The Advanced Threat Protection tests included in my previous post were slightly outdated.
So, I inspected the attack vectors included in newer tests (do not include CIS/CCS/Xcitium).
www.av-test.org
www.av-test.org
www.av-test.org
www.av-test.org
www.av-test.org
www.av-test.org
www.av-test.org
The newer tests include some of the methods that might bypass CIS (such as DLL hijacking). However, the required methods are applied at the later infection stages, when the attack is already contained. For example (the red part of the attack can be auto-contained):
Email with attachment ---> EXE or script file in the archive ----> EXE or script file unpacked/executed ----> ... ----> DLL hijacking
It is rather clear that the used attack vectors are prepared to bypass NextGen solutions and do not bother to bypass Comodo.
So, I inspected the attack vectors included in newer tests (do not include CIS/CCS/Xcitium).
ATP Test: How easily Windows can be tricked by malware
Many users have known for a long time that they always need to keep their Windows up to date so that cyberattackers will have as few opportunities as possible to launch an assault. But Windows itself has a number of vulnerabilities that only security software can mitigate. Interesting fact...
ATP test: defending against attacks by ransomware and info stealers
They are the leading vectors for attacks: ransomware and info stealers. If attacks are successful, what follows is extortion for ransom, the data ends up for sale on the Internet, or both. None of this happens if good protection software thwarts the attacks immediately. But is the software...
ATP test: Keeping data thieves and encryptors at bay
Attackers are constantly developing new tools and tactics in order to launch attacks on Windows systems. The actual attack generally takes place through ransomware or an infostealer. In our latest Advanced Threat Protection test – or ATP test, for short – the AV-TEST team checked whether...
Cybersecurity: Defense Against the Latest Attacking Techniques in the ATP Test
In an ongoing race against cybercriminals, security vendors need to constantly maintain the upper hand in order to sustainably guarantee the security of data for both consumer users and corporate users. The Advanced Threat Protection test from AV-TEST relies on detailed individual tests to...
ATP: live test against data theft and encryption malware
For consumer users, all their vacation photos and other memories are often lost – for corporate users, the entire future of the company may be at stake. When info stealers or ransomware attackers strike, data ends up in the hands of strangers or is professionally encrypted to a large degree...
Prevention against ransomware and info stealers: 20 security solutions in the ATP test
Take a look at any study on the subject of malware: ransomware and info stealers have consistently been on the front line of cybersecurity threats for years now. Good protection software detects attackers before they wreak devastation. But what happens if the attackers are not readily detected...
ATP TEST: 26 security packages fend off ransomware and info stealers
In 2024, there was a steady flow of IT security news reporting on how ransomware and info stealers attacked PCs and servers, and encrypted or extracted data. No matter how they ensued, they always ended up with a ransom demand. But could the attacks have been prevented? Can security software...
The newer tests include some of the methods that might bypass CIS (such as DLL hijacking). However, the required methods are applied at the later infection stages, when the attack is already contained. For example (the red part of the attack can be auto-contained):
Email with attachment ---> EXE or script file in the archive ----> EXE or script file unpacked/executed ----> ... ----> DLL hijacking
It is rather clear that the used attack vectors are prepared to bypass NextGen solutions and do not bother to bypass Comodo.