People relies in Matryoshka dolls as tooling, I also do til some degree, but what happens latter when the trojan scapes the Matryoshka ? nobody land, time endless. I use HISP in manual mode because I want to detect signs, and also because I want to limit and to know what benign programs want to access. And I'm talking about this even for simple domestic computers at home!
Needed to say in case a manager who has never used Windows read that:
For to use HISP in manual mode the user really have to want to do it above everything else, literally it is painful and very time-consuming. I've been doing it for more than ten years and even now requires to keep to want it. It is like the difference between walking on sand dunes and walking on pavement when I use other people's computers, so the moment you have no desire for it, the technique is more dangerous than automated mode by far. I mean, in Windows most of the people use it in automated mode (no pop-up), the default mode in antivirus.
My last words, mostly to the rest of the community,
The matter is, the Windows Kernel provides this option of security matters to everyone, and due this the tooling around it, is I guess.
(Although certainly it is mostly through commercial products developed by dedicated teams. And so on.)