This test shows how an antivirus behaves with certain threats, in a specific environment and under certain conditions.
We encourage you to compare these results with others and take informed decisions on what security products to use.
Before buying an antivirus you should consider factors such as price, ease of use, compatibility, and support. Installing a free trial version allows an antivirus to be tested in everyday use before purchase.
Hello @Adrian Ścibor we have alredy Blacklisted 10 samples,we will keep goingYou can check out about the SHA by download all results for every single sample by all vendors. The technical data from the test is transparent for everyone.
Click on "DOWNLOAD COMPARISON TABLE": Recent Results » AVLab Cybersecurity Foundation
View attachment 290532
Malware Analysts team
Hello @Andy Ful we work for Xcitium now the name is rebranded from Comodo to XcitiumDo you and this team officially work for Comodo?
Hello @Andy Ful we work for Xcitium now the name is rebranded from Comodo to Xcitium
Best Regards
Nikola
We are Malware Analysts only if someone needs support team from Xcitium the email is support@xcitium.comWelcome Xcitium team, here on MT.![]()
Melih and official Comodo staff don't reply to or confirm the mod comments; I agree you cannot take them as an official statement.I think it was a moderator (DecimaTech). Melih and @Umut (official Comodo staff) also participated in this thread and did not correct anything posted by DecimaTech. I think that those posts include valid information; however, you cannot take them as an official statement.
I believe you can break any protection measures. Yes, you can bypass Comodo using vulnerabilities, protection design, etc.As you can read from the provided links, some restriction levels (higher than partially limited) were intended to prevent bypass, although they did not due to incompatibility with UAC. However, it is not important. There are known ways to tamper with Comodo drivers and services, so the sandbox design can be bypassed (if someone is highly motivated). You cannot assume that malware that bypassed Comodo has to do it without bypassing the sandbox.
Anyway, I think that bypassing Comodo fully from the sandbox will be rather related to possible incompatibility with Windows UAC, like in the recent bypass. Although this particular bypass was patched, there is no information about solving the UAC incompatibility. A similar problem was in Sandboxie, where the higher isolation required disabling elevation to Administrator rights.
I agree with you about Comodo AV and whitelisted malware. Comodo will not integrate Valkyrie in CIS, as Comodo Cloud provides Valkyrie detection as per Melih.I'll be brief about Comodo:
My message is not intended to insult Comodo's staff or its users, but I am speaking as a tester.
Comodo as an AV engine is a real joke. It detects too few threats, and some of them are even old...
Comodo pushes everything to the Sandbox, which can be a good compromise, but also insufficient.
All it takes is for malware to be signed or steal the signature that is placed in Comodo's Whitelist => No sandbox, malware allowed...
I'm still waiting for Valkyrie to be integrated into the AV engine, at which point its engine will be almost on par with the competition...
I guess @Nikola Milanovic didn't mean he is official Xcitium staff. Did you @Nikola Milanovic?Welcome Xcitium team, here on MT.![]()
Hello @rashmi we are employees of Xcitium we work for Xcitium so we are official Xcitium EmployeesMelih and official Comodo staff don't reply to or confirm the mod comments; I agree you cannot take them as an official statement.
I believe you can break any protection measures. Yes, you can bypass Comodo using vulnerabilities, protection design, etc.
Higher restriction levels mean more limits. They improve security but affect containment usability. The theory that "default security" is weak is misleading. There have been no confirmed Comodo bypasses. At least, I am not aware of any. The recent PoC bypassed default and custom setups. Did the tester disable UAC and test Comodo with restriction levels? Did the PoC bypass defaults but not the higher restriction level?
I agree with you about Comodo AV and whitelisted malware. Comodo will not integrate Valkyrie in CIS, as Comodo Cloud provides Valkyrie detection as per Melih.
I don't agree with the statement, "Comodo pushes everything to the sandbox." In a malware-only test, what do you expect from a security layer that protects against malware and unknown files?
You contradict yourself when you recommend, say, a smart-deny program like CyberLock when it blocks everything in your test, but you give the opposite reaction for Comodo when it performs similarly to CyberLock or contains everything, especially when there is no usability test. Comodo's usability is far better than CyberLock's.
I guess @Nikola Milanovic didn't mean he is official Xcitium staff. Did you @Nikola Milanovic?
yikes suddenly I am getting phone calls to my iphone from Xcitium (sales I presume) I know I did NOT give them my phone number when I signed up for Valkyrie online...Hello @rashmi we are employees of Xcitium we work for Xcitium so we are official Xcitium Employees
Its Nikola.yikes suddenly I am getting phone calls to my iphone from Xcitium (sales I presume) I know I did NOT give them my phone number when I signed up for Valkyrie online...![]()
hacke your phone to prove their comptenceyikes suddenly I am getting phone calls to my iphone from Xcitium (sales I presume) I know I did NOT give them my phone number when I signed up for Valkyrie online...![]()
Hello @simmerskool did this number call you +1 (973) 859-4000 or this number +1 (888) 551-1531?yikes suddenly I am getting phone calls to my iphone from Xcitium (sales I presume) I know I did NOT give them my phone number when I signed up for Valkyrie online...![]()
well I thought I had deleted the call, but at 20:26 UTC my phone shows 973-265-9528 XCITIUM. -- I might have given Xcitium EDR my number 17 months ago, March 2024, when I considered installing Xcitium on a VM, but decided to wait and see... I assume this was a legit call unless someone is spoofing Xcitium -- unsolicited calls will not convince me...Hello @simmerskool did this number call you +1 (973) 859-4000 or this number +1 (888) 551-1531?
Please let us know
Best Regards
Nikola
Hello @simmerskool we are sorry for the inconvinience please drop email to support@xcitium.com and any releated screenshots please do drop team will be able to assist you with your querywell I thought I had deleted the call, but at 20:26 UTC my phone shows 973-265-9528 XCITIUM. -- I might have given Xcitium EDR my number 17 months ago, March 2024, when I considered installing Xcitium on a VM, but decided to wait and see... I assume this was a legit call unless someone is spoofing Xcitium -- unsolicited calls will not convince me...