- Sep 2, 2021
- 2,773
Welcome to this comparison!
Today we're going to compare 4 enterprise versions of antivirus software: Sophos InterceptX, Checkpoint Harmony, ESET Protect + EDR and Bitdefender GravityZone with HyperDetect.
A few details:
- All the antivirus products have been configured to the maximum for this test, and the default test was carried out 1 month ago.
- I add the EDRs offered by the suppliers if they offer them (this is the case with Sophos, ESET and Bitdefender).
- I don't own the licences, I don't show the whole panel and I hide the owner.
- Many thanks to @kamiloxf for the licences
Today we're going to compare 4 enterprise versions of antivirus software: Sophos InterceptX, Checkpoint Harmony, ESET Protect + EDR and Bitdefender GravityZone with HyperDetect.
A few details:
- All the antivirus products have been configured to the maximum for this test, and the default test was carried out 1 month ago.
- I add the EDRs offered by the suppliers if they offer them (this is the case with Sophos, ESET and Bitdefender).
- I don't own the licences, I don't show the whole panel and I hide the owner.
- Many thanks to @kamiloxf for the licences
Sophos offers a very simple agent and a fairly simple yet comprehensive panel.
The software is easy to set up, so I set it to maximum.
On the Web, Sophos leaves 1 malware which is ConnectWise.
Nothing to say about the fake crack.
Malware Pack: remains 58 out of 122.
Sophos's behavioural protection is very average...
It will try to defend itself as best it can (it managed to block a few attacks) but during the test, not everything went as I expected.
During execution, ConnectWise activated and gave me a magnificent block (often used by "Microsoft Tech Support" crooks) and I had to restart the machine by force.
When I continued, the situation got worse... Sophos left a BATCH script that installed a Ransomware without reacting.
I have to stop the test.
The software is easy to set up, so I set it to maximum.
On the Web, Sophos leaves 1 malware which is ConnectWise.
Nothing to say about the fake crack.
Malware Pack: remains 58 out of 122.
Sophos's behavioural protection is very average...
It will try to defend itself as best it can (it managed to block a few attacks) but during the test, not everything went as I expected.
During execution, ConnectWise activated and gave me a magnificent block (often used by "Microsoft Tech Support" crooks) and I had to restart the machine by force.
When I continued, the situation got worse... Sophos left a BATCH script that installed a Ransomware without reacting.
I have to stop the test.
CheckPoint is evolving and offering a new interface that's more polished and elegant for my taste! It's still in BETA, but I'm activating it to check it out.
On the Web, CheckPoint lets through a malicious Google Chrome download, although the dropper is detected afterwards.
There's nothing to say about the fake crack detected either.
Malware Pack: Remains 26 out of 122
CheckPoint proves its performance by blocking all the traps I set for it.
The HTA file is blocked, so it cannot connect.
1 file remains in memory, detected by no antivirus.
Just 1 trace of infection is present at the end of the test.
On the Web, CheckPoint lets through a malicious Google Chrome download, although the dropper is detected afterwards.
There's nothing to say about the fake crack detected either.
Malware Pack: Remains 26 out of 122
CheckPoint proves its performance by blocking all the traps I set for it.
The HTA file is blocked, so it cannot connect.
1 file remains in memory, detected by no antivirus.
Just 1 trace of infection is present at the end of the test.
ESET offers an enterprise version based on Smart Security Premium. I'm integrating its EDR for the test.
Surprisingly for ESET, everything is configured on the agent! Few settings are available on the panel... It's a debatable choice, but let's move on.
On the Web, ESET blocks all links by blocking them at source.
On the fake crack, nothing to say, ESET blocks executions.
Malware Pack: remains 34 out of 122.
ESET has held on to executions, and is starting to react well to scripts.
When GuLoader tries to install itself, ESET prevents it from connecting, a good point!
On the other hand, the same script that killed Sophos passes through without reacting and installs the Ransomware... ESET is unable to stop it, nor to remedy this with its EDR.
Quite disappointing.
Surprisingly for ESET, everything is configured on the agent! Few settings are available on the panel... It's a debatable choice, but let's move on.
On the Web, ESET blocks all links by blocking them at source.
On the fake crack, nothing to say, ESET blocks executions.
Malware Pack: remains 34 out of 122.
ESET has held on to executions, and is starting to react well to scripts.
When GuLoader tries to install itself, ESET prevents it from connecting, a good point!
On the other hand, the same script that killed Sophos passes through without reacting and installs the Ransomware... ESET is unable to stop it, nor to remedy this with its EDR.
Quite disappointing.
Bitdefender has updated its GravityZone version and FINALLY has an excellent panel, which is very comprehensive, if not too comprehensive!
You can now configure everything: Engine aggressiveness, IDS aggressiveness, HyperDetect aggressiveness etc.
I also activated the Bitdefender Sandbox for the test.
On the Web, everything is blocked except Google Chrome, which installs itself.
On the fake crack: Bitdefender blocks all launches.
Malware Pack: remains 36 out of 122.
After an analysis that lasted over 1 hour, I can finally run the threats.
And I have to say I'm very surprised: Bitdefender makes a totally clean machine! No malware got through!
This is down to its proactive protection and HyperDetect, which correctly blocked the threats.
The detection of NPE is a false positive, it's the blocking of Microsoft telemetry.
I was very surprised!
You can now configure everything: Engine aggressiveness, IDS aggressiveness, HyperDetect aggressiveness etc.
I also activated the Bitdefender Sandbox for the test.
On the Web, everything is blocked except Google Chrome, which installs itself.
On the fake crack: Bitdefender blocks all launches.
Malware Pack: remains 36 out of 122.
After an analysis that lasted over 1 hour, I can finally run the threats.
And I have to say I'm very surprised: Bitdefender makes a totally clean machine! No malware got through!
This is down to its proactive protection and HyperDetect, which correctly blocked the threats.
The detection of NPE is a false positive, it's the blocking of Microsoft telemetry.
I was very surprised!