The Protection policy uses malware detection and quarantine to secure your Windows endpoints. You can configure different malware scanning engines, define on-demand and event-based scans, and set quarantine actions for infected files.
Protection
Option | Definition |
|---|---|
Signature and Heuristic Detection | Combines signature-based detections of Bitdefender for known threats and heuristic detection for unknown threats. The first Bitdefender update occurs within 1 to 7200 seconds of installation, with subsequent updates downloaded every two hours.
|
Malware Guard Detection | Provides advanced detection against zero-day threats using the Malware Guard Engine, which receives threat updates from DTI. |
Cloud lookup | Uses Bitdefender’s cloud-based verification system to identify malware authenticity. |
Note
The malware protection service is not enabled by default when the EDRF is deployed.
Malware Detection Options
Option | Definition |
|---|---|
Scan network files | To use Malware Detection Options, enable the Scan network files option. The scan options include:
|
Enable archive file scan | Allows the scanner to check for malware in compressed files like .zip or .rar. This feature lets you specify the number of nested layers to scan. Default: 4 |
On-Demand Malware Scans
On-demand malware scan actively inspects endpoint files, memory, and system areas for malicious software. Its primary purpose is to proactively find dormant or hidden threats that may not be actively running on the endpoint. You can define the scan depth and configure options to allow users to cancel or pause scans. Alerts from these scans are visible in the Forensics workspace or in ePO Threat Events.
Option | Definition |
|---|---|
Scan on Install | Triggers an on-demand malware scan when new malware signatures are installed or updated on the endpoint. |
User cancelled scans | Allows users to terminate a running scan. |
User paused scans | Allows users to pause a running scan; the pause duration and limit are customizable. |
Pause duration | Specifies the duration, in minutes, for which a paused scan remains suspended. Default: 60 minutes |
Pause limit(per scan) | Specifies the maximum number of times a single scan can be paused. Default: 10 times |
While some features are available in the Forensics workspace, scheduling time-based and event-based scans is supported only through ePO.
To schedule an On-Demand Malware Scan:
In ePO, go to Menu → Systems → System Tree.
Select a system or a group.
Navigate to Assigned Policies and select New Client Task Assignment.
Enter the details pertaining to the task and click Save.
Event-Based Scan
Triggers a targeted malware scan when a specific event occurs, rather than on a fixed schedule. Scans can be triggered by a signature content update, an endpoint boot, or a USB insertion.
Option | Definition |
|---|---|
Event-Based Scan | Available scan types include :
|
Protection Exclusions
Exclude specific files, folders, MD5 hashes, or processes from malware scanning. By using these exclusions, you can install and run another antivirus or third-party security product alongside the current one without causing conflicts or performance issues.
Option | Definition |
|---|---|
Exclude process(es) by full path from malware scanning | Excludes specific processes from being scanned based on their full file path. |
Exclude files or folders from malware scanning | Excludes specific files or folders from being scanned. |
Exclude hashes from malware scanning | Excludes files with a specific MD5 hash from being scanned, regardless of their name or location. |
Quarantine
Quarantine isolates infected files to stop threats from spreading. Cleaned files can be restored, while the files that cannot be cleaned are deleted.
The ProRem service manages quarantine actions on Windows endpoints. This service is not enabled by default but runs continuously once both Signature and Heuristic Quarantine and Malware Quarantine are enabled. To enable the service, select the Enable Protection and Remediation under Quarantine settings.
Option | Defintion |
|---|---|
Signature and Heuristic Quarantine | Quarantines files detected by signature and heuristic scanning. |
MalwareGuard Quarantine | Quarantines files detected by the MalwareGuard engine. |
Enable Protection and Remediation | Enables the EDRF Client to clean quarantined files, remove malware traces, and notify users. |
Delete files from quarantine that are older than | Specifies the number of days after which quarantined files are automatically deleted. Default: 90 days
|
Quarantine Actions
Option | Defintion |
|---|---|
Remove malware traces(once quarantined) | Removes malware traces from a file if the cleaning process is successful. |
Notify the users on the host when a file has been quarantined or cleared | Displays a notification on the endpoint when a file is quarantined or cleaned. |
Quarantine malicious archives | Infected files within archives that cannot be cleaned are permanently deleted from the endpoint. |
Quarantine Exclusions
Option | Definition |
|---|---|
Exclude Heuristic Detection from quarantine and other protection actions | Excludes threats identified by heuristics-based detection from quarantine actions. |
Exclude Adware from quarantine and other protection actions | Excludes adware from quarantine and protection actions for specific host sets. |
Exclude PUP from quarantine and other protection actions | Excludes Potentially Unwanted Programs (PUP) from quarantine and protection actions. |
Exclude Spyware from quarantine and other protection actions | Excludes spyware from quarantine and protection actions for specific host sets. |
Content Backup
Option | Definition |
|---|---|
Enable AV Content Backup | Backs up the two most recent Bitdefender content versions on your endpoints. If the latest content update is corrupt, the engine automatically reverts to the previous backup. |
Content Exclusion List | Specifies a list of content versions to be excluded from updates and backups. |
Find the version numbers in the Hosts fields in the Forensics workspace or the Product Properties on the ePO server.