顯示具有 Deep Security 標籤的文章。 顯示所有文章
顯示具有 Deep Security 標籤的文章。 顯示所有文章

2026年8月26日 星期三

[研究]SEP, SEP+EDR, DSA, DS+EDR 比較 EDR 能力

[研究]SEP, SEP+EDR, DSA, DS+EDR 比較 EDR 能力

2026-08-26

SEP = Symantec Endpoint Protection、DSA = Trend Micro Deep Security Agent

ChatGPT

能力 SEP 本身 SEP + Symantec EDR DSA 本身 DSA + Trend Vision One EDR/XDR
Anti-Malware 🟢 🟢 🟢 🟢
即時防護 🟢 🟢 🟢 🟢
Behavior Monitoring 🟢 🟢 🟢 🟢
Exploit 防護 🟢 🟢 🟢 🟢
Process 偵測 🟢 🟢 🟢 🟢
可疑行為偵測 🟢 🟢 🟢 🟢
Endpoint Telemetry 端點遙測 🟡 🟢 🟡 🟢
Threat Hunting 威脅狩獵 ❌/🟡 🟢 ❌/🟡 🟢
事件關聯分析 ❌/🟡 🟢 🟡 🟢
攻擊事件 Investigation 調查 🟡 🟢 🟡 🟢
IOC 搜尋 (Indicator of Compromise(入侵指標)搜尋) ❌/🟡 🟢 🟡 🟢
Incident Response 🟡 🟢 🟡 🟢
EDR Console 🟢 🟢
完整 EDR 🟢 ❌/🟡 🟢
FIM / Integrity Monitoring 🟡 🟡 🟢 🟢
指定目錄監控 🟡 🟡 🟢 🟢
檔案新增偵測 🟡 🟡 🟢 🟢
檔案修改偵測 🟡 🟡 🟢 🟢
檔案刪除偵測 🟡 🟡 🟢 🟢
Registry 監控 🟢 🟢 🟢 🟢
Server 防護 🟢 🟢 🟢 🟢
IPS 🟢 🟢 🟢 🟢
Virtual Patching 🟢 強項 🟢 強項

(完)

[研究]SEP (Symantec Endpoint Protection) 和 DSA (Deep Security Agent) 比較目錄監控能力

[研究]SEP (賽門鐵克 Symantec Endpoint Protection) 和 DSA (趨勢科技 Trend Micro Deep Security Agent) 比較目錄監控能力

2026-08-26

表格比較 SEP 和 DSA 對目錄監控能力 ? (自行開發Code 於正式機更版;目錄內檔案是否被駭客新增、修改、寫入檔案 、、、等)

注意,AI不一定正確

能力 SEP Trend Micro DSA 說明
即時掃描檔案 SEP Auto-Protect 可在檔案存取、複製、儲存、移動、開啟等操作時掃描。
偵測惡意檔案 兩者主要都是防惡意程式/病毒的能力
偵測「有人新增檔案」 ⚠️ 不是主要用途 適合 DSA Integrity Monitoring 可監控檔案/目錄的完整性
偵測「既有檔案被修改」 ⚠️ 可因惡意程式而偵測 專門能力 DSA 以 baseline 比對變更
偵測「Web Code 被偷偷改掉」 ⚠️ 不適合當主要機制 非常適合 這正是 Integrity Monitoring 的用途
偵測「駭客新增 .aspx/.config/.dll/.exe」 ⚠️ 不保證單純新增就告警 可以 DSA 可設定 FileSet / DirectorySet
偵測檔案內容 Hash 改變 ⚠️ 非主要功能 可以 DSA FileSet 可監控 Contents / hash 等屬性。(Trend Micro Documentation)
偵測檔案大小改變 ⚠️ 非主要功能 可以 FileSet 可監控 Size
偵測檔案時間改變 ⚠️ 非主要功能 可以 Created / LastModified 可監控
偵測檔案權限改變 ⚠️ 有限 可以 DSA 可監控 Permissions、Owner 等
偵測目錄本身被修改 ⚠️ 非主要用途 可以 DSA 有 DirectorySet
監控整個 Web 目錄 ⚠️ 可用 ADC 做存取控制 適合 DSA 可指定 Base Directory + 子目錄
即時 Integrity Monitoring ⚠️ 非 SEP 核心功能 可以 DSA 可啟用 Real-time Integrity Monitoring。(瑞世安全幫助中心)
Baseline / 正式版基準 ❌ 非主要功能 核心能力 DSA 建立 baseline 後比對後續變更
告警「正式版 Code 被修改」 ⚠️ 不適合 適合 DSA 會產生 Integrity Monitoring Event
告警「正式版 Code 被新增」 ⚠️ 不適合 適合 FileSet/DirectorySet 可涵蓋新增檔案
找出修改者 User ⚠️ 非主要用途 較適合 新版 Windows DSA 即時監控可提供修改檔案的 user/process 資訊。(瑞世安全幫助中心)
找出哪個 Process 修改 ⚠️ 非主要用途 較適合 DSA Integrity Monitoring event 可記錄 Process/User。(TrendAI 商業成功入口網站)
阻止未授權程式執行 Application Control 兩者都有不同形式的 Application Control
阻止程式寫入特定目錄 可以做 ⚠️ 可透過 Application Control 等功能達成 SEP ADC 可以控制 files/folders 的存取
只「記錄」而不阻擋 SEP ADC 有 Test/Log 模式;DSA IM 主要是偵測/告警
發現後自動還原原始檔 ❌ 一般不是這個用途 ❌ Integrity Monitoring 本身不負責還原 DSA 官方明確說 IM detects,但不 prevent/undo。(瑞世安全幫助中心)
SIEM 整合 可將事件送集中管理/SIEM
適合「Web Code 完整性監控」 ⭐⭐ ⭐⭐⭐⭐⭐ DSA 明顯較適合

DSA 會比 SEP 好。

(完)

[研究]SEP (Symantec Endpoint Protection) 和 DSA (Deep Security Agent) 能否共存?

[研究]SEP (賽門鐵克 Symantec Endpoint Protection) 和 DSA (趨勢科技 Trend Micro Deep Security Agent) 能否共存?

2026-08-26

強烈建議不要兩套包含防毒(防惡意程式)的軟體共同安裝於同一台電腦,可能非常危險,後果難料。

如果是虛擬機(VM),建議先做快照;實體機,資料備份好,要有 format 重新安裝的考量。

*****

能共存範例





測試過2台 Windows Server 2019 + SEP + DSA 正常,測試過另2台 Windows Server 2022 + SEP + DSA 正常。

*****

能共存範例


有人按下「確定」按鈕後,畫面全黑。

有人電腦上所有可執行程式 (例如 .exe) 全部無法執行,administrator 無法操作。

*****

(完)

2026年2月2日 星期一

[研究]Windows 執行「工作管理員」出現「檔案系統錯誤(-1073740791)」

[研究]Windows 執行「工作管理員」出現「檔案系統錯誤(-1073740791)」

2026-02-02

Windows Server 2022 執行 工作管理員,出現

C:\Windows\system32\taskmgr.exe 

檔案系統錯誤(-1073740791)

以前是正常的,加裝 Symantec Endpoint Protection 後異常;

但Windows Server 2019 上正常,兩台都安裝相同版的 Trend Micro Deep Security Agent (DSA),和相同版本 Symantec Endpoint Protection (SEP)

********************************************************************************

檔案系統錯誤(-1073740791)

  • 這個數字轉成十六進制是:0xC0000409
  • 意義:STATUS_STACK_BUFFER_OVERRUN
  • Windows 偵測到程式有潛在緩衝區溢位風險,系統主動終止程式 (self-protect)。
  • 也就是說 taskmgr.exe 被系統認定可能被篡改或危險,直接中止。

可能原因

  • Symantec Endpoint Protection 的 Tamper Protection / SONAR / 自我保護功能
    • SEP 可能攔截或掃描 system32 裡的 taskmgr.exe,誤判為風險。
    • Windows Server 2022 對 核心安全和完整性防護 比 2019 更嚴格,導致相同軟體在不同版本上行為不同。
  • 與 Trend Micro Deep Security 的互相衝突
    • 雖然兩台都裝了 Deep Security,但 2022 的 Kernel 模式或防護策略可能讓 SEP 和 Deep Security 發生競爭鎖定。
  • taskmgr.exe 被即時掃描或駐留防護鎖住
    • SEP 的即時保護或安全策略可能阻止 taskmgr.exe 啟動。

(完) 

2023年7月13日 星期四

[研究]Windows Defender Firewall 僅允許 Deep Security 連上本機某些 port ( Windows 2019)

[研究]Windows Defender Firewall 僅允許趨勢科技 Trend Micro Deep Security Server 連上本機 Deep Security Agent (DSA) 某些 port ( Windows Server 2019)

2023-07-13

相關軟體

Deep Security Agent (DSA) 、Deep Security (DS)

********************************************************************************

緣起

最近收到一份 Nessus 弱點掃描報告,其中2個弱點

弱點1



51192 - SSL Certificate Cannot Be Trusted
Synopsis
The SSL certificate for this service cannot be trusted.
Description
The server's X.509 certificate cannot be trusted. This situation can occur in three different ways, in which
the chain of trust can be broken, as stated below :
- First, the top of the certificate chain sent by the server might not be descended from a known public
certificate authority. This can occur either when the top of the chain is an unrecognized, self-signed
certificate, or when intermediate certificates are missing that would connect the top of the certificate chain
to a known public certificate authority.
- Second, the certificate chain may contain a certificate that is not valid at the time of the scan. This can
occur either when the scan occurs before one of the certificate's 'notBefore' dates, or after one of the
certificate's 'notAfter' dates.
- Third, the certificate chain may contain a signature that either didn't match the certificate's information
or could not be verified. Bad signatures can be fixed by getting the certificate with the bad signature to be
re-signed by its issuer. Signatures that could not be verified are the result of the certificate's issuer using a
signing algorithm that Nessus either does not support or does not recognize.
If the remote host is a public host in production, any break in the chain makes it more difficult for users
to verify the authenticity and identity of the web server. This could make it easier to carry out man-in-themiddle
attacks against the remote host.
See Also
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
172.16.3.71 8
Plugin Information
Published: 2010/12/15, Modified: 2020/04/27
Plugin Output
tcp/4118/unknown
The following certificate was at the top of the certificate
chain sent by the remote host, but it is signed by an unknown
certificate authority :
|-Subject : CN=Deep Security Manager/DC=172.16.(遮蔽)/2.5.4.5=1614323416856
|-Issuer : CN=Deep Security Manager/DC=172.16.(遮蔽)/2.5.4.5=1614323416856

【說明】

TCP/4118/unknow,憑證不可信,Deep Security Manager 是未知憑證發行者。

********************************************************************************

弱點2

57582 - SSL Self-Signed Certificate
Synopsis
The SSL certificate chain for this service ends in an unrecognized self-signed certificate.
Description
The X.509 certificate chain for this service is not signed by a recognized certificate authority. If the remote
host is a public host in production, this nullifies the use of SSL as anyone could establish a man-in-themiddle
attack against the remote host.
Note that this plugin does not check for certificate chains that end in a certificate that is not self-signed, but
is signed by an unrecognized certificate authority.
Solution
Purchase or generate a proper SSL certificate for this service.
Risk Factor
Medium
CVSS v3.0 Base Score
6.5 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
CVSS v2.0 Base Score
6.4 (CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
Plugin Information
Published: 2012/01/17, Modified: 2022/06/14
Plugin Output
tcp/4118/unknown
The following certificate was found at the top of the certificate
chain sent by the remote host, but is self-signed and was not
found in the list of known certificate authorities :
|-Subject : CN=Deep Security Manager/DC=172.16.(遮蔽)/2.5.4.5=1614323416856

【說明】

問題:TCP/4118/unknow,SSL自簽憑證,憑證發行者為Deep Security,非著名單位。

********************************************************************************

【評估】

憑證不可信、使用SSL自簽憑證、憑證發行者為Deep Security,非著名單位等問題,比較正規處理是讓憑證可信 (例如掃描工具是否可以設定信任某些根憑證),或改用商用、對外公開正式商用憑證。

但一般內部網段軟體Client 和 Server 端通訊,不會使用外部正式公開對外憑證;而且Deep Security是趨勢科技公司資安軟體,不是客戶可以隨便或輕易處理的,而且被要求處理的時間很短,簡單應急處理就是目前限制來源 IP 和目的 Port。

********************************************************************************

【處理】

因為對 Deep Security 並不熟,本篇不是唯一方法,也不保證100%正確。













********************************************************************************

2023-08-31

管 Deep Security Server 那邊反映 Deep Security Agent 軟體無法更新,做了些調整。




(完)

相關

Deep Security 連線使用的通訊埠
更新於: 21 Jun 2018
https://success.trendmicro.com/tw/solution/1060007