顯示具有 Symantec EndPoint Protection 標籤的文章。 顯示所有文章
顯示具有 Symantec EndPoint Protection 標籤的文章。 顯示所有文章

2026年8月26日 星期三

[研究]SEP, SEP+EDR, DSA, DS+EDR 比較 EDR 能力

[研究]SEP, SEP+EDR, DSA, DS+EDR 比較 EDR 能力

2026-08-26

SEP = Symantec Endpoint Protection、DSA = Trend Micro Deep Security Agent

ChatGPT

能力 SEP 本身 SEP + Symantec EDR DSA 本身 DSA + Trend Vision One EDR/XDR
Anti-Malware 🟢 🟢 🟢 🟢
即時防護 🟢 🟢 🟢 🟢
Behavior Monitoring 🟢 🟢 🟢 🟢
Exploit 防護 🟢 🟢 🟢 🟢
Process 偵測 🟢 🟢 🟢 🟢
可疑行為偵測 🟢 🟢 🟢 🟢
Endpoint Telemetry 端點遙測 🟡 🟢 🟡 🟢
Threat Hunting 威脅狩獵 ❌/🟡 🟢 ❌/🟡 🟢
事件關聯分析 ❌/🟡 🟢 🟡 🟢
攻擊事件 Investigation 調查 🟡 🟢 🟡 🟢
IOC 搜尋 (Indicator of Compromise(入侵指標)搜尋) ❌/🟡 🟢 🟡 🟢
Incident Response 🟡 🟢 🟡 🟢
EDR Console 🟢 🟢
完整 EDR 🟢 ❌/🟡 🟢
FIM / Integrity Monitoring 🟡 🟡 🟢 🟢
指定目錄監控 🟡 🟡 🟢 🟢
檔案新增偵測 🟡 🟡 🟢 🟢
檔案修改偵測 🟡 🟡 🟢 🟢
檔案刪除偵測 🟡 🟡 🟢 🟢
Registry 監控 🟢 🟢 🟢 🟢
Server 防護 🟢 🟢 🟢 🟢
IPS 🟢 🟢 🟢 🟢
Virtual Patching 🟢 強項 🟢 強項

(完)

[研究]SEP (Symantec Endpoint Protection) 和 DSA (Deep Security Agent) 比較目錄監控能力

[研究]SEP (賽門鐵克 Symantec Endpoint Protection) 和 DSA (趨勢科技 Trend Micro Deep Security Agent) 比較目錄監控能力

2026-08-26

表格比較 SEP 和 DSA 對目錄監控能力 ? (自行開發Code 於正式機更版;目錄內檔案是否被駭客新增、修改、寫入檔案 、、、等)

注意,AI不一定正確

能力 SEP Trend Micro DSA 說明
即時掃描檔案 SEP Auto-Protect 可在檔案存取、複製、儲存、移動、開啟等操作時掃描。
偵測惡意檔案 兩者主要都是防惡意程式/病毒的能力
偵測「有人新增檔案」 ⚠️ 不是主要用途 適合 DSA Integrity Monitoring 可監控檔案/目錄的完整性
偵測「既有檔案被修改」 ⚠️ 可因惡意程式而偵測 專門能力 DSA 以 baseline 比對變更
偵測「Web Code 被偷偷改掉」 ⚠️ 不適合當主要機制 非常適合 這正是 Integrity Monitoring 的用途
偵測「駭客新增 .aspx/.config/.dll/.exe」 ⚠️ 不保證單純新增就告警 可以 DSA 可設定 FileSet / DirectorySet
偵測檔案內容 Hash 改變 ⚠️ 非主要功能 可以 DSA FileSet 可監控 Contents / hash 等屬性。(Trend Micro Documentation)
偵測檔案大小改變 ⚠️ 非主要功能 可以 FileSet 可監控 Size
偵測檔案時間改變 ⚠️ 非主要功能 可以 Created / LastModified 可監控
偵測檔案權限改變 ⚠️ 有限 可以 DSA 可監控 Permissions、Owner 等
偵測目錄本身被修改 ⚠️ 非主要用途 可以 DSA 有 DirectorySet
監控整個 Web 目錄 ⚠️ 可用 ADC 做存取控制 適合 DSA 可指定 Base Directory + 子目錄
即時 Integrity Monitoring ⚠️ 非 SEP 核心功能 可以 DSA 可啟用 Real-time Integrity Monitoring。(瑞世安全幫助中心)
Baseline / 正式版基準 ❌ 非主要功能 核心能力 DSA 建立 baseline 後比對後續變更
告警「正式版 Code 被修改」 ⚠️ 不適合 適合 DSA 會產生 Integrity Monitoring Event
告警「正式版 Code 被新增」 ⚠️ 不適合 適合 FileSet/DirectorySet 可涵蓋新增檔案
找出修改者 User ⚠️ 非主要用途 較適合 新版 Windows DSA 即時監控可提供修改檔案的 user/process 資訊。(瑞世安全幫助中心)
找出哪個 Process 修改 ⚠️ 非主要用途 較適合 DSA Integrity Monitoring event 可記錄 Process/User。(TrendAI 商業成功入口網站)
阻止未授權程式執行 Application Control 兩者都有不同形式的 Application Control
阻止程式寫入特定目錄 可以做 ⚠️ 可透過 Application Control 等功能達成 SEP ADC 可以控制 files/folders 的存取
只「記錄」而不阻擋 SEP ADC 有 Test/Log 模式;DSA IM 主要是偵測/告警
發現後自動還原原始檔 ❌ 一般不是這個用途 ❌ Integrity Monitoring 本身不負責還原 DSA 官方明確說 IM detects,但不 prevent/undo。(瑞世安全幫助中心)
SIEM 整合 可將事件送集中管理/SIEM
適合「Web Code 完整性監控」 ⭐⭐ ⭐⭐⭐⭐⭐ DSA 明顯較適合

DSA 會比 SEP 好。

(完)

[研究]SEP (Symantec Endpoint Protection) 和 DSA (Deep Security Agent) 能否共存?

[研究]SEP (賽門鐵克 Symantec Endpoint Protection) 和 DSA (趨勢科技 Trend Micro Deep Security Agent) 能否共存?

2026-08-26

強烈建議不要兩套包含防毒(防惡意程式)的軟體共同安裝於同一台電腦,可能非常危險,後果難料。

如果是虛擬機(VM),建議先做快照;實體機,資料備份好,要有 format 重新安裝的考量。

*****

能共存範例





測試過2台 Windows Server 2019 + SEP + DSA 正常,測試過另2台 Windows Server 2022 + SEP + DSA 正常。

*****

能共存範例


有人按下「確定」按鈕後,畫面全黑。

有人電腦上所有可執行程式 (例如 .exe) 全部無法執行,administrator 無法操作。

*****

(完)

2026年2月2日 星期一

[研究]Windows 執行「工作管理員」出現「檔案系統錯誤(-1073740791)」

[研究]Windows 執行「工作管理員」出現「檔案系統錯誤(-1073740791)」

2026-02-02

Windows Server 2022 執行 工作管理員,出現

C:\Windows\system32\taskmgr.exe 

檔案系統錯誤(-1073740791)

以前是正常的,加裝 Symantec Endpoint Protection 後異常;

但Windows Server 2019 上正常,兩台都安裝相同版的 Trend Micro Deep Security Agent (DSA),和相同版本 Symantec Endpoint Protection (SEP)

********************************************************************************

檔案系統錯誤(-1073740791)

  • 這個數字轉成十六進制是:0xC0000409
  • 意義:STATUS_STACK_BUFFER_OVERRUN
  • Windows 偵測到程式有潛在緩衝區溢位風險,系統主動終止程式 (self-protect)。
  • 也就是說 taskmgr.exe 被系統認定可能被篡改或危險,直接中止。

可能原因

  • Symantec Endpoint Protection 的 Tamper Protection / SONAR / 自我保護功能
    • SEP 可能攔截或掃描 system32 裡的 taskmgr.exe,誤判為風險。
    • Windows Server 2022 對 核心安全和完整性防護 比 2019 更嚴格,導致相同軟體在不同版本上行為不同。
  • 與 Trend Micro Deep Security 的互相衝突
    • 雖然兩台都裝了 Deep Security,但 2022 的 Kernel 模式或防護策略可能讓 SEP 和 Deep Security 發生競爭鎖定。
  • taskmgr.exe 被即時掃描或駐留防護鎖住
    • SEP 的即時保護或安全策略可能阻止 taskmgr.exe 啟動。

(完) 

2025年12月8日 星期一

[研究]Symantec EndPoint Protection 14.3 RU9 (SEP)安裝記

[研究]Symantec EndPoint Protection 14.3 RU9 (SEP)安裝記

2025-12-08

下圖,安裝後,不會提示要 Windows Reboot,但是點右下角 SEP 圖示,會告訴你需要重新啟動。









(完)