App Review COMODO Internet Security Pro 2027

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
Shadowra
That is not a complete security suite. That is a demo with a paywall.

The first is true. The second is unsupported by data.
You are wrong when thinking that I am a supporter of CIS. However, I try to critique CIS in a constructive way.

I think that we all agree that:
1. CIS in default configuration can protect home users well when they like such a solution and can use it in practice (it is not a solution for all).
2. The EDR advanced settings are not recommended for most users (but not for all).
3. The behavioral engine can block some unknown threats, but it is only a secondary protection layer for some suspicious actions.
4. A niche security solution (like Comodo Firewall) can be a strong addition to the Home AV.
 
Last edited:
The bypasses exist. They are probably non-existent in the wild in the home environment. EDR/HIPS in default settings does not flag the malicious activity of WiseConnect in the @Shadowra test. There is no disagreement here.
There is possible disagreement related to CIS efficiency against targeted attacks. However, there are no sufficient test data to confirm who is right.
thank you for this reply. By confirming that the bypasses exist, that the EDR failed to flag the activity in the test, and that there is no disagreement on these technical facts, you have brought absolute clarity to the discussion.

However, I must press on your conclusion: the idea that these bypasses are very rare in the wild for home users.

People do not install security software because threats are common; they install it because threats are devastating when they happen. A seatbelt is not considered useless just because car crashes are statistically rare. A lock is not deemed secure just because burglars rarely pick that specific model.

Security is about stopping the threat when it arrives, not assuming the attacker won't bother.

If the default settings allow the bypass, and the EDR fails to catch it, then the user's safety relies entirely on the attacker's choice to ignore them, rather than on the product's ability to stop them.

The first is true. The second is unsupported by data.
You are wrong when thinking that I am a supporter of CIS. However, I try to critique CIS in a constructive way.

I think that we all agree that:
1. CIS in default configuration can protect home users well when they like such a solution and can use it in practice (it is not a solution for all).
2. The EDR advanced settings are not recommended for most users (but not for all).
3. The behavioral engine can block some unknown threats, but it is only a secondary protection layer for some suspicious actions.
4. A niche security solution (like Comodo Firewall) can be a strong addition to the Home AV.
I appreciate the clarification that you approach this as a constructive critic rather than a blind supporter. In fact, your summary of what we all agree on is perhaps the strongest argument against using Comodo as a primary standalone antivirus that has been made in this entire thread.

Let us look at your four conclusions:
  1. It is not a complete suite, and not a solution for everyone.
  2. Its flagship 2027 feature (EDR) is not recommended for most users.
  3. Its behavioral engine is only a secondary protection layer.
  4. Its best use case is actually just the Firewall, as a supplementary addition to a diffrent Home AV.

When the product's most knowledgeable critic concludes that it is an incomplete suite, its main feature should be ignored by the majority, and it is best utilized as an add-on to a completely different antivirus... the debate is effectively settled. You have perfectly articulated why a standard user is better off relying on a complete, out-of-the-box free AV.

Thank you for this highly constructive summary. It has brought excellent clarity to the discussion, and I believe it serves as a perfect, respectful place for me to conclude my participation in this exchange.
 
Last edited:
  • Like
Reactions: Jonny Quest
I really appreciate you pulling the official release notes, because they perfectly validate the premise.

You confirmed three massive things in a single post. First, the flagship new 2027 feature is literally just a UI text change from HIPS to EDR to match Xcitium's branding.

Second, the specific folder protection tweak you actually rely on works perfectly fine with the EDR turned off. And third, your preferred way to use Comodo is to strip it down to just a firewall and let Microsoft Defender do the actual virus scanning.

If the 2027 upgrade is just a Find and Replace text patch, the utility you rely on doesn't even need it, and your ideal setup requires a free, built in Windows tool (SRP / APPLOCKER ) to handle the actual malware... what exactly is Comodo bringing to the table?

At that point, isn't it just a third-party firewall wearing an antivirus costume?

The release notes only mention this change and reliability improvements for updates.

People misinterpret how Comodo works and it's combination of different layers. The Protected Objects element of EDR is part of Comodo's core system protection hence the fix for a containment elevated permissions fix with version 12.3.4.8162 where they added Windows Sockets Interface to Protected Files under HIPS/Protected Objects.

With Comodo, it's not about signatures. By default CIS ships with a Light version of the AV database for reduced system resource usage and the signatures with Comodo are more about naming the unknown file because any uknown file will be sandboxed and then checked with File Rating, Viruscope and cloud lookup. You can have it use the full signature base under the Update Settings but there isn't much point given that Comodo will upload and analyse the sandboxed file. Comodo and Xcitium share the same cloud signature base.

You can totally just use Comodo Firewall on it's own as it provides the same level of protection just without the on demand scanning and use whichever AV of your choice though there has been some software conflict with the likes of Kaspersky. The only thing really that full internet security product adds is the on demand virus scanning which is something @cruelsister has pointed out several times in her videos. You can even run @Andy Ful 's Hard_Configurator product with CIS or CFW installed though you might get some performance impact because of Comodo's kernel level hooks. I use full CIS because why have the additional 250mb+ ram being used up by Microsoft Defender when CIS sitting in the background is just using 40mb all together.

I'm not the expert here, it works for me and with this latest version bringing naming in line with Xcitium, I'm hopeful that any fixes or changes implemented such as the recent DLL fix in Xcitium will hopefully filter through quicker to the consumer product.

Anyway, others have clarified most of these points already and in recent posts since drafting this reply so will leave it to people to judge for themselves what they decide to use when protecting their data.
 
  • Like
Reactions: Jonny Quest
Anyway, others have clarified most of these points already and in recent posts since drafting this reply so will leave it to people to judge for themselves what they decide to use when protecting their data.
I appreciate the drafted reply. While saving 210MB of RAM is a nice optimization, it is a steep trade to justify on a modern 8GB or 16GB system when the cost is sacrificing out of the box security for manual configuration.

But I completely agree with your final sentence: the technical realities are on the table, and the readers can now judge for themselves. Thank you again for the exchange.
 
  • Like
Reactions: Jonny Quest
Security is about stopping the threat when it arrives, not assuming the attacker won't bother.

CIS stops most threats when they arrive. It is a fact that attackers do not bother, not an assumption.
However, you can freely use those solutions that attackers bother to bypass all the time (successfully in many cases).

Let us look at your four conclusions:
  1. It is not a complete suite, and not a solution for everyone.
  2. Its flagship 2027 feature (EDR) is not recommended for most users.
  3. Its behavioral engine is only a secondary protection layer.
  4. Its best use case is actually just the Firewall, as a supplementary addition to a different Home AV.

The last point is incorrect. The best use case is auto-containment combined with a firewall. The contained processes cannot make connections.

You have perfectly articulated why a standard user is better off relying on a complete, out-of-the-box free AV.

We have a different meaning of complete security. There is no complete out-of-the-box Home AV.