App Review Crowdstrike Falcon Review | Tested vs Malware

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Wraith

Level 13
Verified
Top Poster
Well-known
Aug 15, 2018
634
Everyone knows about your longstanding vendetta against Dan. So let's get that out there for posterity so people know there is a history and we can move on to more important matters.

Get Cylance or Crowdstrike+VS (Always On, Aggressive) over to the malware hub in appropriately allocated VM's, throw everything at it, including non-traditional attacks and lets see the test results. I think it would be interesting.

Back on topic, I think CS is an interesting offering, but probably needs some ancillary assistance.
Cylance + VS won't be much of a test since VS will block all the files from running. It's like testing an AV alongwith AppGuard. :geek: I think a more suitable test will be WD + Cylance to see what benefits these claimed "next-gen" AV's can offer compared to the traditional ones.
 

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
7,613
Get Cylance or Crowdstrike+VS (Always On, Aggressive) over to the malware hub in appropriately allocated VM's, throw everything at it, including non-traditional attacks and lets see the test results. I think it would be interesting.

I've been wishing for just this for quite awhile now, but realize that Hub testers have their priorities. Maybe at some point this wish will be realized ... :whistle::whistle::whistle: (y)
 

Wraith

Level 13
Verified
Top Poster
Well-known
Aug 15, 2018
634
I've been wishing for just this for quite awhile now, but realize that Hub testers have their priorities. Maybe at some point this wish will be realized ... :whistle::whistle::whistle: (y)
Testing Cylance is okay but I'm not so sure about VS. by default VS will block all the samples from being executed since it allows only whitelisted items to be run from user space. It'll be like testing AppGuard that will block all non whitelisted items execution from user space and hence no malware can run. :geek:
 

artek

Level 5
Verified
May 23, 2014
236
Testing Cylance is okay but I'm not so sure about VS. by default VS will block all the samples from being executed since it allows only whitelisted items to be run from user space. It'll be like testing AppGuard that will block all non whitelisted items execution from user space and hence no malware can run. :geek:

Which is the paradoxical thing to me about most hips programs being advocated for general use by consumers. Most of them are getting infected by files they're choosing to run. And when you're not a novice user you're not going to run those files anyway so what's the point?
 

oldschool

Level 85
Verified
Top Poster
Well-known
Mar 29, 2018
7,613
Testing Cylance is okay but I'm not so sure about VS. by default VS will block all the samples from being executed since it allows only whitelisted items to be run from user space. It'll be like testing AppGuard that will block all non whitelisted items execution from user space and hence no malware can run. :geek:

Yes, but I'd add these two points: VS in Autopilot is the recommended mode for testing because it performs most like an AV. And we might recall that Hard_Configurator was tested by @askalan. I appreciated those even if they got a little boring. Where has he been anyway?
 

Wraith

Level 13
Verified
Top Poster
Well-known
Aug 15, 2018
634
Yes, but I'd add these two points: VS in Autopilot is the recommended mode for testing because it performs most like an AV. And we might recall that Hard_Configurator was tested by @askalan. I appreciated those even if they got a little boring. Where has he been anyway?
Generally combos are not allowed to be tested in the hub(except SysHardener) since they skew the effectiveness of the suite/AV. In the next malware samples test, I'll make a ESET + VS test for you and PM you the screenshots. :emoji_beer: Sadly I don't have a Cylance license and so can't test it.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top