App Review McAfee Protection (Plus Plans, Total Protection, LiveSafe)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Product name
McAfee Total Protection/Plus Plans
Installation (rating)
5.00 star(s)
User interface (rating)
5.00 star(s)
Performance (rating)
5.00 star(s)
Core Protection (rating)
5.00 star(s)
Proactive protection (rating)
5.00 star(s)
Additional Protection notes
See tests
Browser protection (rating)
5.00 star(s)
Positives
    • Many features
    • Low impact on system resources
    • Lightning fast scans
    • Easy to use
    • Simple and non-intrusive
    • Ransomware protection
    • Strong and reliable protection
    • Detects or blocks in the wild malware
    • Consistently high test scores
    • Accurate results and reliable antivirus engine
    • Effective malicious URL blocking
    • Virus signatures are updated daily
    • Excellent scores in independent tests
    • Great value for money
    • Effective malware removal
    • Well designed, clear and easy to use interface
    • Multi-layer protection approach
Negatives
    • Advanced users may want more control
    • Short on configuration options
    • Includes paid-for components (paywall)
Time spent using product
Reviewed between 1 to 7 days
Computer specs
11th Gen Core i5
16GB RAM
Recommended for
  1. All types of users
Overall rating
5.00 star(s)
No, they are a customer, these are paid feeds. Any alliances between CIA, KGB and so on would be for internal governmental projects. McAfee is not gonna get this intelligence.
I see. So McAfee gets some intel from Kaspersky but Kaspersky does not get any feeds from McAfee. No sharing or some sort of collaboration.

I'm thinking McAfee needs intel for the Russian Speaking/Writing world and the underground. Instead of reinventing the wheel and doing it themselves, just subscribe to K.
 
@Trident Thank you very much for the article and the topic you created on the McAfee Protection (Plus Plans, Total Protection, LiveSafe) The article is objective and very clear. I admit that I've loved McAfee in all respects since I started using it on the first day, it's very efficient, super light on resources, doesn't consume a lot of ram or CPU and without bloatware, without beating around the bush, it detects the threat and neutralises it automatically. These types of topics need to be posted a lot here on the forum, it fills an empty space here, bringing a lot of valuable information to MT members. (y) ;)
 
I was not only convinced of McAfee's virtues because of my overall smooth and pleasant personal experience with Total Protection 2025, but also the truly impressive scope of McAfee Global Threat Intelligence. According to their descriptions, GTI collects data from millions of endpoints worldwide: billions of sensors across devices, networks, and cloud environments. They process petabytes of threat data daily. McAfee Labs' 2023 Threat Predictions stated that they track over 1 billion malware samples annually. Finally, this extraordinary network operates across 120+ countries for thoroughly global reach of intelligence.
 
Just noticed that McAfee is one of the companies subscribed to Kaspersky Threat Intelligence Feeds. That explains a lot!

Very interesting, could you share the link that has this info? I am curious to see how many clients Kaspersky has with this service that by all means should be a top tier feed.
 
Very interesting, could you share the link that has this info? I am curious to see how many clients Kaspersky has with this service that by all means should be a top tier feed.

1753454735255.png
1753454776442.png
1753454807924.png
1753454839565.png

In addition to offering lookups through Restful API, the intelligence is also offered as hashes in JSON format. Fortrinet also seems to be subscribed to ESET feeds as a lot of detection names seem to be similar to ESET.
 
Thanks for your message.
Just noticed that McAfee is one of the companies subscribed to Kaspersky Threat Intelligence Feeds. That explains a lot!
Just a clarification: McAfee is not a subscriber. That information means that their technologies can use Kaspersky Threat Data Feeds integrated in their SIEM - SOAR products to improve their detection capabilities.

More like CIA+KGB alliance....same goes for AV intel sharing
1753463904273.png
 
Thanks for your message.

Just a clarification: McAfee is not a subscriber. That information means that their technologies can use Kaspersky Threat Data Feeds integrated in their SIEM - SOAR products to improve their detection capabilities.


View attachment 289833
Are you a Kaspersky employee?
 
Decoding the McAfee detections and how exactly they are produced. Demistifying the antivirus log.

McAfee uses multi-dimensional malware analysis where a bunch of engines all analyse a file and return a verdict. The overall verdict is then combined.

Here are a few examples.
FieldValue
Timestamp2025-07-26T14:48:40.237Z
Action Taken✅ Infection Quarantined
Detection Nameti!9CEF965A2154
Malicious File (Target)C:\Users\user\AppData\Roaming\win32lic\win32lic.exe
Initiating Processpowershell.exe
SHA256 Hash9cef965a21542636597c702b37147cc63a3cdc67baf5cfe5036618190e130cf0

Detection SourceFile ReputationHTI Reputation
hti44 <- online reputation reports the file as malicious
cache00 <- nothing in cache, as detections are cached only once they occur, not before that
uwp00 <- not a UWP app
signature050 <- picked up by a Yara rule
trust-dat44 <- file is untrusted
rp-s44 <- minor tweaks to the final score. RealProtect static analysis deems the file suspicious
av01 <- these verdicts are minor tweaks to the final score
neo01 <- minor tweaks to the final score

FieldValue
Timestamp2025-07-26T14:44:02.718Z
Action Taken✅ Infection Quarantined
File PathC:\Program Files\RunTime\RuntimeBroker.exe
SHA256 Hash84dafe1119847505f10f7459efef60d5d0a77df39ee810d12c8bd4865b1c8960

Detection SourceFile ReputationHTI Reputation
hti22 <- suspicious file
cache00 <- again, nothing cached
uwp00
signature050 <- picked by a Yara rule
trust-dat22 <- the file is not trusted
rp-s22 <- Real Protect Static analysis doesn’t like the file
av050 < there was a standard AV Generic detection
neo050 <- neo detected the malware

Example 3: Signed malware (Signature by Valve, issuer DigiCert).
FieldValue
Timestamp2025-07-26 at 4:16:05 PM BST
Action Taken✅ Infection Quarantined
File PathC:\Users\user\Downloads\...\7bd7a1...exe
SHA256 Hash7bd7a1e25b131a3a1fb8cc36f763259ea956468eedf410bf670cd095c0d34ab1

Detection SourceFile ReputationHTI Reputation
hti22 <- not trusted but suspicious
cache00
uwp00
signature050 <- picked up by a Yara rule
trust-dat22 <- not trusted
rp-s22 <- not reported as safe by static analysis
av050 <- there is a generic detection
neo050 <- Neo identifies via heuristics
 
Another instance, VBE file with relatively low VT 11/61, of which some detections are by engines that typically detect everything uploaded as malware (Google, looking at you).

FieldValue
Timestamp2025-07-26 at 4:36:27 PM BST
Action Taken✅ Infection Quarantined
File PathC:\Users\user\Downloads\...\30f1ac...vbe
SHA256 Hash30f1ac88eeef485cb4ca647cccfb8f5c827e6309a4c106a6615702e2c32c6ded

Detection SourceFile ReputationHTI Reputation
hti1515 <- this previously returned lower scores, here, it looks like the file is not on the wanted, but on the most wanted list. Probably a widespread malware that McAfee is tracking actively.
cache00
uwp00
signature00 <- No Yara rule
rp-s00
av050 <- generic detection
neo01 Neo emulation returns very minor confidence that the file is malicious, perhaps it detected and attempted to evade emulation
 
I am not here to support fanboyism and truly don't care who's a fan or not a fan of what.

Anyway, this thread is for tests (not for people who are hurt because the thread is not about MalwareBytes appraisal) so let's get to the tests, shall we?

Another bunch of low VT files, assassinated by McAfee.

FieldValue
Timestamp2025-07-29 at 10:26:33 PM BST
Action Taken✅ Infection Quarantined
TargetC:\Users\user\Downloads\...\172f10...bat
Initiatorexplorer.exe
Detection NameTrojan:Script/ObfuBAT.EOFF
SHA256 Hash172f10d6d541ebda465da45badd31e32ad325a8399e2ecbe4ff64e32da481222
TLSHNot Provided
Key Enginessignature (50), trust-dat (50), av (50), hti (25)


FieldValue
Timestamp2025-07-29 at 10:23:35 PM BST
Action Taken✅ Infection Quarantined
TargetC:\Users\user\Downloads\...\761af9...js
Detection Nameti!761AF9448AED
SHA256 Hash761af9448aedaf83e539e45fb8f9f3eefe84bbff59131397f8990f7b2adf9fa6
TLSHNot Provided
Key Enginessignature (50), av (50), neo (50)

FieldValue
Timestamp2025-07-29 at 10:17:33 PM BST
Action Taken✅ Infection Quarantined
TargetC:\Users\user\AppData\LocalLow\...\kpbec.ps1
Detection NameTrojan:Script/SuspiciousPowershell.O!1
SHA256 Hashe055cf8142d621a2db4efab9abe68bc8ef3a77ac159800c38e47c41b952c5c79
TLSHNot Provided
Enginessignature (50), rp-fileless (50), av (50)
 
I am not here to support fanboyism and truly don't care who's a fan or not a fan of what.

Anyway, this thread is for tests (not for people who are hurt because the thread is not about MalwareBytes appraisal) so let's get to the tests, shall we?

Another bunch of low VT files, assassinated by McAfee.

FieldValue
Timestamp2025-07-29 at 10:26:33 PM BST
Action Taken✅ Infection Quarantined
TargetC:\Users\user\Downloads\...\172f10...bat
Initiatorexplorer.exe
Detection NameTrojan:Script/ObfuBAT.EOFF
SHA256 Hash172f10d6d541ebda465da45badd31e32ad325a8399e2ecbe4ff64e32da481222
TLSHNot Provided
Key Enginessignature (50), trust-dat (50), av (50), hti (25)


FieldValue
Timestamp2025-07-29 at 10:23:35 PM BST
Action Taken✅ Infection Quarantined
TargetC:\Users\user\Downloads\...\761af9...js
Detection Nameti!761AF9448AED
SHA256 Hash761af9448aedaf83e539e45fb8f9f3eefe84bbff59131397f8990f7b2adf9fa6
TLSHNot Provided
Key Enginessignature (50), av (50), neo (50)

FieldValue
Timestamp2025-07-29 at 10:17:33 PM BST
Action Taken✅ Infection Quarantined
TargetC:\Users\user\AppData\LocalLow\...\kpbec.ps1
Detection NameTrojan:Script/SuspiciousPowershell.O!1
SHA256 Hashe055cf8142d621a2db4efab9abe68bc8ef3a77ac159800c38e47c41b952c5c79
TLSHNot Provided
Enginessignature (50), rp-fileless (50), av (50)
Please help me! I bought McAfee Total Protection. It includes Scam Detector. But why is this all I see on my Windows PC?
What I marked in red is Scam Detector. That's all I can see. No email, nothing like what you have. Why is that? Does that mean the service isn't working? Or what's the problem?
 

Attachments

  • Képernyőkép 2025-07-31 092110.jpg
    Képernyőkép 2025-07-31 092110.jpg
    38.2 KB · Views: 103
Please help me! I bought McAfee Total Protection. It includes Scam Detector. But why is this all I see on my Windows PC?
What I marked in red is Scam Detector. That's all I can see. No email, nothing like what you have. Why is that? Does that mean the service isn't working? Or what's the problem?
You are looking on the main console. You need to open protection.mcafee.com

Also, it’s not available in all regions/languages.