Comodo nails @cruelsister's tests but fails @Andy Ful's ...
However, we both agree that Comodo nails at home, if one can live with @cruelsister's settings.
Comodo nails @cruelsister's tests but fails @Andy Ful's ...
However, the attack presented in the video was easily detected by Microsoft Defender (I did not submit the DLL to analysis).
...
That is why the attackers avoid this method in the wild. They use other attack vectors optimized to bypass popular AVs.
May I say MD behavioral analysis was comparable to that of B?
May I say MD behavioral analysis was comparable to that of B?
But the ultimate result is blocking the attack post-execution by both.Bitdefender Advanced Threat Defense is more aggressive.
It also includes something similar to MD ASR rules.
But the ultimate result is blocking the attack post-execution by both.
Event[0]:
Time Created : 25/02/2026 13:42:48
ProviderName : Microsoft-Windows-Windows Defender
Id : 1121
Message : Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.
For more information please contact your IT administrator.
ID: c0033c00-d16d-4114-a5a0-dc9b3a7d2ceb
ConfigureDefender option: Block use of copied or impersonated system tools
Detection time: 2026-02-25T12:42:48.415Z
User: ahome\andrzej
Path: E:\H_C\DLL\ComodoBypassAAABBB\OPEN_ME.EXE
Process Name: C:\Windows\explorer.exe
Target Commandline:
Parent Commandline: C:\WINDOWS\Explorer.EXE
Involved File:
Inheritance Flags: 0x00000000
Security intelligence Version: 1.445.242.0
Engine Version: 1.1.26010.1
Overall, Comodo is effective for home users, regardless of configuration, except for those involved with cracks, keygens, and mods. I doubt the upcoming version will address any issues related to trusted malware or services; if I recall correctly, Xcitium offers solutions for these through the console or profile.However, we both agree that Comodo nails at home, if one can live with @cruelsister's settings.![]()
One nice false positive block by same ASR rule while installing YandexMicrosoft Defender can block the attack on execution via the ASR rule:
I have used "unblock" and will observe if it will be triggered again after 24 hours, or it just was one time alert during install.Yes, explorer.exe in the temp directory is very suspicious. However, there is a simple solution. Set this ASR rule temporarily to Audit.
Introduction
In July 2026, Zscaler ThreatLabz observed new activity by a threat actor with links to East Asia targeting government entities in the Middle East. During analysis, ThreatLabz captured post-compromise activity and uncovered previously undocumented malware tooling, including TELESHIM, MIXEDKEY, and BINDCLOAK. The campaign used a multi-stage attack chain to establish and maintain access on infected systems, with TELESHIM abusing the Telegram API for command-and-control (C2) communication to blend in with legitimate internet traffic...
Does this defense lead us to believe Comodo will protect where others won't or would that be a misrepresentation of Comodo's abilitiesIt is very hard to find an in-the-wild attack that could bypass Comodo. Probably impossible against home users.
However, here is a recent example (targeted attack on government entities) that uses twice the method presented in my video:
Introduction
In July 2026, Zscaler ThreatLabz observed new activity by a threat actor with links to East Asia targeting government entities in the Middle East. During analysis, ThreatLabz captured post-compromise activity and uncovered previously undocumented malware tooling, including TELESHIM, MIXEDKEY, and BINDCLOAK. The campaign used a multi-stage attack chain to establish and maintain access on infected systems, with TELESHIM abusing the Telegram API for command-and-control (C2) communication to blend in with legitimate internet traffic...
- Khushal
- Replies: 1
- Forum: Security News
View attachment 298951
The EXE files are benign/legitimate, so most AVs can also fail to detect the attack (as 0-day).
One of the used DLLs is still undetected by such strong AVs as Bitdefender, CrowdStrike Falcon, Elastic, GData, Eset, Emsisoft, Palo Alto Networks, TrendMicro, Xcitium, ZoneAlarm.
From VirusTotal, it follows that Xcitium did not detect any of the DLLs noted in the article, but it has an option to block unrecognized DLLs, which can block such attacks anyway.
If the attack accidentally happened at home, it could be blocked by SAC (DLLs are unsigned).
Does this defense lead us to believe Comodo will protect where others won't or would that be a misrepresentation of Comodo's abilities