Software Review Comodo Internet Security vs targeted ransomware attack.

Reviews reflect the reviewer's setup and methods. Check the evidence and limitations.
Content created by
me
The Advanced Threat Protection tests included in my previous post were slightly outdated.
So, I inspected the attack vectors included in newer tests (do not include CIS/CCS/Xcitium).


The newer tests include some of the methods that might bypass CIS (such as DLL hijacking). However, the required methods are applied at the later infection stages, when the attack is already contained. For example (the red part of the attack can be auto-contained):

Email with attachment ---> EXE or script file in the archive ----> EXE or script file unpacked/executed ----> ... ----> DLL hijacking

It is rather clear that the used attack vectors are prepared to bypass NextGen solutions and do not bother to bypass Comodo.
 
AV-Comparatives Advanced Threat Protection tests.


One of the scenarios used in the tests can bypass CIS (as I mentioned in my previous posts).
Advanced Threat Protection Test 2022 - Enterprise

15. This threat is introduced via Removable Media. A malicious office document injects into another user-space process and opens a C2 channel to a commercial C2 framework via https.

Documents on infected removable media do not have Mark of the Web, so macros are not blocked by default in MS Office. The attacker can use VBA code that applies PE injection. The code is well known and effective against CIS (I tested it some time ago). In this case, the VBA macro does not invoke PowerShell, Windows Script Host, or anything that Comodo Script Analysis could block. Other security solutions can use AMSI-based detections to prevent the attack.
 
Last edited:
Some notes about the risk of using trojanized NPM packages at home.

Trojanized NPM package ---> malicious Node addon loaded ---> malware executed filelessly in the memory of the Node executable

In theory, such addons might be detected by Comodo via signatures or Viruscope. However, I would not place much hope in these protection layers for protection against new threats.

On the other side, such attacks require installing the Node.js runtime, which is probably rare at home (except for software developers or tech hobbyists).
Anyway, there were some in-the-wild examples of using portable/archived versions of Node.js environment. I must research those examples to get some insight.

Update.
The known attacks with portable/archived Node.js runtime were mainly initiated via PowerShell, so they could be auto-contained by CIS.
The attackers would have to use another Trusted script interpreter (unrestricted by Comodo Script Analysis) to bypass CIS. This is improbable, except for a highly targeted attack.
 
Last edited:
Another EDR test:

Almost all included attack vectors can be blocked by CIS.
CIS covers attack vectors via file types used in the test, such as BAT, CHM, CPL, EXE, HTA, MSI, PIF, PS1, SCR, and VBS.
However, some attack vectors, such as 4 (USB-delivered Excel add-in with in-process shellcode injection), can be problematic for CIS.
In the test, we can also see 2 attacks that contain DLL hijacking (35 and 50). Yet, the first uses Rundll32, and the second uses PowerShell - both restricted by Comodo Script Analysis.
The attacks via ISO containers can be mostly autocontained - I assume that the embedded payloads were similar to those enumerated in the test table (Active and Passive Response for Phase 1).
The attacks via shortcuts (LNK files) can be mostly mitigated because, in the wild, they use LOLBins restricted by Comodo Script Analysis (such as CMD, PowerShell, etc.).

As long as the attacker does not know about CIS, the protection can be comparable to top-rated products.
 
Last edited:
Another EDR test:

Almost all included attack vectors can be blocked by CIS.
CIS covers attack vectors via file types used in the test, such as BAT, CHM, CPL, EXE, HTA, MSI, PIF, PS1, SCR, and VBS.
However, some attack vectors, such as 4 (USB-delivered Excel add-in with in-process shellcode injection), can be problematic for CIS.
In the test, we can also see 2 attacks that contain DLL hijacking (35 and 50). Yet, the first uses Rundll32, and the second uses PowerShell - both restricted by Comodo Script Analysis.
The attacks via ISO containers can be mostly autocontained - I assume that the embedded payloads were similar to those enumerated in the test table (Active and Passive Response for Phase 1).
The attacks via shortcuts (LNK files) can be mostly mitigated because, in the wild, they use LOLBins restricted by Comodo Script Analysis (such as CMD, PowerShell, etc.).

As long as the attacker does not know about CIS, the protection can be comparable to top-rated products.
Thank you.
There is no mention of Comodo anywhere in this report. Is it possible that Vendor A, Vendor B, or Vendor C could actually be Comodo or Kaspersky،...?
 
Thank you.
There is no mention of Comodo anywhere in this report. Is it possible that Vendor A, Vendor B, or Vendor C could actually be Comodo or Kaspersky،...?

CIS can auto-contain the attacks missed by A, B, and C. I think that Kaspersky should protect better than A, B, or C.
 
Comodo/Xcitium in all probability was one of the three as meeting the specific inclusion qualifications. If one has no life and does a Deep Dive into the inclusion criteria it would be noted that an important part is the weighted average of Active (important here would be detection via definition) vs Passive detection must exceed a pre-determined percent. In other words, a poor result in Active would bring down the overall percent even if Passive is perfect.

Second, the test results include a score for Operational impact which includes something termed Workflow Delays which would be seen in Sandbox protections as malware can hang around in the Sandbox doing nothing untoward until system reboot of box cleaning. The latter point is also relevant as actual User Action would be somewhat needed- also something that the inclusion criteria loathes.

Finally a Fun Fact- although percentages varied among the 11 products tested, neither they (the 11) nor the 3 excluded products allowed actual system infection.
 
in trecut foloseam si eu Comodo dar, Kaspersky, ce fosesc acum e peste toate solutiile.

In the past I used Comodo but, Kaspersky, what they are now over all the solutions.
 
Last edited by a moderator:
The EDR (EPR) test mentioned in my previous post was conducted in an enterprise-like environment. The attack vectors in Phase 1 were related to Initial Access + Execution + Persistence. In enterprises, the attacks mainly continue with Internal Propagation (Defense Evasion, Lateral Movement, Discovery, etc.) and final breach.

From the viewpoint of the concrete machine, it is compromised if it misses the infection vector ("No active response / prevention" and "No passive response / detection") included in the Phase 1 table. However, in the home environment, the attack chains are much shorter, and malicious actions (like ransomware) are often included in Phase 1. So, at home, a missed Phase 1 attack often also means infection.
 
Last edited:
Community
Security tip
Private browsing has a scope. Incognito helps limit browsing traces stored in that browser session. Websites and network operators may still observe activity, so use it with realistic expectations.
Back
Top