protection and Remediation under Quarantine settings.

Option

Defintion

Signature and Heuristic Quarantine

Quarantines files detected by signature and heuristic scanning.

MalwareGuard Quarantine

Quarantines files detected by the MalwareGuard engine.

Enable Protection and Remediation

Enables the EDRF Client to clean quarantined files, remove malware traces, and notify users.

Delete files from quarantine that are older than

Specifies the number of days after which quarantined files are automatically deleted.

Default: 90 days

Note

Quarantined files are automatically purged after 90 days of inactivity. This duration can be customized.

Quarantine Actions

Option

Defintion

Remove malware traces(once quarantined)

Removes malware traces from a file if the cleaning process is successful.

Notify the users on the host when a file has been quarantined or cleared

Displays a notification on the endpoint when a file is quarantined or cleaned.

Quarantine malicious archives

Infected files within archives that cannot be cleaned are permanently deleted from the endpoint.

Quarantine Exclusions

Option

Definition

Exclude Heuristic Detection from quarantine and other protection actions

Excludes threats identified by heuristics-based detection from quarantine actions.

Exclude Adware from quarantine and other protection actions

Excludes adware from quarantine and protection actions for specific host sets.

Exclude PUP from quarantine and other protection actions

Excludes Potentially Unwanted Programs (PUP) from quarantine and protection actions.

Exclude Spyware from quarantine and other protection actions

Excludes spyware from quarantine and protection actions for specific host sets.

Content Backup

Option

Definition

Enable AV Content Backup

Backs up the two most recent Bitdefender content versions on your endpoints. If the latest content update is corrupt, the engine automatically reverts to the previous backup.

Content Exclusion List

Specifies a list of content versions to be excluded from updates and backups.

Find the version numbers in the Hosts fields in the Forensics workspace or the Product Properties on the ePO server.