New Update Introducing Comodo Internet Security 2027 V12.4.0.8170

Hey everyone, I hosted a nearly 4-hour livestream to showcase the new version of CIS, find out if anything changed beyond the name and terms like HIPS and EDR, and put CIS to the test against 299 malware samples—ranging from zero-days to "one-day" exploits.

Here are the tests and results:

1) CIS updates + CIS 2027 vs. the old exploit: CIS had been updated and protected against the PoC, even with all its modules disabled except for Auto-Containment (I mean *all* of them, even script analysis);

2) CIS 2027 vs. 299 malware samples (without Auto-Containment or Cloud Analysis): Its AV identified just over 100 samples, while the rest fluctuated between execution and offline identification;

3) CIS 2027 vs. the same 299 malware samples (without the antivirus module, but with Auto-Containment + Firewall + WebLookUp): 298 samples were isolated by Auto-Containment and 1 executed; however, when I uploaded that file to VirusTotal, no engines detected a threat. I ran some checks, and it appears the file is either legitimate, an incomplete malware sample (the type that needs to download a payload but fails to complete that step, even without CIS), or simply a corrupted/incomplete file.

Now, I'm just waiting to see if Loyiza will be kind enough to send me her new PoC/exploit so I can test it in a future livestream against the new CIS 2027 :D

Livestream link: (In pt-BR only. I don´t know if Youtube already made the automatic subs for this live)
 
Still, you don't need to escape the containment, DLL hijacking Is All You Need.

Hi Loyisa,

Some users did not believe that there is malware in the wild that can bypass CIS auto-containment via DLL hijacking, so I created a special thread.
Those examples are interesting:

However, all known examples so far are POCs or highly targeted malware.
 
Last edited:
So in this case the DLL was not auto contained?
Comodo cannot contain DLLs loaded by Trusted processes. Only Xcitium has an option to do it.
As for a home product, allowing such DLLs is understandable because it would trigger many false positives.
Smart App Control can do it, and we know how many false positives can happen. Many signed applications use unsigned DLLs.
 
Last edited:
Comodo cannot contain DLLs loaded by Trusted processes. Only Xcitium has an option to do it.
As for a home product, allowing such DLLs is understandable because it would trigger many false positives.
Smart App Control can do it, and we know how many false positives can happen. Many signed applications use unsigned DLLs.
and even excluding the whole folder in WHHL did not stop WDAC from blocking Vulkan.dll of Yandex browser according to events log.
 
Hi, Like the previous version, everything that goes through the sandbox doesn't connect, which limits its usefulness because we can no longer launch our browsers in a Comodo sandbox (so we go back to the Windows sandbox). It's a shame about that, but otherwise it's good. Now we'll have to see how it holds up over time.
 
  • Like
Reactions: Halp2001
Hi, Like the previous version, everything that goes through the sandbox doesn't connect, which limits its usefulness because we can no longer launch our browsers in a Comodo sandbox (so we go back to the Windows sandbox). It's a shame about that, but otherwise it's good. Now we'll have to see how it holds up over time.
 

It is worth mentioning that this solution allows contained malware to use network services.
 
  • Hundred Points
  • Thanks
Reactions: ErzCrz and Halp2001
But when malicious activity takes place, doesn't Comodo hips alert of that suspicious/malicious activity?
Although Comodo's help(http://help.comodo.com/topic-72-1-766-9163-HIPS-Settings.html) states:
  • Safe Mode: While monitoring critical system activity, HIPS automatically learns the activity of executables and applications certified as 'Safe' by Comodo. It also automatically creates 'Allow' rules for these activities, if the checkbox 'Create rules for safe applications' is selected. For non-certified, unknown, applications, you will receive an alert whenever that application attempts to run. Should you choose, you can add that new application to the HIPS rules list by choosing 'Treat as' and selecting 'Allowed Application' at the alert with 'Remember my answer' checked. This instructs the HIPS not to generate an alert the next time it runs. If your machine is not new or known to be free of malware and other threats then 'Safe Mode' is recommended setting for most users - combining the highest levels of security with an easy-to-manage number of HIPS alerts.
However, HIPS in Safe Mode will allow all activities of trusted processes(even it loaded malicious DLL)
 
It is worth mentioning that this solution allows contained malware to use network services.
Agreed but the only immediate workaround I could find though I think you can refine the rule or create a specific hips/edr rule for a browser but as I don't want anything in sandbox to connect out, I leave it as is. Not done any testing with the new version on this front.
 
It's not normal for it to show that value; it's all in the Windows Registry—I'll show it in the image below.

1785011594865.png


I can't show every detail, but the process at the top of the list—the one that's fully expanded—is a Windows process. It's really bizarre... I wonder if it's a bug?

1785011699085.png
 
  • Like
Reactions: Divine_Barakah
But when malicious activity takes place, doesn't Comodo hips alert of that suspicious/malicious activity?

Paranoid HIPS settings can probably block some malicious actions. But no one use such settings due to known bugs, Windows Update problems, many blocks, and system crashes.
 
It is not only about CIS. The same happened when Emsisoft deprecated Online Armour. Some people just refuse to accept it. It happens all the time. Some software becomes to much of a burden to maintain. Some software are abandoned for various reasons. Software get acquired and pulled out from the market to be incorporated in another product. The list goes on.
And this is the one thing that just gets to me... Look at Prevx , Webroot, Emsisoft, and then there was this on-the-fly imaging program we were all talking about a couple years ago, it was great, a real competitor to Rollback RX... All these software's are developed by someone who had an idea, it was their idea, their invention, it was a part of them, it was their baby... Then for some reason they get bought up, maybe by Microsoft, maybe by someone else. It gets buried, or messed up, or they lose interest after messing it up, being unable to fix it. It's just a shame. Never sell your invention, your hard work, your baby. No one else will be passionate about it like you.
 
  • Like
Reactions: Divine_Barakah
I just finished editing the video. There's a lot to say about this version!
I won't say any more—see you tomorrow when it's posted! ;)
OK waiting with great anticipation...

Murphy's law says he won't interfere...

Whoops, 11:49 PM, post ready, uploading now. Complete in 4 minutes. World ends 11:51 Pm.

That would be a bummer.
 
And this is the one thing that just gets to me... Look at Prevx , Webroot, Emsisoft, and then there was this on-the-fly imaging program we were all talking about a couple years ago, it was great, a real competitor to Rollback RX... All these software's are developed by someone who had an idea, it was their idea, their invention, it was a part of them, it was their baby... Then for some reason they get bought up, maybe by Microsoft, maybe by someone else. It gets buried, or messed up, or they lose interest after messing it up, being unable to fix it. It's just a shame. Never sell your invention, your hard work, your baby. No one else will be passionate about it like you.
Unfortunately it does not work that way. Business is harsh. People want to use your product for free.

Sometimes, you face roadblocks and you need a larger team. Or a corporate wants to kill competition. Some devs want money and they sell a project to work on another one. The list goes on.
 
  • Like
Reactions: Parkinsond
OK waiting with great anticipation...

Murphy's law says he won't interfere...

Whoops, 11:49 PM, post ready, uploading now. Complete in 4 minutes. World ends 11:51 Pm.

That would be a bummer.

Odysee is having a minor glitch; I'll try to upload it a little later.
 
I think that the full potential of CIS/CF, including advanced HIPS (or EDR in the new version), can be applied on Windows 10 with no system updates.
Using advanced HIPS/EDR on Windows 11 is not recommended.
 
  • +Reputation
Reactions: Parkinsond