Cylance Commissioned Test with AV-Test

What do you think of this test?


  • Total voters
    30
W

Wave

Thread author
The other concern I have is regarding False Positive detection's; there are so many pieces of GENUINE software which rely on device drivers to function properly... One would be other Anti-Malware products, another would be simple development tools like DebugView (for kernel-mode output), ... How would CylancePROTECT react to CreateServiceA and StartServiceA to load a device driver? You can't just flag every program which uses those APIs, you should alert the user to decide if it should be allowed/not or perform a scan of the device driver being loaded.

In that scenario, if they don't flag and block that, then the device driver will be loaded... Guess what? Call PsLookupProcessByProcessId and then ObOpenObjectByPointer and then call NtTerminateProcess -> bye bye CylancePROTECT. If they hook them on x86, then unhook them.

Unless they bypass PatchGuard (which would be unethical and highly unstable because MS will patch it through an update, they don't like kernel-mode patching) on x64 or block all device drivers from being loaded, then there's nothing they can do IMO.

Plus attacks to patch Windows device drivers, if they aren't prevented then that can be used to bypass the product too!

.... Or let's say they have a great white-listing system, ok great! Sounds amazing right? Now find a trusted piece of software which uses device drivers -> hack the network to replace the device driver files and publish your own malicious update from the companies own server -> now the software on the target machine which is white-listed by CylancePROTECT is updated and now your own malicious code is being executed from a trusted program, on god knows how many systems. ;)


There are limitless things which can be done to try and bypass the product and eventually one of them will work.
---------------------------------------------------------------

The other concern I have is their shitty advertising, check this from the official website (front-page):
Boost the efficiency of IT resources and reduce user impact throughout your organization with endpoint security products that use very little memory, less than 1% of CPU and require no Internet connection or signature updates.

Urm ok kiddo... Less than 1% CPU? Haha. I am sure it uses more than 1% CPU and it will also use additional memory... Why? Because the CPU will be performing more CPU instructions for the logging (e.g. if it injects into processes then when the hooked APIs are called, more CPU is used to execute their own instructions before the action is completed for the actual program calling the API originally, plus more RAM into the other running programs to store the logging code). Or, if they work with device drivers for real virtualization like the hyper-visor, then that's still more RAM/CPU.

There's more to system resource usage than a damn GUI.
 

XhenEd

Level 28
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Mar 1, 2014
1,708
An Avast dev speaks up:
"I can't believe how incredibly flawed this test from AV-TEST is. I mean, I would have never believed that the guys over at AV-TEST would go this far and undersign something that is so obviously WRONG. They just did something terrible for their reputation if you ask me."
- vlk, AV-TEST Advanced Threat Prevention Test Results
 
W

Wave

Thread author
Hahahahaha

I wish CylancePROTECT would give me a one week demo so I can bypass it LOL, I recon it'd take me a day to destroy the MBR or shut the protection down hahaha

In fact I love Cylance now because it makes me laugh to much :D
 

vemn

Level 6
Verified
Malware Hunter
Well-known
Feb 11, 2017
264
Hahahahaha

I wish CylancePROTECT would give me a one week demo so I can bypass it LOL, I recon it'd take me a day to destroy the MBR or shut the protection down hahaha

In fact I love Cylance now because it makes me laugh to much :D
I saw before a very simple demo of repacking a calculator app to a cab file and Cylance rated it as malicious...
 

sudo -i

Level 4
Verified
Jan 17, 2017
154
Did that video even get made?
Was the demo product even licensed to cruelsister? I vaguely remember discussion about the "demo product" settings being altered to begin with, so it was dismissed entirely. Might be wrong about that last part.

Which honestly makes this whole ordeal all the more believable. They're known for altering settings, even when offering it to people to "test".
 
W

Wave

Thread author
Was the demo product even licensed to cruelsister? I vaguely remember discussion about the "demo product" settings being altered to begin with, so it was dismissed entirely. Might be wrong about that last part.

Which honestly makes this whole ordeal all the more believable. They're known for altering settings, even when offering it to people to "test".
I am not sure :/
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,344
Did that video even get made?
No. She had to check if Cylance and her company had any relationship or possibility that they might have in the future first. I didn't see anything after that. Later Malware managed gave the option for anyone to do it as long as he/she is qualified to do a video test.
 
5

509322

Thread author
I'm looking for the 50 subscribers who got a discount for Cylance PROTECT: Hot Deals & Discounts - Malware Managed Cylance PROTECT - 20% OFF Discount

I hope one of them, at least, come here and share his/her experiences.

The posted test videos here and elsewhere are pretty representative of what you can realistically expect. From what I have observed, it isn't the miracle security soft that interested parties work extremely hard to make it out to be. It's certainly capable - doing well against most, but not all malwares. From what I see, it ain't SkyNet as some would have you believe.

Anyway, there is no substitute to testing it against malwares on your own system.

Check out current and past employee reviews of Cylance on sites like Glassdoor. You can pick-up useful tidbits of infos and string them together. Just be aware that it is probable that there are fake, glowing reviews on Glassdoor. I think it would be a safe bet. :D

Don't go by online Admin user reviews; their statements are based upon day-to-day usage instead of actual malware testing.

Let me put it this way: 1 + 1 ≠ 2
 
Last edited by a moderator:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top