What are the key advantages of ESET LiveGuard Advanced?
Central management – Managed from the ESET PROTECT console only.
Cloud sandbox – Unknown files are executed and analysed remotely.
Fast verdicts – Most new samples are analysed within five minutes.
Broad coverage – Windows, macOS, Linux, Exchange and Microsoft 365.
Privacy controls – Set retention, exclusions and deletion after analysis.
Important note – Add-on only, no endpoint protection included.
Cloud sandbox analysis – Suspicious files are executed and observed in ESET's cloud.
Four detection layers – Unpacking, machine learning, sandbox execution and behavioural analysis.
Proactive file blocking – Unknown files stay blocked until the verdict arrives.
Console reporting – Behavioural reports and dashboards inside the ESET PROTECT console.
Policy control – Per device or group: submission scope, retention, exclusions.
Important – No console, no endpoint protection and no EDR included.
ESET LiveGuard Advanced, previously sold as ESET Dynamic Threat Defense, is an add-on module that sends unknown files from ESET endpoint, server and mail applications to an ESET cloud sandbox for execution and analysis. It has no interface of its own: activation, policies and results all sit in the ESET PROTECT or ESET PROTECT On-Prem console.
Verdict in minutes – ESET analyses most new samples in under five minutes.
Company-wide result – One verdict then protects every machine in the company.
Mail attachment scanning – External Exchange attachments are checked before delivery.
Roaming device support – Laptops off the network still receive sandbox verdicts.
Four graded verdicts – Clean, suspicious, highly suspicious or malicious per file.
Privacy controls – Retention, exclusions and immediate deletion after analysis.
The decisive factor is not headcount but whether ESET business products are already in use, because this module cannot be deployed on its own. Companies that already run ESET endpoint or mail protection can add it without changing their agents or their console.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Existing ESET application required | ✓ | ✓ | ✓ |
| This product fits | If ESET used | ✓ | ✓ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, so most SMEs are affected only indirectly through their customers. Operators who are in scope must submit an initial report of a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. ESET LiveGuard Advanced supports the detection side of that duty: it holds an unknown file until the verdict returns and stores a behavioural report per sample in the ESET PROTECT console, which gives you a dated technical description of what the file attempted to do. What it does not do is recognise an incident across several systems, reconstruct an attack chain, or write the report for you; that needs a detection and response component such as ESET Inspect plus an internal process with named responsibilities. It also keeps no log archive of its own, because retention and export are functions of the management console rather than of this module. This text is general orientation and does not replace legal advice.
No software product makes a company NIS 2 compliant, because the directive addresses organisational risk management rather than the purchase of tools. NIS 2 requires entities in scope to take measures across defined categories, among them risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, cryptography, access control and staff awareness. ESET LiveGuard Advanced contributes to two of these categories: incident handling, by stopping unknown malware before it executes, and basic protective hygiene, by adding sandbox analysis to email attachments and downloaded files. It contributes nothing to business continuity and backup, vulnerability handling and patching, cryptography, access control, multi-factor authentication or staff awareness, and each of those gaps needs a separate module or a separate product. Because scope and reporting rules are set nationally when the directive is transposed, confirm the rules for the country in which your entity is established.
Partly, and it is worth knowing which lines it fills in. It answers questions about protection against unknown and zero-day malware, about automated analysis of email attachments from outside the organisation, and about whether malicious files are blocked before execution rather than cleaned afterwards; the per-sample behavioural report and the console reports serve as the evidence for those answers. It does not answer questions about endpoint detection and response, attack chain reconstruction, patch and vulnerability status, disk encryption, multi-factor authentication, backup and restore capability, log retention periods, or SIEM export, because none of those are functions of this module. If several of those lines are blank, the cheaper route is normally to move up within the ESET PROTECT tiers rather than to mix vendors, since the higher tiers add encryption, vulnerability and patch management, mail server security and detection and response under the same console and the same agent.
The decisive difference is that ESET LiveGuard Advanced is only the cloud sandbox layer, while ESET PROTECT Advanced is a full protection tier that already contains that same layer. Buying the module separately makes sense when endpoint and server protection are already licensed and only the sandbox is missing. If endpoints still need protecting as well, the tier is the more sensible starting point, because it also brings mobile coverage and full disk encryption. Mail server security and cloud application protection begin at ESET PROTECT Complete, and detection and response begins at ESET PROTECT Elite, so neither column below covers those.
| Module | ESET LiveGuard Advanced | ESET PROTECT Advanced |
|---|---|---|
| Cloud sandbox analysis | ✓ | ✓ |
| Endpoint protection | ✕ | ✓ |
| Server security | ✕ | ✓ |
| Mobile threat defense | ✕ | ✓ |
| Full disk encryption | ✕ | ✓ |
| Management console | Required separately | ✓ |
| Mail server security | ✕ | ✕ |
| Detection and response | ✕ | ✕ |
Samples do not stay in the country: files are uploaded to ESET and analysed at ESET headquarters in Slovakia, while the hash and result databases run in Azure data centres in the United States and Europe. Administrators can limit this through folder and process exclusions, a shortened retention period, or a policy that requires deletion immediately after analysis, but organisations with strict data residency rules should clarify this before rollout. A second point that surprises many administrators is that documents and PDF files with active content such as macros or JavaScript are not submitted by default and must be enabled in the policy. Mobile devices are outside the scope entirely, since Android and iOS applications are not on the list of applications that can submit samples. The follow-up purchases that most often result are a detection and response component for attack chain analysis and, where mailboxes need covering, ESET Mail Security or ESET Cloud Office Security.
ESET LiveGrid is a reputation system that returns no visible result to the administrator and handles samples at low priority. ESET LiveGuard Advanced analyses samples at high priority and returns one of four verdicts, clean, suspicious, highly suspicious or malicious, together with a behavioural report in the console.
The ESET application can hold the file and prevent it from running until the verdict arrives, and the waiting period is set in the policy. In ESET Cloud Office Security the default wait for an email is five minutes, after which the message is released if no result has come back.
Yes. A roaming device with no connection to an on-premises server still submits samples directly to the ESET cloud and acts on the result. The metadata for those submissions appears in ESET PROTECT On-Prem only once the device reconnects to the network.
Only in combination with ESET Cloud Office Security, which submits attachments and files from Exchange Online, OneDrive, Teams groups and SharePoint sites. That path does not use an ESET management console, so the submissions and results are shown inside ESET Cloud Office Security instead.
ESET LiveGuard Advanced runs suspicious files in an ESET cloud sandbox with four detection layers. Add-on to existing ESET business products.
ESET LiveGuard Advanced, ESET, ESET PROTECT, ESET Dynamic Threat Defense, cloud sandbox, advanced threat defense, zero-day protection, ransomware protection, behavioural analysis
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies