Cylance Smart Antivirus

  • Thread starter Deleted Member 3a5v73x
  • Start date
Status
Not open for further replies.
F

ForgottenSeer 58943

Thread author
"(I could test only seven because of the restart)"

Wait, so static scan detects 7/19, which leaves 12 files left. And out of those 12 files you were only able to to test 7 further. So there are 5 more files that could have potentially been detected, but are still being counted as misses in your results?

Am I reading this wrong?

Console results are 10/14 before system dropped. Looks like Askalan updated the results to reflect this.

public.png.exe
QUARANTINED 8/13/2018
C:\Users\Alan\Desktop\19\public.png.exe
docer.exe
QUARANTINED 8/13/2018
C:\Users\Alan\Desktop\19\docer.exe
C:\Users\Alan\AppData\Local\TempaKU65.exe
haa.exe
QUARANTINED 8/13/2018
C:\Users\Alan\Desktop\19\haa.exe
Bunker_Invoices_130818.exe
QUARANTINED 8/13/2018
C:\Users\Alan\Desktop\19\Bunker_Invoices_130818.exe
more.exe
QUARANTINED 8/13/2018
C:\Users\Alan\Desktop\19\more.exe
ProformaInvoice.exe
QUARANTINED 8/13/2018
C:\Users\Alan\Desktop\19\ProformaInvoice.exe
ppx.exe
QUARANTINED 8/13/2018
C:\Users\Alan\Desktop\19\ppx.exe
nvjfh.exe
QUARANTINED 8/13/2018
C:\Users\Alan\nvjfh.exe
chondrites.dll
QUARANTINED 8/13/2018
C:\Users\Alan\AppData\Local\Temp\chondrites.dll
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
I'd remind people - some of SHP's stronger assets aren't utilized in the test. I suspect it likely SHP would snag that with their web filtration, heuristic traffic evaluation and new file reputation on download. (My favorite protection category)
if you consider everything is downloaded to the computer and SHP can block them
there is a free alternative = windows smartscreen, which works almost the same as SHP's download reputation checker

https://malwaretips.com/threads/13-08-2018-19.85938/#post-756929

I think you forgot smartscreen. Many people have this tool enabled by default in windows 8 and 10
 
D

Deleted Member 3a5v73x

Thread author
This missed .exe is also interesting. I wonder what's going on with Cylance. :whistle:

cyl2.jpg

cyl1.PNG
 
F

ForgottenSeer 69673

Thread author
I might be wrong but Most AV's don't detect malware in archives. A Jar file is just a Java archive. Can an archive if even a Java one cause an infection? I remember Kevin from Bo-Clean says it would not do anything until the archive was unpacked. But like I said, I could be wrong about Java archives.
 
F

ForgottenSeer 69673

Thread author
I am a bit disappointed in the testmy av samples lately. I don't have access to MT's hub. All the latest sample I got from testmyav are deleted by windows defender.
 
  • Like
Reactions: oldschool

DeepWeb

Level 25
Verified
Top Poster
Well-known
Jul 1, 2017
1,396
Maybe we can finally stop pretending that enterprise security solutions are superior to home solutions. Home AVs are superior because they have to designed for a far more diverse environments than just a boring office space. Lesson as usual: Stick to AV vendors with a high reputation.
 
5

509322

Thread author
Maybe we can finally stop pretending that enterprise security solutions are superior to home solutions. Home AVs are superior because they have to designed for a far more diverse environments than just a boring office space. Lesson as usual: Stick to AV vendors with a high reputation.

Enterprise solutions are built more "robust" (more features) and configurable because the risks and threats are much greater than in a home-use environment. The corporate space is anything but boring. They tend to be the most dynamic. If anything would be on the boring side, almost static, it would be a home environment.

Protection and reputation are not linear. Although there is a weak correlation. Product type is a much stronger determinant of protection than reputation.
 
Last edited by a moderator:
F

ForgottenSeer 58943

Thread author
Maybe we can finally stop pretending that enterprise security solutions are superior to home solutions. Home AVs are superior because they have to designed for a far more diverse environments than just a boring office space. Lesson as usual: Stick to AV vendors with a high reputation.

Enterprise solutions are most assuredly better than consumer offerings. Worry Free Advanced is VASTLY superior to Trend Micro Maximum Security in a huge number of ways. Not to mention WFA has a granular firewall control system and IPS, along with much deeper threat detection module configurations.

A few reasons why enterprise solutions are superior;

1) Granularity. Configuration is usually very deep. This configuration allows much higher levels of security in many cases. Home versions are usually 'default', which is the weakest configuration of the enterprise offerings. -Umbra points this out and it's important.
2) Control. Enterprise solutions generally have more control over endpoints. The ability to lock down specific, higher risk aspects isn't unusual in the enterprise offerings but almost always absent from the consumer ones.
3) Threat Detection. As Lockdown notes, the enterprise environment has a much higher threat surface than consumers. You have WAN facing servers, on-prem exchange, SAS/SAN devices, IP Phones (Shortel, Digium, etc). As Lockdown says, the enterprise market is dynamic and intense, while the home market is largely stagnant.
4) Single Pane of Glass management. 'Awareness' of what is transpiring is important. Enterprise offerings usually have a lot of ways to get notifications of problems out to the right people. You'll know instantly when an installed AV quits working or an infection is present in the enterprise realms. Consumer stuff is often operating blind and default.
5) Consumer offerings are almost always the easiest to hijack and most exploits are designed to bypass them. Enterprise grade offerings generally are more hardened, use encrypted communications and update channels and higher grade self protection than consumer junk.
6) Privacy. Generally speaking, privacy is much higher with enterprise stuff. Some of that stuff is designed to be used in facilities where privacy is crucial. As such, logging is almost always off or restricted unless a support enables debugging. Telemetry is bare minimum, and also over encrypted channels.

Protection and reputation are not linear. Although there is a weak correlation. Product type is a much stronger determinant of protection than reputation.

Absolutely. Reputation and Brand doesn't mean as much as the product TYPE. For example Norton itself is pretty bad IMO. But their SEP offerings when properly configured are quite robust. That SEP firewall alone can be tweaked to block virtually every threat imaginable, even to the point of only allowing through actual ports your businesses need. Trend WF Advanced can be tweaked to high heaven and includes vastly more robust anti-ransomware and machine learning. Not to mention additional protections for deeper business environments.


As a general rule, it's safe to assume any enterprise offering is going to vastly outstrip any consumer offering.
 
Last edited by a moderator:
F

ForgottenSeer 58943

Thread author
I logged into one of my Trend Micro Worry Free Advanced portals. Let's take a look at the BB section alone. Then please, tell me Trend Micro for consumers is going to offer even a fragment of the protection this offers. :eek:

wfa2.png
 

simmerskool

Level 31
Verified
Top Poster
Well-known
Apr 16, 2017
2,094
So I have counted like 4-5 regular users of Cylance commenting, anyone else? Maybe someone out of 800+ MT guests? Don't be shy and chime in, share your experience with Cylance or if you use Cylance Smart Antivirus. All feedback is appreciated, either good or bad. (y)

Well I've been using CylanceProtect via cyberforce for 8+ months, and very light and no issues. I had used CylanceProtect for a few months via malwaremanged on an older pc, and that was not a good fit. I just put Cylance Smart on another pc but it is mostly used by my wife in another location. At first glance after that install did not notice many or any differences between Protect and Smart, but then I've hardly played with Smart. CylanceProtect on my primary box is also behind a pretty secure cisco router with advanced threat protection and voodooshield (home office). It's probably not as light as ForgottenSeer 58943's referenced light combo above, but I do not see any slowdowns. CylanceProtect caught a trojan the other day! must have come in via vpn?? First detection in 8+ months. I have not found a reason (yet) to switch. Prior was using KIS 2017, liked that too, but liking Cylance more, but that's me. I tried DeepArmor and very slow but that was several months ago, not sure what they're doing...

EDIT fwiw appguard is running too. they seem to play well together little or no noticeable slowdown
 
Last edited:
F

ForgottenSeer 58943

Thread author
CylanceProtect on my primary box is also behind a pretty secure cisco router with advanced threat protection and voodooshield (home office). It's probably not as light as ForgottenSeer 58943's referenced light combo above, but I do not see any slowdowns. CylanceProtect caught a trojan the other day! must have come in via vpn?? First detection in 8+ months. I have not found a reason (yet) to switch. Prior was using KIS 2017, liked that too, but liking Cylance more, but that's me. I tried DeepArmor and very slow but that was several months ago, not sure what they're doing...

Tossing Cylance behind an ASA is pretty much what I was saying. I have a few combos of Cylance I really like ranging from lightest and least protective to light and maximum protective.

Config 1 - Cylance+Windows Defender Browser Extension+Syshardener
Config 2 - Cylance+OSArmor+Syshardener+Windows Defender Browser Extension
Config 3 - Cylance+Heimdal+OSArmor+Syshardener+Windows Defender Browser Extension

My personal favorite;
Config 4 - Gryphon UTM+Heimdal+OSArmor+Syshardener+Quad9 DNS on Router (layer after mighty layer)

But I know Cylance is designed to be behind a UTM/NGFW and with other protects in place with DNS, GP's, etc. So I wouldn't even consider running Cylance naked as I have stated because I do not believe it's designed to run naked. But Cylance has proved to be quite protective in enterprise settings from what I have seen, but that's partly attributed to the adjunct technologies in place. (I know I am repeating myself)

For example not a single thing in that last pack would make it through most enterprise setups. The likely attack vector would be email, and a qualified, properly configured antispam/email solution would nail them at the outset. (Trend HES comes to mind) Hence, Cylance is sufficiently good for what it deals with in enterprise. Consumers rarely have outlook installed locally and pinned to an opened up exchange server, so you know, that vector doesn't even exist with Web Mail services who already have robust scanning. Consumers, if they use outlook, have IMAP to their Gmail or something, and already have robust email protection in most cases.

So we need to be aware of vectors, and in most cases for consumers, vectors that don't even - and will never exist.
 
Last edited by a moderator:
D

Deleted Member 3a5v73x

Thread author
Cylance support are now aware of it and Threat Guidance team is analysing why it wasn't detected.
While they are still analysing it, added Heimdal RC to Cylance, and Heimdal nicely intercepts connections to those domains
heimdal.gif


37.1.218.68:80 (smart.cloudnetwork.kz) POST /t
195.22.26.248:80 (static.apiinformationsec.com) POST /t
212.227.20.93:80 (mel.cloudcontentsmak.com) POST /t
195.22.26.248:80 (nicru.supermicrotransapi.ru) POST /t
so Heimdal would also be a quite nice addition for CSAV tests in the MH.
 
Last edited by a moderator:
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top