Dr.Web Katana icon

Dr.Web Katana 2.0.0 Build 5291

Behavior monitoring and application access controls for Windows

Download for Windows 32-bit and 64-bit 2.0.0 Build 5291 · 61.9 MB
Updated July 2, 2025
Free · Shareware
61.9 MB
4.0

Use the arrow keys to choose a rating, then press Enter or Space to submit it.

Very good 1 user ratings
Listed in our directory since 2026
Developer: Doctor Web
Page updated October 4, 2026

Overview

Dr.Web Katana is a preventive security application for Windows that monitors running programs for malicious actions. It uses behavior analysis, local protection rules and cloud reputation to block activity such as code injection and unauthorized system changes. Katana can operate alongside a third-party antivirus.

Katana is paid software with an all-feature trial. Its preventive technologies are also included in Dr.Web Security Space, so users of that product already have this part of its protection.

Process monitoring and application access

Katana examines what processes do while they run, including attempts to inject code into another application, alter user files or modify critical Windows settings. It also blocks connections between spyware components and their control servers.

Local rules let protection continue without an internet connection. When connected, Katana also uses cloud reputation about malicious routines, known-clean files and compromised software signatures. There is no signature database to refresh, although program updates change protection algorithms and correct errors.

Protection levels

Behavior Analysis controls application access to protected system objects. Its targets include the HOSTS file, drivers, low-level disk writing and registry settings used for program startup, system services and safe mode. Protected objects remain readable; the rules govern attempts to change them.

The available levels apply different access restrictions:

  • Optimal: blocks clearly malicious system-object changes by untrusted applications, including harmful HOSTS changes and low-level disk access.
  • Medium: restricts access to additional critical objects that malicious programs could use. Legitimate applications that need those objects may also encounter restrictions.
  • Paranoid: adds interactive control over driver loading and automatic program startup.
  • User-defined: saves custom protection settings for individual objects.

Application rules

Dr.Web Katana can apply separate rules to a particular application instead of giving every process the same access. Applications can be selected by executable path, name or name mask. Each rule can allow access, block it or ask the user when a protected object is involved.

This lets a program retain the access it needs while other applications stay subject to the general protection level. Changes to these settings require administrator mode within Katana.

Ransomware and exploit prevention

File encryption attempts

Ransomware Protection watches for processes attempting to encrypt user files. The default Block reaction prevents detected encryption activity. Allow permits it, while Ask presents a notification in which the user decides how Katana should respond.

In Ask mode, choosing Fix blocks the process and moves the application to quarantine. Closing the notification leaves the application unneutralized. An application restored after this action cannot launch until the computer restarts.

Separate application rules let the user choose a different reaction for a specific executable. This accommodates applications that legitimately encrypt files without changing the general response for every program.

Exploit attempts

Exploit Prevention targets malicious code that uses vulnerabilities in applications, including browsers and their plugins. Its reaction can block unauthorized code automatically, request an interactive decision or allow execution.

When Katana neutralizes an exploit through another application, it ends the attacked process. It leaves that application's files unchanged and does not move them to quarantine. A notification and event-log entry record the interrupted attack.

Protected local folders

Data Loss Prevention restricts changes to folders selected by the user. Applications outside the allowed rules cannot modify or remove their contents. The user can enable trusted-application access and add individual applications that receive full access to a particular folder.

Reading, copying and creating new items remain possible. A process that creates a new item can continue changing that item until the process ends. Katana displays a notification when it blocks an application's access.

Folder protection applies to files physically stored on the device within the Windows installation where it is configured. Network folders cannot be protected. System folders must be left outside the selected set. A computer with separate operating systems needs protection configured within each one.

The Saved copies tab appears only when copies from earlier Katana installations already exist. Those copies can be restored to a chosen folder or removed. Katana cannot create new copies through this function.

Quarantine and remote management

Isolated files

Quarantine Manager lists isolated objects with their threat classification and original path. The user can inspect details, restore selected objects to a chosen folder or delete them. Administrator privileges expose objects that the current account cannot otherwise view.

Network computers

Anti-Virus Network provides access to compatible Dr.Web Katana, Security Space or Server Security Suite installations on other computers. Their product versions must match, and the remote installation must permit connections. Computers can be selected from the network list or added by IPv4 or IPv6 address.

After connecting with the remote installation's access code, the user can view statistics, switch components on or off and change their settings. Only one remote connection can be active at a time. Remote access excludes Quarantine, Data Loss Prevention and Anti-Virus Network itself.

Key Features

  • Non-signature process-behavior monitoring
  • Cloud reputation information
  • Unauthorized file-change and code-injection controls
  • Protection for boot and selected registry areas
  • Exploit response through process interruption
  • Blocked-action notifications and event log

Similar Apps