Advice Request macOS needs an AV?

Please provide comments and solutions that are helpful to the author of this topic.

Trident

Level 34
Verified
Top Poster
Well-known
Feb 7, 2023
2,349
I’m using F-Secure on my Mac, so far so good. F-Secure, as far as I’m aware, is the only AV product that has behavioral protection function (DeepGuard) on macOS.
The new version can be installed and managed from either the on-premises Symantec Endpoint Protection Manager or the Integrated Cyber Defense Manager (ICDm) cloud console. This agent release includes key innovations such as:

  • Behavioral analysis, which analyzes good and bad behaviors to prevent new and unknown threats on the macOS.
According to Symantec documentation above, Symantec client for Mac includes behavioural analysis as well. Since Norton for Mac in the package names still carries “Symantec” references, one can assume that behavioural protection is included. However documentation is inconclusive to say for sure. Nevertheless, F-Secure is not the only one.
 

Anthony Qian

Level 10
Verified
Well-known
Apr 17, 2021
454

According to Symantec documentation above, Symantec client for Mac includes behavioural analysis as well. Since Norton for Mac in the package names still carries “Symantec” references, one can assume that behavioural protection is included. However documentation is inconclusive to say for sure. Nevertheless, F-Secure is not the only one.
I’ve edited my comment. However F-Secure lets you create your own HIPS-like rule on macOS, which is quite customizable.
 

Anthony Qian

Level 10
Verified
Well-known
Apr 17, 2021
454
Do you need those functions when running trusted apps? Are you able to share screenshots as an example.
According to F-Secure's help manual, there are three levels of protection of DeepGuard:
• Default: This level allows most built-in macOS apps and processes to work normally. It does not monitor read operations on the computer, but checks attempts to write or run files.
• Classic: This level allows most built-in macOS apps and processes to work normally. It monitors attempts to read, write, or run files.
• Strict: This level only allows access to necessary processes. This allows you to more closely monitor system processes and built-in applications.

So I believe Apple's native apps are not monitored and are allowed to run smoothly. For other third-party apps, I have not noticed DeepGuard blocking their behavior, except for the app called pap.er. Screenshot is attached.

截屏2023-05-21 23.03.45.png
 

Trident

Level 34
Verified
Top Poster
Well-known
Feb 7, 2023
2,349
HIPS like in a way that it will block certain behaviours of your choice (let’s say screenshot creation for the sake of example or writing files in certain directories) or it just includes aggressiveness level for the behaviour monitor?

I might give it a spin in the coming days. Do you know if it still uses Avira engine or just proprietary ones?
 

simmerskool

Level 37
Verified
Top Poster
Well-known
Apr 16, 2017
2,605
I’ve edited my comment. However F-Secure lets you create your own HIPS-like rule on macOS, which is quite customizable.
I think I have an unused F-Secure license, tempted to try F-Secure on mac, but still reluctant to drift away from pure Apple protection :cautious:
 
  • Like
Reactions: Trident

Anthony Qian

Level 10
Verified
Well-known
Apr 17, 2021
454
HIPS like in a way that it will block certain behaviours of your choice (let’s say screenshot creation for the sake of example or writing files in certain directories) or it just includes aggressiveness level for the behaviour monitor?

I might give it a spin in the coming days. Do you know if it still uses Avira engine or just proprietary ones?
Only when you turn on the advanced mode of DeepGuard does it allow you to create your own rules and modify protection levels.

Yeah, like F-Secure for PC, Mac version also uses Avira engine as well as their own engine, Hydra (F-Secure Latest Database Updates). Additionally, detection from Protection Cloud can also be triggered and suspicious files will also be sent.
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
According to F-Secure's help manual, there are three levels of protection of DeepGuard:
• Default: This level allows most built-in macOS apps and processes to work normally. It does not monitor read operations on the computer, but checks attempts to write or run files.
• Classic: This level allows most built-in macOS apps and processes to work normally. It monitors attempts to read, write, or run files.
• Strict: This level only allows access to necessary processes. This allows you to more closely monitor system processes and built-in applications.

So I believe Apple's native apps are not monitored and are allowed to run smoothly. For other third-party apps, I have not noticed DeepGuard blocking their behavior, except for the app called pap.er. Screenshot is attached.

View attachment 275550
Interesting to know that F-Secure goes beyond the generic Antivirus route and offers DeepGuard for pro-active protection against potentially harmful changes.

How to Geek mentioned a KnockKnock for scanning if you do not want a real-time av on macOS. I have never used it.
LuLu Firewall is another great free and open-source tool for Mac users.
 

bob974

Level 4
Verified
Feb 5, 2013
182
Hi,
I have tried F-secure, norton, kaspersky, bitdefender and since a year I have switched to INTEGO.
Frankly, for me it is the best protection on MAC.
Fast scans
firewall
What more can you ask for?
 

Gandalf_The_Grey

Level 83
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,255
The last test done in June by 2022 AV-Comparatives Intego was the only one not certified:
Unfortunately, Intego app did not quite reach our threshold for Mac malware detection, and so was not certified this year.
Let's see what's changed this year (probably June 2023).
 

Trident

Level 34
Verified
Top Poster
Well-known
Feb 7, 2023
2,349
The last test done in June by 2022 AV-Comparatives Intego was the only one not certified:

Let's see what's changed this year (probably June 2023).
It’s also quite expensive and uneconomical for users who have devices with different platforms, as the Windows version is not great (just another Avira-based AV). They don’t offer any mobile apps either.
 

NormanF

Level 9
Verified
Jan 11, 2018
404
Never any antivirus on my MacPro now with macOS Ventura 13.4. Just robust firewall protection with Murus Pro. Never had a virus problem: never caught a virus in years.

The reason why an AV is unnecessary is because like on Linux, software installation on a Mac is done with the highest security privilege. Users are on a standard account where in contrast on Windows, the administrator account is the default.
 

simmerskool

Level 37
Verified
Top Poster
Well-known
Apr 16, 2017
2,605
Interesting to know that F-Secure goes beyond the generic Antivirus route and offers DeepGuard for pro-active protection against potentially harmful changes.


LuLu Firewall is another great free and open-source tool for Mac users.
what about Little Snitch?
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top