Views:

Predictive Machine Learning requires enabling the following:

  • Advance Protection Service
  • Unauthorized Change Prevention Service
  • Real-Time Scan (For file detections)

Ensure to enable the required service for appropriate Windows platforms in Additional Service Settings.

Below are the recommended settings to enhance process detection:

  • Enable Web Reputation.
  • Enable Malware Behavior Blocking and Enable program inspection to detect and block compromised executable samples in Behavior Monitoring Settings.

To enable Predictive Machine Learning:

  1. Log on to the Apex One web console.
  2. Go to Agents > Agent Management.
  3. In the Agent Tree, select the Apex One Server/Domain/Computer.
  4. Go to Settings > Predictive Machine Learning Settings.
  5. Tick Enable Predictive Machine Learning.
  6. Under Detection Settings, select the type of detections and related action that Predictive Machine Learning takes

    Detection TypeActions
    File
    • Quarantine: Select to automatically quarantine files that exhibit malware-related features based on the Predictive Machine Learning analysis
    • Log only: Select to scan unknown files and log the Predictive Machine Learning analysis for further in-house investigation of the threat
    Process
    • Terminate: Select to automatically terminate processes or scripts that exhibit malware-related behaviors based on the Predictive Machine Learning analysis

       
      Predictive Machine Learning attempts to clean the files that executed the malicious processes or scripts. If the clean action is unsuccessful, Predictive Machine Learning quarantines the affected files.
       
    • Log only: Select to scan unknown processes or scripts and log the Predictive Machine Learning analysis for further in-house investigation of the threat
  7. Under Exceptions, configure the global Predictive Machine Learning file exceptions to prevent all agents from detecting a file as malicious.
    1. Click Add File Hash.
    2. Specify the file SHA-1 hash value to exclude from scanning.
    3. Optionally provide a note regarding the reason for the exception or to describe the file name(s) associated with the hash value.
    4. Click Add.
  8. Click Save/Apply to All Agents/Apply to Future Domains Only.

To enable Predictive Machine Learning:

  1. Log on to the Apex Central web console.
  2. Go to Policies > Policy Management.
  3. Create a new or select an existing Policy Name.
  4. Under Advanced Threat Protection, select Predictive Machine Learning.
  5. Tick Enable Predictive Machine Learning.
  6. Under Detection Settings, select the type of detections and related action that Predictive Machine Learning takes
    Detection TypeActions

    File

    • Quarantine: Select to automatically quarantine files that exhibit malware-related features based on the Predictive Machine Learning analysis
    • Log only: Select to scan unknown files and log the Predictive Machine Learning analysis for further in-house investigation of the threat

    Process

    • Terminate: Select to automatically terminate processes or scripts that exhibit malware-related behaviors based on the Predictive Machine Learning analysis
       
      Predictive Machine Learning attempts to clean the files that executed the malicious processes or scripts. If the clean action is unsuccessful, Predictive Machine Learning quarantines the affected files.
       
    • Log only: Select to scan unknown processes or scripts and log the Predictive Machine Learning analysis for further in-house investigation of the threat
  7. Under Exceptions, configure the global Predictive Machine Learning file exceptions to prevent all agents from detecting a file as malicious.
    1. Click Add File Hash.
    2. Specify the file SHA-1 hash value to exclude from scanning.
    3. Optionally provide a note regarding the reason for the exception or to describe the file name(s) associated with the hash value.
    4. Click Add.
  8. Click Deploy.