> Source: [sk129892](https://support.checkpoint.com/results/sk/sk129892)

# sk129892 - SandBlast Agent Behavioral Guard Basic Configuration

| Property | Value |
|----------|-------|
| Solution ID | sk129892 |
| Date Created | 2018-06-24 |
| Last Modified | 2024-01-10 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X, R82.20, R82.10, R82, R81.20 |

## Solution

SandBlast Agent Behavioral Guard is a behavioral detection engine that detects and remediates all forms of malicious behavior. When the Behavioral Guard detects malicious behavior, a forensics report is generated of the entire attack. The attack can be automatically or manually remediated based on the forensics report.

This article covers basic configuration of the Behavioral Guard, which includes enabling/disabling the product and creating exclusions.

Enabling aggressive behavioral rules or switching from **detect** to **prevent** requires advanced configuration knowledge. For more on this, see [sk130012: SandBlast Agent Behavioral Guard Advanced Configuration](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk130012).

Configuring Behavioral Guard
----------------------------

Starting with E80.85, Behavioral Guard is turned on by default.

It is recommended that users upgrade to the latest SmartConsole version.

Click on the "*Policies* " section of the SmartEndpoint and then scroll down to the "*SandBlast Agent Anti-Ransomware, Behavioral Guard and Forensics* " section. If you are not using the latest SmartConsole version, you will need to scroll down to the "*SandBlast Agent Anti-Ransomware, Forensics and Remediation*" section.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk129892/Policy_Name_Shrunk1806241224.png)

Then open the following: "*Anti-Ransomware and Behavioral Guard Settings* ". If you are not using the latest version of the SmartConsole, you will need to open "*Anti-Ransomware Backup Settings* "*.*

### Enabling/Disabling Behavioral Guard

Anti-Ransomware and Behavioral Agent are configured using the same check box. This means that you can enable both or disable both. If you want the granularity to disable one and enable the other, refer to [sk130012: SandBlast Agent Behavioral Guard Advanced Configuration](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk130012).

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk129892/ARandBG1806241229.png)

**Note: If you are not using the latest version of SmartConsole, the check box will say "Enable Anti-Ransomware" only. However, turning it on or off will affect the behavior of Behavioral Guard, as well.**

### Exclusions for Behavioral Guard

Like Anti-Ransomware, Behavioral Guard allows for exclusions by Certificate, Process and Folder. In addition, Behavioral Guard allows for exclusion by Behavioral Rule Name.

There is no Behavioral Rule Name choice in the UI, but you can do the following **workaround** . Under *Exclusion Setting* , click on "*Add location...* ". This will bring up the window shown below. Select *Certificate* and click OK.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk129892/Add_Location1806241231.png)

Then add the following text: rulename:: \<signature\>. For example: rulename::Gen.Win.hashcpy. This will prevent the rule from being enforced.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk129892/Rule_Name_Exclusion1806241234.png)

**Note: The exclusions applied here apply to both Anti-Ransomware and Behavioral Guard. However, the Behavioral Rule Name exclusions described above currently DO NOT apply to Anti-Ransomware.**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
