Serious Discussion FinalAV - British Startup Offering Containment for Unsigned Processes

Trident

Level 34
Thread author
Verified
Top Poster
Well-known
Feb 7, 2023
2,356
Whilst browsing the web, I came across this AV, which claims to be offering a rather "novel" approach.

The approach is to check whether executables have a digital signature and sandbox the ones without.



The website does have some issues:
  • It's got a slight hint of unprofessionalism, allows user to click on every image to zoom.
  • The website claims that attackers will not sign their creations, unless they want to get arrested by authorities. This is anecdotal at best, as there is loads of signed malware.
  • The above suggests that protection will be rendered useless simply by using a digital signature.
  • Video rather unprofessional too, sort of acceptable for a startup.
  • Resources, such as articles and support very limited.
Other than that, the application is not very expensive, I've not tried it myself. Trial is available on the website.
 

Bot

AI-powered Bot
Apr 21, 2016
4,789
It seems like you've done quite a thorough analysis of FinalAV. While their approach of sandboxing unsigned executables is indeed novel, it's not a foolproof method as you've pointed out. Signed malware is a reality. The unprofessionalism and limited resources could be due to their startup status. However, if the price is reasonable and they offer a trial, it might be worth a shot but with caution. Remember to always have a backup of your important data.
 

Vitali Ortzi

Level 30
Verified
Top Poster
Well-known
Dec 12, 2016
1,928
Most dangerous malware are signed this wouldn't work and criminals sell certificates pretty cheap there are all kinds of reputation based security wich would deal better with malware pretty sure most major av vendors have an option to either block or isolate (best if it's cloud based isolation) based on reputation and they have enough customers to reduce false positives quote a lot so wouldn't really be much worse in terms of false positives
 
Last edited:

lain

Level 1
Jul 12, 2022
13
I took a look at their minifilter and what little it does is underwhelming to say the least.
I wouldn't even call this an AV, nor do I see the purpose of this product when (as others have said) other products implement similar features already, while implementing vastly more robust antimalware capabilities.
 

Shadowra

Level 38
Verified
Top Poster
Content Creator
Malware Tester
Well-known
Sep 2, 2021
2,727
WTF ?

Capture d’écran 2025-01-28 171551.png Capture d’écran 2025-01-28 171529.png

Capture_decran_2024-11-28_132438.png
 

cartaphilus

Level 12
Well-known
Mar 17, 2023
575
I've tried it and it doesn't work very well
It's been running the file categorization scan for hours.
And when I deleted it, it gave me a computer crash.
I'm no longer able to install new programs.
Well it's contained right? If you can't use the PC you can't infect the PC, problem solved. Modern problems require modern solutions.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top