Software Review Comodo's killer.

Reviews reflect the reviewer's setup and methods. Check the evidence and limitations.
Thread details
Content created by
@Andy Ful
We talk about the opposite. Trusted executables can use something unknown to destroy the system and avoid containment.
100% but we are trying to figure out all kinds of different setups , solutions to get that so hard that it will take more then a skid and a malicious dll mod to infect a system yet be enough user friendly (low false positives) for users to use

I think cruel sister settings are not too bad on usability as you can install a fair amount of popular games , popular piracy with not too many false positives although some here and there


Andy solution will be too aggressive and even an admin of the PC might look for a more convenient method to secure his kids PC
 
Even sandbox is bypassable yes but still Xcitium does a pretty good job against unknown zero day malware
The method used to bypass comodo is used by skids to put malware in mods .dll (game exe is trusted)
not even talking about how big of an issue that flaw is to enterprises but even to home users it's awful as it's definitely in the wild and not rare
 
The below list includes three applications currently blocked (but allowed with 1-day time limit and ignored *.tmp files). The executables are parts of applications installed via UniGetUI.

Example of the block for the uninstall.exe included in the Plex installation Folder in Program FIles.
I tried again, and yes, Comodo blocked the unknown files from Program Files.
What is the difference between applying an "Ignore" action to the application and not doing this?

When Comodo Auto-containment is set to "Ignore" a particular application, all its actions are ignored too (including possible exploits, *.tmp files, etc.). This is very usable, but not always safe.
Yes, one should use the "ignore" option for troublesome software or issues.
Not anything, but most of the unknowns.
Which configuration do you propose?
It does not contain/block the unknown DLLs loaded by applications (except for some LOLBins included in the Script Analysis panel).
However, the main problem is with Comodo's alerts. Most children should not be allowed to interact with containment alerts, because they tend to bypass the restrictions.
It is hard to configure CIS/Xcitium to be silent and very strong, without problems with software.
So yes, CIS/Xcitium can be really good for children, but not optimal for parents who must solve problems with silently blocked/contained software.
On our kids' system, I simply use Comodo Firewall proactive security with the containment/firewall set to block unknown programs.

Have you looked into data protection from ransomware with Comodo?
 
Hello everyone! I would like someone who is more expert than me on the subject, to test Comodo firewall by activating “hips” and selecting the option “Do not show popup alerts / Block requests” and in the Sandbox module “Do NOT show privilege escalation alerts / Block” to know if this would increase protection against unknown malware, POC, etc. Thanks and best regards :)
 
@cruelsister has often recommended this combo in the past.
Pretty sure she has defender enabled on her system

Another av she recommended to those looking for an av to combine (those that asked )
Was Kaspersky but anyway she trusts comodo alone and unfortunately looking how easy a dll hijack I personally don't trust it as much
But she's an actual security expert at least judging by her knowledge so I'm not saying she's wrong but really hope she will come back and share some more of her knowledge
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top