App Review Comodo's killer.

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
@Andy Ful
Unknown executables might use something that is trusted to destroy the system but even that will get contained

We talk about the opposite. Trusted executables can use something unknown to destroy the system and avoid containment.
 
Well every AV is bypassable just so you know

Yes, that is true. However, in this thread, we would like to present the setup which is significantly better than most AVs and better than standard CIS/Xcitium settings.:)
 
No AV is perfect and it will never be but AVs are Good and i choosed Xcitium to protect my pc from zero-day malware i also know sources of where to get samples from
I Submit samples on a daily basis to Xcitium
It is a good choice.(y)
 
We talk about the opposite. Trusted executables can use something unknown to destroy the system and avoid containment.
100% but we are trying to figure out all kinds of different setups , solutions to get that so hard that it will take more then a skid and a malicious dll mod to infect a system yet be enough user friendly (low false positives) for users to use

I think cruel sister settings are not too bad on usability as you can install a fair amount of popular games , popular piracy with not too many false positives although some here and there


Andy solution will be too aggressive and even an admin of the PC might look for a more convenient method to secure his kids PC
 
The Comodo team was unable to fix the sandbox, the POC was able to bypass the CIS.
What they did was a workaround.

Which POC was able to bypass the newest version of CIS due to the sandbox bypass?
 
Last edited:
Even sandbox is bypassable yes but still Xcitium does a pretty good job against unknown zero day malware
The method used to bypass comodo is used by skids to put malware in mods .dll (game exe is trusted)
not even talking about how big of an issue that flaw is to enterprises but even to home users it's awful as it's definitely in the wild and not rare
 
The below list includes three applications currently blocked (but allowed with 1-day time limit and ignored *.tmp files). The executables are parts of applications installed via UniGetUI.

Example of the block for the uninstall.exe included in the Plex installation Folder in Program FIles.
I tried again, and yes, Comodo blocked the unknown files from Program Files.
What is the difference between applying an "Ignore" action to the application and not doing this?

When Comodo Auto-containment is set to "Ignore" a particular application, all its actions are ignored too (including possible exploits, *.tmp files, etc.). This is very usable, but not always safe.
Yes, one should use the "ignore" option for troublesome software or issues.
Not anything, but most of the unknowns.
Which configuration do you propose?
It does not contain/block the unknown DLLs loaded by applications (except for some LOLBins included in the Script Analysis panel).
However, the main problem is with Comodo's alerts. Most children should not be allowed to interact with containment alerts, because they tend to bypass the restrictions.
It is hard to configure CIS/Xcitium to be silent and very strong, without problems with software.
So yes, CIS/Xcitium can be really good for children, but not optimal for parents who must solve problems with silently blocked/contained software.
On our kids' system, I simply use Comodo Firewall proactive security with the containment/firewall set to block unknown programs.

Have you looked into data protection from ransomware with Comodo?
 
defender is a good combination to comodo and since comodo itself can block majority of malware (those not launched by a trusted process ) it should boost the security of the system a lot
@cruelsister has often recommended this combo in the past.
 
Hello everyone! I would like someone who is more expert than me on the subject, to test Comodo firewall by activating “hips” and selecting the option “Do not show popup alerts / Block requests” and in the Sandbox module “Do NOT show privilege escalation alerts / Block” to know if this would increase protection against unknown malware, POC, etc. Thanks and best regards :)
 
@cruelsister has often recommended this combo in the past.
Pretty sure she has defender enabled on her system

Another av she recommended to those looking for an av to combine (those that asked )
Was Kaspersky but anyway she trusts comodo alone and unfortunately looking how easy a dll hijack I personally don't trust it as much
But she's an actual security expert at least judging by her knowledge so I'm not saying she's wrong but really hope she will come back and share some more of her knowledge