Advice Request Is Cisco keeping ClamAV bad on purpose?

Please provide comments and solutions that are helpful to the author of this topic.

F

ForgottenSeer 89360

I wouldn't say bad, but they do have their own proprietary products for security and networking.

By the looks of it, it appears to be more community driven for mail servers, than to compete with Microsoft Defender on a Windows PC.
https://talosintelligence.com/clamav
https://talosintelligence.com/immunet
The ClamAV architecture was originally designed for mail servers.
Talos detections are mainly in the cloud, I am not aware of any cloud components being presented in ClamAV. This may explain the difference in detection.
 

MacDefender

Level 16
Verified
Top Poster
Oct 13, 2019
779
ClamAV has always been bad at general malware detection. Its primary use case has been for mail servers and stopping the distribution of emerging outbreaks as quickly as possible. Back before AVS had hourly definition updates ClamAV definitely was one of the fastest to stop new email worms. These days, almost all AV vendors have closed that gap.
 
F

ForgottenSeer 89360

ClamAV has always been bad at general malware detection. Its primary use case has been for mail servers and stopping the distribution of emerging outbreaks as quickly as possible. Back before AVS had hourly definition updates ClamAV definitely was one of the fastest to stop new email worms. These days, almost all AV vendors have closed that gap.
It still detects some threats, such as double extension (*.pdf.exe for example) or some PE malware, but performance is not impressive.
ClamAV is to be run only as part of Immunet together with other technologies implemented.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top