1. ProtectKit's core principle
ProtectKit is designed to help you distinguish between what was observed and what that observation may mean. Those are not always the same thing.
Legitimate software can sometimes look unusual, and malicious software can sometimes appear normal. ProtectKit aims to show useful context so you can make a better decision.
Whenever possible, consider multiple pieces of evidence rather than relying on a single name, score, connection, reputation result, or unusual behavior.
2. Common ProtectKit finding statuses
Protecting / Protected
The relevant protection or security control appears to be active based on the information ProtectKit was able to verify.
This does not guarantee that the computer is free from threats. It means the particular protection being checked appears to be in the expected state.
Trusted
Available evidence provides reasons to regard the item as relatively trustworthy. Examples can include expected location, known publisher information, valid signing information, normal behavior, or other supporting evidence.
Trust is not an absolute guarantee that software is safe.
Needs Attention / Warning
ProtectKit identified a condition that deserves review. This may be a disabled protection, unusual configuration, incomplete security setting, or another condition that could reduce protection or require a decision.
Read the explanation before changing anything.
Suspicious
ProtectKit found one or more characteristics that justify closer investigation. Suspicious does not mean ProtectKit has proven the item is malicious.
Unknown
ProtectKit does not have enough reliable evidence to classify the item confidently. Unknown should normally lead to investigation, not automatic removal.
Critical
A critical result indicates a high-priority condition based on the feature's available evidence or security logic. Review the details promptly, but still verify what ProtectKit found before taking an irreversible action.
Inconclusive
ProtectKit could not reach a reliable conclusion from the information available. Permissions, unavailable data, external-service failures, unusual configurations, or conflicting evidence can contribute to an inconclusive result.
Admin Required
Windows requires elevated administrator permission for ProtectKit to complete the requested check or action. This is a permissions state, not a malware classification.
3. What counts as useful evidence?
The evidence available depends on the ProtectKit feature and the item being investigated. Useful evidence may include:
Identity
File name, executable path, service name, process name, startup location, or other identifying information.
Publisher
Publisher information and whether the software appears to come from an expected organization.
Digital signature
Whether an executable is digitally signed and what ProtectKit can determine about that signature.
File hash
A cryptographic identifier can help distinguish one exact file from another and can be useful for reputation research.
Network behavior
Remote addresses, ports, protocols, connection state, and the process associated with network activity.
System behavior
How an item starts, what it changes, where it runs from, and other behavior relevant to the feature being analyzed.
4. Confidence matters
Security analysis is rarely perfect. A strong conclusion should normally be supported by stronger or multiple pieces of evidence. Weak, incomplete, or conflicting evidence should produce a more cautious interpretation.
ProtectKit's goal is to communicate uncertainty rather than hide it. If evidence is insufficient, an Unknown or Inconclusive result can be more responsible than pretending certainty exists.
5. What should I do with a Suspicious finding?
Do not panic and do not immediately delete the item. Start by examining the details ProtectKit provides.
- Check the file or executable path.
- Check the publisher and digital signature.
- Determine whether you recognize the software.
- Review associated startup or service behavior.
- Review network activity when relevant.
- Use available investigation and reputation tools for additional context.
- Consider whether several independent signals point toward the same conclusion.
A program connecting to the internet is normal for many applications. The same connection may deserve more attention if the executable is unsigned, runs from an unusual location, appeared unexpectedly, and communicates with an unexplained destination.
6. What does Unknown mean?
Unknown means ProtectKit lacks enough reliable evidence to make a stronger classification. It does not mean safe and it does not mean malicious.
New software, uncommon applications, custom utilities, unsigned programs, and files with limited reputation information can all be difficult to classify automatically.
If the item matters, investigate it using the available evidence rather than treating the word Unknown as a verdict.
7. What does Critical mean?
Critical is intended to draw attention to a high-priority condition. The exact meaning depends on the ProtectKit feature producing the result.
A critical security configuration problem is different from a suspicious executable, for example. Read the explanation and supporting evidence so you understand what ProtectKit is actually reporting.
If a critical result involves a potentially destructive response, preserve relevant evidence and understand the recommended action before proceeding.
8. Admin Required is not a threat result
Windows restricts access to many security-sensitive settings and operations. ProtectKit may need administrator permission to inspect or change those areas.
If ProtectKit displays Admin Required, it means the operation could not be completed with the current permission level. It does not mean administrator access itself is unsafe, nor does it mean ProtectKit detected an infection.
9. Why would a result be Inconclusive?
An inconclusive result can occur when ProtectKit cannot obtain enough dependable information. Possible reasons include insufficient Windows permissions, missing information, conflicting evidence, a temporary Windows problem, a network failure, or an unavailable external service.
Try the appropriate check again when conditions change. If the result remains inconclusive and the item is important, investigate it manually or contact ProtectKit Support.
10. Before blocking, disabling, or removing something
Some security actions can interrupt legitimate applications or Windows functionality. Before taking an irreversible action:
- Understand exactly what ProtectKit found.
- Confirm which file, process, service, rule, setting, or connection is involved.
- Review more than one piece of evidence whenever possible.
- Consider whether the item belongs to software you intentionally installed.
- Preserve logs, screenshots, hashes, paths, or other evidence if the activity may require further investigation.
- Prefer reversible actions when appropriate.
- Maintain appropriate Windows recovery and backup options before significant system changes.
11. False positives and incorrect findings
A false positive occurs when legitimate activity is incorrectly treated as suspicious or threatening. No security analysis system can guarantee that false positives will never occur.
If you believe ProtectKit is repeatedly reporting a legitimate item incorrectly, send a false-positive report. Include the exact finding, the feature involved, file or process information, publisher or signature details when available, and why you believe the item is legitimate.
ProtectKit is designed to help you see the evidence, understand why it matters, and choose the next step. It should not pressure you into treating every unfamiliar item as a threat.