App Review Comodo's killer.

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
@Andy Ful

Nikola Milanovic

Level 4
Verified
Oct 17, 2023
178
Not anything, but most of the unknowns.
Which configuration do you propose?
CIS/Xcitium does not contain the unknown DLLs loaded by applications (except for some LOLBins included in the Script Analysis panel).
However, the main problem is with Comodo's alerts. Most children should not be allowed to interact with containment alerts, because they tend to bypass the restrictions.
It is hard to configure CIS/Xcitium to be silent and very strong, without problems with software.
So yes, CIS/Xcitium can be really good for children, but not optimal for parents who must solve problems with silently blocked/contained software.

Post edited.
When a file is sandboxed i submit it to Xcitium for analysis and i get a verdict in less then 1 hour
 

Vitali Ortzi

Level 29
Verified
Top Poster
Well-known
Dec 12, 2016
1,810
When a file is sandboxed i submit it to Xcitium for analysis and i get a verdict in less then 1 hour
But if a malicious dll like starrailbase ?
Isn't blocked by virus scope and is launched as trusted that means you're infected and it's popular for gaming mods , piracy sites to have dll in archives that are malicious or that a user will be suggested to put inside the game directory and the game exe is marked as trusted (even pirated software exes that are safe are marked as trusted)


Basically there is a flaw in comodo and no current solution that doesn't increase false positives ratio
Not sure what config you're using but I'm very confident the same vulnerability will work on your machine unless you used something more aggressive then proactive
 
  • Like
Reactions: simmerskool

Vitali Ortzi

Level 29
Verified
Top Poster
Well-known
Dec 12, 2016
1,810
We talk about the opposite. Trusted executables can use something unknown to destroy the system and avoid containment.
100% but we are trying to figure out all kinds of different setups , solutions to get that so hard that it will take more then a skid and a malicious dll mod to infect a system yet be enough user friendly (low false positives) for users to use

I think cruel sister settings are not too bad on usability as you can install a fair amount of popular games , popular piracy with not too many false positives although some here and there


Andy solution will be too aggressive and even an admin of the PC might look for a more convenient method to secure his kids PC
 

Vitali Ortzi

Level 29
Verified
Top Poster
Well-known
Dec 12, 2016
1,810
Even sandbox is bypassable yes but still Xcitium does a pretty good job against unknown zero day malware
The method used to bypass comodo is used by skids to put malware in mods .dll (game exe is trusted)
not even talking about how big of an issue that flaw is to enterprises but even to home users it's awful as it's definitely in the wild and not rare
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top