Comodo nails @cruelsister's tests but fails @Andy Ful's ...
However, we both agree that Comodo nails at home, if one can live with @cruelsister's settings.
Comodo nails @cruelsister's tests but fails @Andy Ful's ...
However, the attack presented in the video was easily detected by Microsoft Defender (I did not submit the DLL to analysis).
...
That is why the attackers avoid this method in the wild. They use other attack vectors optimized to bypass popular AVs.
May I say MD behavioral analysis was comparable to that of B?
May I say MD behavioral analysis was comparable to that of B?
But the ultimate result is blocking the attack post-execution by both.Bitdefender Advanced Threat Defense is more aggressive.
It also includes something similar to MD ASR rules.
But the ultimate result is blocking the attack post-execution by both.
Event[0]:
Time Created : 25/02/2026 13:42:48
ProviderName : Microsoft-Windows-Windows Defender
Id : 1121
Message : Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.
For more information please contact your IT administrator.
ID: c0033c00-d16d-4114-a5a0-dc9b3a7d2ceb
ConfigureDefender option: Block use of copied or impersonated system tools
Detection time: 2026-02-25T12:42:48.415Z
User: ahome\andrzej
Path: E:\H_C\DLL\ComodoBypassAAABBB\OPEN_ME.EXE
Process Name: C:\Windows\explorer.exe
Target Commandline:
Parent Commandline: C:\WINDOWS\Explorer.EXE
Involved File:
Inheritance Flags: 0x00000000
Security intelligence Version: 1.445.242.0
Engine Version: 1.1.26010.1
Overall, Comodo is effective for home users, regardless of configuration, except for those involved with cracks, keygens, and mods. I doubt the upcoming version will address any issues related to trusted malware or services; if I recall correctly, Xcitium offers solutions for these through the console or profile.However, we both agree that Comodo nails at home, if one can live with @cruelsister's settings.![]()
One nice false positive block by same ASR rule while installing YandexMicrosoft Defender can block the attack on execution via the ASR rule:
I have used "unblock" and will observe if it will be triggered again after 24 hours, or it just was one time alert during install.Yes, explorer.exe in the temp directory is very suspicious. However, there is a simple solution. Set this ASR rule temporarily to Audit.