Trend Micro suggests enabling the appropriate settings to have best protection from ransomware.
- Log on to the Apex One management web console.
- Go to Agents > Agent Management.
- Click Apex One domain from Apex One server lists.
- Click Settings and select Predictive Machine Learning Settings.
- Tick to Enable Predictive Machine Learning.
-
Under Detection Settings, enable the following:
- Click Save to deploy changes.
- Log on to the Apex One management web console.
- Go to Agents > Agent Management.
- Click Settings and go Web Reputation Settings.
-
On the Internal Agents tab, tick the checkbox for Enable Web Reputation on the following operating systems. Select the following;
- Click Apply to All Agents to deploy changes
- Log on to the Apex One management web console.
- Go to Agents > Agent Management.
- Click Settings and go Behavior Monitoring Settings.
-
Tick the checkbox for Enable Malware Behavior Blocking and select Known and potential threats from the dropdown next to Threats to block.
- Protect documents against unauthorized encryption or modification & automatically back up files changed by suspicious programs
- Block processes commonly associated with ransomware
- Enable program inspection to detect and block compromised executable files
- Terminate programs that exhibit abnormal behavior associated with exploit attacks.
-
Under Newly Encountered Programs:
This notification requires that administrators enable Real-time Scan and Web Reputation. -
To enable Unauthorized Change Prevention Service on desktop and server platforms:
- Select the Apex One domain
- Click Settings and go to Additional Service Settings.
- Under Unauthorized Change Prevention service, tick to enable both Windows desktops and Windows Server platforms.
- Click Save to deploy changes.
- Log on to the Apex One management web console.
- Go to Agents > Agent Management.
- Click Apex one domain from Apex One server lists.
- Click Settings and go to Additional Service Settings > Advance Protection Services.
-
Tick to enable Windows desktop and Windows Server platforms.
- Click Save to deploy changes.
- Log on to the Apex One management web console.
- Go to Agents > Agent Management.
- Click Apex one domain from Apex One server lists.
- Click Settings and go to Additional Service Settings > Suspicious Connection Service.
-
Tick to enable Windows desktop and Windows Server platforms.
- Click Save to deploy changes.
- To go to Suspicious Connection Settings.
- Click Apex one domain from Apex One server lists.
- Click Settings and select Suspicious Connection Settings.
-
Tick the checkboxes for the following:
- Detect network connections made to address in the Global C&C List. Select "block" from the dropdown and Log and allow access to User-defined Blocked IP list addresses.
- Detect connections using malware network fingerprinting. Select block from the dropdown and Clean suspicious connections when C&C callback is detected.
Image