App Review COMODO Internet Security Pro 2027

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
Shadowra

Shadowra

Level 41
Thread author
Verified
Top Poster
Content Creator
Malware Tester
Well-known
High Reputation
Forum Veteran
Sep 2, 2021
3,096
39,651
3,980
29
France
COMODO is an American publisher, well known among computer geeks.
The software presents itself as a totally free security suite, offering defensive shields: anti-malware, firewall, HIPS and a sandbox.
We got the software first, so here's our test!

Let’s take a closer look at all of this.



Interface :

The interface is identical to that of the 2026 version. The new feature is in the configuration: Comodo now includes EDR!
In fact, the EDR will detect dangerous behavior and attempt to mitigate the ongoing attack. This is a major plus.
The antivirus is also trying to become a bit more accessible to beginners, even though it remains geared toward advanced users.
During installation, I accepted Comodo’s secure DNS and cloud-based scanning.

Malware URL : 8/8
Comodo does not block any websites using its web filtering or DNS. Only one piece of malware is blocked by its anti-malware engine.
Other malware is sent to the sandbox without attacking the system.

Malware Pack : 109 out of 162 threats remain
COMODO's anti-malware is clearly bad, and it has been for years.
On the other hand, Comodo's strength is its sandbox!
Even when I threw some major challenges at it (like two ransomware samples that locked up the system and were difficult for me to deal with so I could continue the test), the machine held up.
And we started from a tough spot! Between Trojans, attacks, and computer worms, the memory was completely saturated!
But the sandbox is NOT perfect. ConnectWise slips through undetected because it’s signed (so Comodo trusts it) and the machine is riddled with traces of infections detected by Comodo itself during a quick scan and by other scanning tools (KVRT even detects a memory infection!!)

Final scan :
Comodo 5
Symantec : 14
Emsisoft : 14
KVRT : 12 (Memory infected !!)
Eset : 9

Final opinion:

It's hard to give it a rating.
Comodo is a good basic product, but it has several drawbacks:
- Very poor anti-malware protection
- The sandbox is good but won't prevent a memory infection or a registry entry made by malware (you can see the traces in JS/VBS scripts)
- Web filtering is nonexistent

Given these shortcomings, I don’t really see Comodo as a complete suite. But it could work as a backup alongside another antimalware program.
 
This result was expected for CIS default settings (Internet Security configuration). It auto-contains the unrecognized files (also digitally signed) that are less than 3 days old. CIS can also skip containing the signed malware if the signer is on the Trusted Vendor List. There can also be some false negatives (Valkyrie Snadbox bypassed). I am not sure which was the case in the video. In the case of a false negative, the malware would be auto-contained as a 0-day (the Comodo Valkyrie analysis can take some days).
That is why the recommended setup for CIS (on MT and Wilders Security forums) is Proactive Security configuration + reduced Trusted Vendor List (false negatives can still bypass the auto-containment in the test).
Comodo auto-containment with Internet Security configuration was tested many times by SE Labs, and the results were similar to those in the video.

SE Labs 2024 (Consumer):

total samples ........................... 300 100
Avast Free Antivirus ............... 0 ...... 0
Comodo Antivirus .................. 0 ..... 7
Kaspersky Plus ......................... 0 ..... 0
McAfee Total Protection ...... 0 ..... 1
Microsoft Defender ............... 3 ..... 0
Norton360 ................................ 0 ..... 2
Panda Free/Dome .................. 4 ......13
Sophos Home Premium ...... 0 ...... 0
Webroot Antivirus ................. 2 ...... 9

As we can see, the result for commodity malware (the first scoring column) is perfect, but not for targeted attacks (the second scoring column).
 
Last edited: