Guys, just pay attention to the release notes the developer posted on the forum. He made it clear that the only changes are: swapping the word "HIPS" for "EDR," and changing the product name and version to CIS 2027 vxxx.xx.xx.xx.xx. Nothing else was modified beyond those two aspects.
In other words, all the 50+ bugs the community has been reporting for (at least) five years remain unresolved. All published CVEs remain unaddressed. The flaw allowing the auto-containment feature to be bypassed is still there, etc.
I’m going to test this "new" CIS live on my channel. Probably tonight at 10:30 PM (Brazil time). I plan to run two tests:
1) Discuss the so-called "new features" of this edition, perform the installation, check for any different options or changes in CIS, and test this new version against that old PoC that bypasses auto-containment and executes ransomware;
2) Download a bunch of zero-day malware samples, test the CIS antivirus module (just the AV—no auto-containment or firewall) against them, and then rerun the same test with the same malware, but this time using the firewall and auto-containment, without the AV module.
Before anyone starts hassling me: the PoC test will be done in two ways. First, I'll leave CIS at default settings (it should flag the PoC as malware). Then, I'll disable all CIS modules except auto-containment to see if the PoC executes or gets automatically isolated, prompting the user to decide whether to allow execution.
