App Review COMODO Internet Security Pro 2027 (Re-Test)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
Shadowra

Shadowra

Level 42
Thread author
Verified
Top Poster
Content Creator
Malware Tester
Well-known
High Reputation
Forum Veteran
Sep 2, 2021
3,149
40,267
4,080
29
France
Comodo Internet Security Pro 2027 is back for a full re-test!

Comodo Internet Security Pro combines antivirus protection, firewall capabilities, behavioral detection and its famous sandbox technology to protect Windows systems against malware and other threats.
Since my previous test, the developers have fixed several issues that were identified during the original evaluation. So, rather than simply relying on the previous results, I decided to give Comodo another chance and test the latest version from scratch.
In this re-test, I put Comodo Internet Security Pro 2027 through a new series of real-world security tests, including malicious URLs, malware samples, ransomware and other threats.
Have the fixes made a difference? How does Comodo perform now?

Let's find out!



Interface :

The interface is identical to that of the 2026 version. The new feature is in the configuration: Comodo now includes EDR!
In fact, the EDR will detect dangerous behavior and attempt to mitigate the ongoing attack. This is a major plus.
The antivirus is also trying to become a bit more accessible to beginners, even though it remains geared toward advanced users.
During installation, I accepted Comodo’s secure DNS and cloud-based scanning.

Malware URL : 8/8
The anti-malware engine detected a piece of malware.
The rest was sent to its sandbox for isolation.
No damage was caused.

Malware Pack : 114 out of 168 threats remain
Let's be honest: Comodo doesn't exactly shine when it comes to its engine's detection rate. I think its engine is really just a secondary feature.
On the other hand, its isolation is very good. The issues I had noticed have been properly fixed; Comodo isolates threats correctly.
Even though I had to restart the machine because the Unicorn worm tried to overload the RAM, there was nothing left active after the restart.

Final scan :
Comodo : 0
Emsisoft : 16 (traces in the Sandbox and on the system; not active)

Final opinion:

Comodo listened to the feedback and completely overhauled the software.
The Sandbox bugs have been fixed, and the software seems to run more smoothly than before.
What I find unfortunate is that its anti-malware feature seems to have been completely neglected, given its very low detection rate, and the same goes for its web filtering (both software-based and DNS-based): it didn’t block a single page!
It’s finally back among the top-rated programs; it’s worth recommending, but not for beginners—it’s still quite complicated for them. Intended for advanced users.

(There's a surprise at the end of the video—Comodo fans, please don't be mad at me; I just couldn't help myself :D)
 
Last edited:
1790107000811.png
(y)(y)(y):ROFLMAO::ROFLMAO::ROFLMAO:
 
@Shadowra, thank you for your dedication and for consistently raising the level of testing within the community. The clarity and rigor of your work help us better understand the real‑world behavior of each security solution. Your contribution makes MalwareTips a more reliable and valuable place for everyone. 🔧🛡️
 
Nice video, and thanks for taking the time to do it. I agree with most (especially the web and AV modules being deficient), however must disagree about the product being for advanced users. If one puts C into silent mode there would be no choices for the user to make, so no advanced knowledge needed.

Regarding Containment, Enterprise products have certainly realized the power of the sandbox in protection from malware: Palo Alto, Zscaler, Check Point SandBlast, and Cisco Secure Malware Analytics utilize such containment and analysis in the Cloud; unknowns need to be uploaded first before analysis whereas Comodo does such analysis Locally on the system. The importance of the sandbox in containment was seen a little while ago with the Antigravity (double signed) malware which was caught by the products mentioned above but blown off by others.
 
So were all of these contained before they could do any damage?

Yep. Everything is safely stored in memory and sandboxed, including the injections.
When I reboot after Unicorn tries to overload the RAM, nothing is left in memory.
But there are some small traces (many of them in the sandbox), though no malicious activity.
 
Excuse me but
The new feature is in the configuration: Comodo now includes EDR!
This is just the old HIPS.

the developers have fixed several issues that were identified during the original evaluation.
Where can we read an official Comodo statemant what has been fixed?

Comodo listened to the feedback and completely overhauled the software.
The Sandbox bugs have been fixed,
Really a complete overhaul? Cannot believe that, Comodo would never do that.
There is no changelog which tells us what has been fixed (and what not).

Please don't get me wrong, you are doing really a great job, I just have my doubts about above points...
 
  • Wow
Reactions: lokamoka820
Excuse me but

This is just the old HIPS.


Where can we read an official Comodo statemant what has been fixed?


Really a complete overhaul? Cannot believe that, Comodo would never do that.
There is no changelog which tells us what has been fixed (and what not).

Please don't get me wrong, you are doing really a great job, I just have my doubts about above points...

1. Yep
2. From the Comodo forum. Keep in mind that I made the video about a month ago; I read there often :)
3. Same thing, on the Comodo forum. A lot of issues have been fixed since my first test of version 2027 (and a lot of people criticized the first version...)
 
  • +Reputation
Reactions: lokamoka820
I don't see any specific bug fixes nor a changelog on Comodo forum for 2027 version, maybe I've missed something.