AVLab.pl Advanced In-The-Wild Malware Test in March 2026 including effectiveness analysis and telemetry

Disclaimer
  1. This test shows how an antivirus behaves with certain threats, in a specific environment and under certain conditions.
    We encourage you to compare these results with others and take informed decisions on what security products to use.
    Before buying an antivirus you should consider factors such as price, ease of use, compatibility, and support. Installing a free trial version allows an antivirus to be tested in everyday use before purchase.

MS defender is known for predominance of post-execution than pre-execution stopping of threats, may be related on relying mainly on the cloud, as it is shown in July 2025 test results.
View attachment 297207

Surprisingly, two quarters later, MS defender became not relying on the cloud that much, as its pre-execution detection predominate in Jan 2026 test results!
View attachment 297208
This may be due to switching from Firefox to Opera each version has its own description in the article, so you should look for it in the details.

Additionally, in May 2026, we’re using Block Mode for Microsoft EDR, which I suppose is the default setting.

As for the rest of the calculations. OK though without concrete data like ours, we can’t say with 100% certainty what quality of samples AV-T and AV-C are using.
In our tests, results are often worse at first, before publication, but later, after contacting the vendor, it turns out that some samples have to be removed because they don’t work. So a result of, say, 98% becomes 99.8%, but that’s better than pretending that the 10 samples that didn’t work are still included in the test. That’s why I mention that other lab don’t share details with vendors, so they can’t respond to them and influence a change in the result.

I’ve been in this industry for a while now, and sometimes what’s written in a PDF doesn’t match reality. On the other hand, a lack of evidence also means there’s no way to prove something isn’t true. Of course, this is just a theory.

From what I know, samples from the RTTL database are still being used, but not by us, because there’s nothing interesting there except for Linux samples: scripts and binaries. It’s not a database focused on Windows samples.

I think this is important: :)

On the other hand, due to the lack of good samples in the wild, we have already started working on a project in March 2026 in collaboration with the global community. We want to provide them with a project that, on the one hand, will enhance their online security, and on the other, will allow us to collect samples for testing. Details will be available once the MVP project for the community and business is released publicly. We may invite someone from the MT forum to test it and provide feedback before the release.
 
Corrected, I can be prone to such mistakes
Thank You for the heads up albeit the intended meaning was conveyed.
me too but I was unclear last night whether "its" referred to mabwarebytes, avast, ME, or AvLab -- perhaps lack of sleep... I'm probably getting too picky as I draft prompts to AI/LLM. :rolleyes: