Comodo has the ability to prevent infection from trusted binaries (see the video I linked to above). Regarding msi detection inability, that is totally untrue (nonsense) and was discussed earlier. As for the EDR, I personally don't recommend the use as some can't understand it, and others add ill conceived Rules that have unintended consequences, and it really doesn't add to overall protection.
As to free AV's- one must break the shackles of trusting these. A relic of the past, either it has a definition for the malware or it does not. If one feels lucky, then use it- but to be better protected choose another path.
Cruelsister, I respect your experience and your contributions here, so I want to engage carefully. But I must point out three things that I cannot reconcile.
First: the MSI bypass. You called the MSI detection inability nonsense. But in this very thread, Andy Ful personally tested and confirmed that MSI files older than three days bypass auto containment in default settings.
He posted his results. He explained the mechanism msiexec.exe, rundll32.exe, trusted DLLs. He even corrected his own earlier post to include the isolation time limit he initially forgot. is Andy wrong? Because you and he cannot both be right in the same thread. One of you is describing reality, and the other is calling it nonsense. I would like to know which.
second, the EDR: YOU WROTE "It really doesn't add to overall protection," and I personally don't recommend the use. I want to make sure I am reading this correctly.
You a Comodo defender, Honorary Member, and Content Creator are saying that the headline new feature of CIS 2027 does not improve protection and should not be used. Shadowra called the EDR
a major plus in his review. You just called it a liability.
If the EDR does not add to protection, what exactly is the 2027 version offering over 2026? What is the user upgrading for? Because right now, it sounds like the emperor's new EDR is being politely described as ill-conceived rules with unintended consequences.
Third: the other path. You say we must break the shackles of free AVs and choose another path. I understand the philosophy. But philosophy is not evidence. You dismiss free AVs as relics that only work with existing definitions. Fair. But then I must ask what specific, measurable, testable protection does Comodo provide that a free AV does not? Not a video. Not a recommendation. Not a feeling. A concrete, reproducible result.
Because Shadowra's test showed 109 out of 162 threats remaining. The final scan caught 5, while Symantec caught 14. Those are numbers. Those are definitions. Those are not shackles. Those are results. And regarding your dismissal of free AVs as relics of the past let us look at the evidence, not just in this thread, but across Shadowra's channel.
He has tested Kaspersky, Bitdefender, and Windows Defender in separate reviews. In every single one of those tests, those products shined. They detected threats, blocked malware, and protected the system. And every one of them is either completely free or has a free tier that outperforms Comodo's paid offering.
I am not here to bash Comodo. I am here because three Comodo supporters in this thread have now said three different things: Andy says the bypass exists, you say it is nonsense, and Rashmi says HIPS does not flag malicious activity. I am trying to find the truth in the middle. But I cannot find it when the defenders disagree with each other more than the critics do.
i want toask ask what is Comodo's one concrete, measurable, reproducible advantage over a free AV, demonstrated in a test that you would accept as valid? Because right now, the EDR is dismissed by its own fans, the sandbox has confirmed bypasses, and the anti-malware engine has been called clearly bad by the tester. I want to believe there is more. Help me see it.