The HTTPS scanning method used by ESET and most other AV products (those who have this feature) involves the AV directly being a middleman between the web server and the browser, so the website's certificates are replaced by ESET's self-signing certificate.
The downside is we can not check the original certificate of the website. Browser makers hate this method as many of them call it security through obscurity.
Another downside is, it breaks security and privacy features like, Encrypted Client Hello.
Avast has been using a different method for many years. Instead of being a direct middleman, it relies on using the secret SSLKEYLOGFILE to reveal the contents of the secured HTTPS connection.
After Avast, now Kaspersky is also adopting this method. In the next version of Kaspersky, they are replacing the old method with the SSLKEYLOGFILE method. Currently in the testing phase, they are calling it, SuperMITM.
