App Review COMODO Internet Security Pro 2027

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
Shadowra
Comodo worked as expected and as per its design!
But in that "expected" design, a ConnectWise MSI installer bypassed containment, dropped a malicious DLL via rundll32, and infected the machine.

If a security product's design allows a trusted binary to deliver malware undetected, then the design itself is the vulnerability. Working as designed is not a defense here it is the problem.

if this is Comodo working correctly, what would you accept as Comodo failing? Because if no outcome counts as failure, the product is unfalsifiable, and an unfalsifiable security product gives only false confidence.
 
Last edited:
HIPS don't flag malicious activities; they provide typical HIPS messages. HIPS might flag malicious activities if the sample is in the Comodo databases (at least it used to).
So the new 2027 EDR is basically a signature scanner that rebranded itself on internet and now demands to be called "EDR." Classic Comodo , same engine, new sticker.

what does this EDR catch that a free AV from 2015 doesn't?
 
"no evidence it's worse" is not a defense for a security product it is an admission of unproven reliability. What specific evidence would you accept as informative about CIS, if not a real-world test?

In the case of CIS, I think 20 real-world tests (500 samples per test) could be OK.
 
Last edited:
But in that "expected" design, a ConnectWise MSI installer bypassed containment, dropped a malicious DLL via rundll32, and infected the machine.

The test was done in default settings.
In the settings used by @cruelsister, such malware is almost always auto-contained. There is no evidence that other AVs are better. From what I know about CIS in Proactive Security configuration, it can be better than most AVs against this type of malware.
 
Any tests on how well it does in protecting a system like any other av?

There have been some tests over the last few years, but they are far from being complete. CIS was tested by AVLab a few times (only EXE files). The auto-containment was tested in SE Labs tests on Comodo Antivirus (CAV missed 7 samples in 2024, below-average result on targeted samples). However, in the case of CAV, the auto-containment probably allowed malware to call home (no Firewall shield). @Shadowra tested CIS a few times. All these results are inconclusive in proving with high confidence whether CIS protection is better or worse.
 
Last edited:
So the new 2027 EDR is basically a signature scanner ...
...
what does this EDR catch that a free AV from 2015 doesn't?

You should learn more about CIS. It is not Comodo Antivirus, and it is not just a signature scanner.
 
In the case of CIS, I think 20 real-world tests could be OK.
The test was done in default settings.
In the settings used by @cruelsister, such malware is almost always auto-contained
You should learn more about CIS. It is not Comodo Antivirus, and it is not just a signature scanner.

thank you for taking the time to reply to each point. I genuinely appreciate the engagement. However, I must highlight a pattern I cannot ignore.


When Shadowra published his test, the response was "there is no evidence." When asked what evidence would count, you sai 20 real world tests could be OK.

Shadowra's test is a realworld test , in fact, it is one of the most thorough I have seen on this forum. But now it is dismissed because it used "default settings." The next is that Proactive Security configuration would handle it better.

But let us be honest about what Proactive Security actually does. It blocks everything unknown, indiscriminately. It does not intelligently detect threats. It does not analyze behavior. It simply says unknown? blocked.

That is not advanced protection. That is a paranoid whitelist that any free tool Windows AppLocker, a basic firewall rule, even a wellconfigured router could replicate.

Calling that better than most AVs is like calling a locked room with no doors better architecture. Sure, nothing gets in. But nothing gets out either, and the user must manually open every single door.

So here is my question, If the default settings are insecure, and the "fix" is to block everything like a whitelist tool from 2005, then what is Comodo actual intelligence doing for the user? What is the product contributing beyond what a free, manual, blunt instrument already provides?

And I must reask the EDR question, because it remains unanswered. You told me to learn more about CIS and said it is not just a signature scanner. I am happy to learn.

So please, teach me: What specific threat does the 2027 EDR detect and stop that a basic signature-based antivirus from 2015 does not? Not a general description. A specific, concrete example. Because right now, even Rashmi a Comodo supporter admitted in this thread that "HIPS don't flag malicious activities unless the sample is already in Comodo's database. If the EDR cannot catch unknown threats, and the sandbox can be bypassed via trusted binaries and MSI installers, then I struggle to see what the user is actually protected by.


I say this not to attack Comodo. I say it because the goalposts have moved four times in four posts, and each time, the burden shifts further onto the user. First, the user must provide 20 tests. Then, the user must use the right settings. Then, the user must learn more. But the user who installs Comodo and clicks Next, Next, Finish the user who trusts the product to protect them out of the box that user is not being protected by the product. That user is being asked to protect themselves from the product's defaults.

what does the EDR catch, concretely, that a 2015 free AV does not?
 
  • Like
Reactions: Khushal
and the sandbox can be bypassed via trusted binaries and MSI installers,
Comodo has the ability to prevent infection from trusted binaries (see the video I linked to above). Regarding msi detection inability, that is totally untrue (nonsense) and was discussed earlier. As for the EDR, I personally don't recommend the use as some can't understand it, and others add ill conceived Rules that have unintended consequences, and it really doesn't add to overall protection.

As to free AV's- one must break the shackles of trusting these. A relic of the past, either it has a definition for the malware or it does not. If one feels lucky, then use it- but to be better protected choose another path.
 
  • Like
Reactions: Khushal
So here is my question, If the default settings are insecure, ...

My friend, when I suggested learning more about CIS, I did not have in mind that I wanted to be your teacher. :)
However, I can share some information.
The default settings are not insecure. They are simply less restrictive and more convenient than Proactive setup. Still, probably as strong as most AVs.

and the "fix" is to block everything like a whitelist tool from 2005, then what is Comodo actual intelligence doing for the user? What is the product contributing beyond what a free, manual, blunt instrument already provides?

Unlike typical allowlisting solutions, CIS does not block everything unknown but can run unsafe programs in a sandbox.
There is not much next-gen intelligence in local CIS files, but it is in the Valkyrie Sandbox (many files are whitelisted by this kind of intelligence). There is also an intelligent design hidden in the applied restrictions. However, this design is still too confusing for many users. Furthermore, Valkyrie is not fully integrated in CIS, as it is for Xcitium.

So please, teach me: What specific threat does the 2027 EDR detect and stop that a basic signature-based antivirus from 2015 does not?

@cruelsister can show you many examples.

If the EDR cannot catch unknown threats ...

It can catch many unknown threats, but not in the tested settings. However, the EDR/HIPS settings are the most controversial ones.

... and the sandbox can be bypassed via trusted binaries and MSI installers, then I struggle to see what the user is actually protected by.

Although CIS can be bypassed, this happens only rarely in the wild. You can find more information here:

First, the user must provide 20 tests.

The user must not do this. Anyone can simply believe @cruelsister.:)

Then, the user must use the right settings. Then, the user must learn more. But the user who installs Comodo and clicks Next, Next, Finish the user who trusts the product to protect them out of the box that user is not being protected by the product. That user is being asked to protect themselves from the product's defaults.

You are right. That is why most people do not use CIS. It can be better only for some people.(y)
 
Last edited:
So the new 2027 EDR is basically a signature scanner that rebranded itself on internet and now demands to be called "EDR." Classic Comodo , same engine, new sticker.

what does this EDR catch that a free AV from 2015 doesn't?

As per the official release notes, EDR is a rebranding of HIPS so it's in line with Xcitium endpoint terminology.

"This release completes our transition from HIPS to EDR terminology across the CIS Agent — unifying naming across the interface, tray menu, and system messages — while also resolving key update reliability issues and installer inconsistencies to ensure a smoother setup and update process."

I use EDR with CIS in Proactive configuration as it's enabled by default but the only tweaks I make to it adding Documents and some App Data folders in "Protected Data" that makes the contents of those folders invisible to sandboxed files and processes. You can still use this feature even with EDR/HIPS disabled.

CIS can be complex and confusing if you don't have experience with it but works well for me either as full CIS or just the Firewall element where I just let MD to the virus scanning.
 
1786041345250.png


I do not like dogs. I feel safer with ComoDino.:)
It is my personal choice!

Edit.
I slightly edited the comment.
 
Last edited:
Comodo has the ability to prevent infection from trusted binaries (see the video I linked to above). Regarding msi detection inability, that is totally untrue (nonsense) and was discussed earlier. As for the EDR, I personally don't recommend the use as some can't understand it, and others add ill conceived Rules that have unintended consequences, and it really doesn't add to overall protection.

As to free AV's- one must break the shackles of trusting these. A relic of the past, either it has a definition for the malware or it does not. If one feels lucky, then use it- but to be better protected choose another path.
Cruelsister, I respect your experience and your contributions here, so I want to engage carefully. But I must point out three things that I cannot reconcile.

First: the MSI bypass. You called the MSI detection inability nonsense. But in this very thread, Andy Ful personally tested and confirmed that MSI files older than three days bypass auto containment in default settings.

He posted his results. He explained the mechanism msiexec.exe, rundll32.exe, trusted DLLs. He even corrected his own earlier post to include the isolation time limit he initially forgot. is Andy wrong? Because you and he cannot both be right in the same thread. One of you is describing reality, and the other is calling it nonsense. I would like to know which.

second, the EDR: YOU WROTE "It really doesn't add to overall protection," and I personally don't recommend the use. I want to make sure I am reading this correctly.

You a Comodo defender, Honorary Member, and Content Creator are saying that the headline new feature of CIS 2027 does not improve protection and should not be used. Shadowra called the EDR a major plus in his review. You just called it a liability.

If the EDR does not add to protection, what exactly is the 2027 version offering over 2026? What is the user upgrading for? Because right now, it sounds like the emperor's new EDR is being politely described as ill-conceived rules with unintended consequences.

Third: the other path. You say we must break the shackles of free AVs and choose another path. I understand the philosophy. But philosophy is not evidence. You dismiss free AVs as relics that only work with existing definitions. Fair. But then I must ask what specific, measurable, testable protection does Comodo provide that a free AV does not? Not a video. Not a recommendation. Not a feeling. A concrete, reproducible result.

Because Shadowra's test showed 109 out of 162 threats remaining. The final scan caught 5, while Symantec caught 14. Those are numbers. Those are definitions. Those are not shackles. Those are results. And regarding your dismissal of free AVs as relics of the past let us look at the evidence, not just in this thread, but across Shadowra's channel.

He has tested Kaspersky, Bitdefender, and Windows Defender in separate reviews. In every single one of those tests, those products shined. They detected threats, blocked malware, and protected the system. And every one of them is either completely free or has a free tier that outperforms Comodo's paid offering.

I am not here to bash Comodo. I am here because three Comodo supporters in this thread have now said three different things: Andy says the bypass exists, you say it is nonsense, and Rashmi says HIPS does not flag malicious activity. I am trying to find the truth in the middle. But I cannot find it when the defenders disagree with each other more than the critics do.

i want toask ask what is Comodo's one concrete, measurable, reproducible advantage over a free AV, demonstrated in a test that you would accept as valid? Because right now, the EDR is dismissed by its own fans, the sandbox has confirmed bypasses, and the anti-malware engine has been called clearly bad by the tester. I want to believe there is more. Help me see it.
 
There is not much next-gen intelligenc
Andy You confirmed that local files lack next-gen intelligence and that the true analytical brain Valkyrie is not fully integrated here, but rather belongs to Xcitium. So the user installing this gets a product whose core intelligence is housed in a different, enterprise focused ecosystem, only partially connected.

That is not a complete security suite. That is a demo with a paywall.

Then there is the EDR, the headline feature of the 2027 release. You noted it can catch unknown threats, but explicitly not in the default settings it ships with. Meanwhile, other long time defenders in this very thread have stated that the EDR doesn't actually add to overall protection and shouldn't even be used, while also admitting that the HIPS module cannot flag malicious activities unless the sample is already known in the database.

So we have a situation where the product's most vocal supporters are collectively admitting three things:

1- The default configuration fails to protect the standard user.
2- The flagship EDR feature is either ineffective or too dangerous to recommend.
3- The behavioral engine cannot detect unknown threats on its own.

I am not attacking the product. I am just reading what its own defenders have written.


Why is CIS the most disputed solution on MT?

The answer is right here in this thread: its own defenders cannot agree on what it actually does. One confirms the MSI bypass exists, another calls that same bypass nonsense, and the default protection is described as merely comparable to competitors, with that assumption doing a lot of heavy lifting.

If the software is only for a niche group of experts, the flagship EDR is dismissed by its own fans, and the core intelligence belongs to a different product entirely what is the 2027 version actually offering to the home user who simply clicks Install? Not what it could offer with hours of expert configuration. What does it offer out of the box?

Your previous reply already answered this by conceding the main point. I am just asking for it to be stated clearly, so everyone reading this thread understands exactly what this product isand what it is not.

Thank you for the conversation.
 
  • Like
Reactions: Divine_Barakah
As per the official release notes, EDR is a rebranding of HIPS so it's in line with Xcitium endpoint terminology.

"This release completes our transition from HIPS to EDR terminology across the CIS Agent — unifying naming across the interface, tray menu, and system messages — while also resolving key update reliability issues and installer inconsistencies to ensure a smoother setup and update process."

I use EDR with CIS in Proactive configuration as it's enabled by default but the only tweaks I make to it adding Documents and some App Data folders in "Protected Data" that makes the contents of those folders invisible to sandboxed files and processes. You can still use this feature even with EDR/HIPS disabled.

CIS can be complex and confusing if you don't have experience with it but works well for me either as full CIS or just the Firewall element where I just let MD to the virus scanning.
I really appreciate you pulling the official release notes, because they perfectly validate the premise.

You confirmed three massive things in a single post. First, the flagship new 2027 feature is literally just a UI text change from HIPS to EDR to match Xcitium's branding.

Second, the specific folder protection tweak you actually rely on works perfectly fine with the EDR turned off. And third, your preferred way to use Comodo is to strip it down to just a firewall and let Microsoft Defender do the actual virus scanning.

If the 2027 upgrade is just a Find and Replace text patch, the utility you rely on doesn't even need it, and your ideal setup requires a free, built in Windows tool (SRP / APPLOCKER ) to handle the actual malware... what exactly is Comodo bringing to the table?

At that point, isn't it just a third-party firewall wearing an antivirus costume?
 
First: the MSI bypass. You called the MSI detection inability nonsense. But in this very thread, Andy Ful personally tested and confirmed that MSI files older than three days bypass auto containment in default settings.

That is true for some files, like those downloaded from the flash drive to the hard disk. However, CIS in the default settings has additional rules for most popular delivery methods, such as files downloaded from the Internet. So, as I mentioned in my previous post, CIS can be bypassed in the wild very rarely.

I am not here to bash Comodo. I am here because three Comodo supporters in this thread have now said three different things: Andy says the bypass exists, you say it is nonsense, and Rashmi says HIPS does not flag malicious activity. I am trying to find the truth in the middle. But I cannot find it when the defenders disagree with each other more than the critics do.

The bypasses exist. They are probably non-existent in the wild in the home environment. EDR/HIPS in default settings does not flag the malicious activity of WiseConnect in the @Shadowra test. There is no disagreement here.
There is possible disagreement related to CIS efficiency against targeted attacks. However, there are no sufficient test data to confirm who is right.
 
Closely following the thread, it seems that some members are trying to find the middle ground despite the facts that have been stated in here. While others are blindly defending Comodo

I believe we can safely conclude that those who defend Comodo are user (or have used) Comodo. And the aforementioned do not use Comodo on the default settings.

The lack of "sufficient" tests/data to prove that Comodo is NOT better/worse that any other solutions in attacks that are rare in home setting proves that there is minimal advantage/disadvantage of using Comodo over any other solution.
 
  • Like
Reactions: Andy Ful