The EDR solution provides a Boot Scan capability to detect and remove malware that may be difficult to identify while the operating system is fully loaded. The scan is performed during the system boot process, before normal Windows operations begin, allowing the EDR engine to inspect critical system areas and detect threats that may attempt to hide or protect themselves during normal operation.
Key Features
- Pre-Boot Threat Detection: Performs malware scanning during the system boot process before the operating system is fully operational.
- Enhanced Malware Detection: Helps detect threats such as rootkits, boot-level malware, persistent malware, and other threats that may evade conventional real-time scanning.
- Automated Scan Execution: The Boot Scan can be configured to execute automatically according to the security policy defined by the administrator.
- Password-Protected Skip Option: If a user attempts to skip or cancel the Boot Scan, the solution prompts for an authorized password.
- Unauthorized Bypass Prevention: Users cannot bypass the mandatory Boot Scan without providing the configured password, ensuring that security controls cannot be easily circumvented.
- Administrator-Controlled Access: Only authorized personnel with the appropriate password can skip the scan when required.
- Security Event Logging: Attempts to skip or bypass the Boot Scan can be recorded for auditing and security monitoring purposes.
Password-Protected Boot Scan
When the Boot Scan is initiated, the endpoint performs the configured security scan before allowing normal system operation to continue. If a user selects the Skip/Cancel Boot Scan option, the EDR solution displays a password authentication prompt.
The Boot Scan will be skipped only after successful authentication with the authorized password. If an incorrect password is entered, the scan continues and the user is not permitted to bypass the security check.
This mechanism ensures that users cannot independently disable or circumvent the organization’s Boot Scan security policy.
Security Benefit
Password protection for the Boot Scan provides an additional layer of endpoint protection by ensuring that mandatory security scans cannot be bypassed by unauthorized users. This helps maintain consistent security enforcement across protected endpoints and reduces the risk of boot-level or persistent malware remaining undetected.