Best Antivirus/EDR vs Unknown Ransomware

preview_player
Показать описание

Рекомендации по теме
Комментарии
Автор

FAQ:
What about Kaspersky & other products? There are only so many products I can fit into one video, so tried to get the most popular ones, I'll try to do a part 2 with Kaspersky, ESET and others.
Why is the file encryption slow, maybe it would be detected if it was fast? False. The encryption is fast, the version used in the test is slow cause of added delays b/w files, we tested all versions with these products and the ones that failed to detect also failed when run without the delay where the whole process happens in seconds.
How is this a malware simulation, isn't it like 7zip encrypting files? No. This is custom code that is unsigned and obfuscated that encrypts files like ransomware without asking the user. 7zip is a trusted application, with a cli and nothing like the file we are running.
If any vendors want help with improving their detections or get in touch with our community members who helped with the test, I'd be happy to facilitate. Our goal is to improve cybersecurity for everyone.

pcsecuritychannel
Автор

Great showing for Bitdefender! I like this as a realistic comparison, given a lot of malware attacks are able to get around signature detection, especially when the EDR is known to the attacker.

EricParker
Автор

For everyone asking for Kaspersky and other AVs, he commented under another comment that he will be doing a part 2 with Kaspersky, ESET and other AVs.

HCG
Автор

That is really interesting information! Would absolutely love to see n episode directly comparing business products from SentinelOne, Crowdstrike, ESET, Bitdefender, and whichever other endpoint there is against a large malware collection. I think as far as a single new malware this video is basically that (minus ESET), because I doubt the detection engine in personal vs business products is any different, but they are set up quite differently so would be interesting to see - and probably an extremely valuable resource for small businesses.

fhgnius
Автор

7:00 'There goes the library of Alexandria'

stagefan
Автор

So thankful I have a 10 user ultimate security license for Bitdefender for myself, wife, my daughters and their boyfriends. This video was certainly very comforting that I made the right decision. Thanks Leo.

HTW_
Автор

Love seeing Bitdefender do well. Been my go to for a long time.

jamesparker
Автор

Excellent video @pcsecuritychannel, It seems likely that behavior analytics aren't enabled for the CS product, as files are being encrypted and deleted immediately, which should be flagged by behavior monitoring. However, the key takeaway is spot on—it's crucial to pentest your high-cost solutions and regularly audit your prevention policy settings. Very informative.

Sunny-nb
Автор

You are defintely my favorite cybersecurity content creator by far. No cringe weird marketing tactics that only work on 12 year olds or anything. Straight to the point, no bs, I love it

tonyrivera
Автор

I have heard that some cybersecurity insurers are requiring the insured company to use an EDR as part of their security solution. Which makes this report even more interesting.

dennisdefotis
Автор

I’m an little surprised that bitdefender didn’t restore the files, I mean in the ransomware remediation section there is an option to have to checked to automatically restore files that were encrypted by ransomware, and an manual button to restore files that have been encrypted. Great video though Leo!

TheawesomeMCB
Автор

imagine paying big bucks for crowdstrike and still your data is gone

velo
Автор

Wow, Bitdefender did really good! Sophos also but I like how Bitdefender has the graphical display of the files.

BOOSTEDDUDE
Автор

Now do Malwarebytes EDR and Roll Back protection.

Ponyo
Автор

Good video. Sophos will restore any files encrypted before the alert, I.e before the behaviour is recognised to be malicious.

ek
Автор

New Danooct1 video and a new and unknown ransomware video from TPCSC. Today is good.

daemonspudguy
Автор

Hey, I am Sophos Security engineer, I do see that you are using the home premium version here, but I would like to share that the enterprise solution which is sophos central endpoint has more behavioral based component which is HMPA along with the XDR data collection.

My suggestion would be to test the sophos endpoint rather than the home version as the endpoint product is more targeted towards enterprise solutions.

Otherwise love watching you videos and you are making a serious contribution to the cybersecurity fields. Keep up the good work. Cheers!

GodofLibra
Автор

I'd like to see MalwareBytes with this test.

BeesCantSwim
Автор

I love how the program thread is called "Womp 1.0" 7:56

patrikondo
Автор

glad to see sophos still perfomes well in you tests since i've been using ever since you first showcased it in you channel and back then it was the best in you tests, because of the build in hitman pro

BLIZZnBLASTER