App Review Microsoft Defender Antivirus feat AI Defender

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
Shadowra

Shadowra

Level 40
Thread author
Verified
Top Poster
Content Creator
Malware Tester
Well-known
High Reputation
Forum Veteran
Sep 2, 2021
2,976
37,969
3,880
29
France
Microsoft Defender is Microsoft's free antivirus software, included since Windows 8.
It offers a comprehensive solution—antimalware, firewall, web protection (via Edge), etc.
In this test, we will add AIDefender, a new product that is designed to enhance protection through various advanced features.
Let's take a look!



Interface :
We won't dwell on MS Defender, which we are familiar with, but rather on AIDefender.

The product features an attractive interface with several options. Their AI, Helios, can quickly scan your computer for threats, guide you through the configuration (which is very comprehensive), block LOLBins via the firewall, etc.
A job well done!

Web protection: 8/9
MS Defender missed one URL (CobaltStrike) and one URL was a false positive.
The rest were blocked correctly.

Fake crack : N/A
The sample is too old and the site that distributed it was down.
Skipped.

Malware Pack : Remaining 30 threats out of 143
There are a few things to mention:

Firstly, I noticed a decline in script detection on Microsoft Defender. Although it can block the payload afterwards, Microsoft has accustomed me to better blocking capabilities.
Although the software still holds up, it's worth noting that the addition of AI Defender has been beneficial, as the machine has come close to being infected several times by some fairly aggressive RATs.
Nevertheless, neither MS Defender nor AI Defender were able to block other fairly virulent RATs, often used legally but which can be hijacked by hackers, such as ConnectWise or GoToResolve, contributing to the infection of the machine.
At the end of the test (and a surprise restart), several pieces of malware did not launch, but traces of them remained.

Final scan :
MS Defender : 0
AI Defender (Helios) : 3
NPE : 5
KVRT : 15

e8da7713-7ef6-49d9-b862-19ba6597a742.png

Final opinion:
Overall, the results are good, but I'm quite disappointed with the Microsoft Defender scan; I expected better.
AI Defender is a good, versatile ally that will help and guide the user.
Of course, the machine is infected, and MS Defender was unable to block legitimate RATs that have been hijacked by hackers (such as ConnectWise), but the machine can be saved.

@Trident request
 
Thank you for the test Shadow.

I am happy to see AiDefender (DHC) is a useful addition as a second opinion scanner, and helps guide the users through the nooks and crannies of MS Defender.

To the users of AiDefender, since that version, reputation and cloud-based AI have been integrated and there is PUP detection coming soon.

With these changes, AiDefender may become another second opinion scanner often used in tests.
 
Credit where credit is due, creating new security software and releasing it to the public for review is good. Us security folks are the harshest of critics.
The tested version is before the integration of AI and reputation, so these threats were stopped purely based on my proprietary heuristics set.

The versions released later had different UI as well as newer engine. It integrates both known goodware and known malware services and AI analyses whatever is the middle.

I am exploring the option of integrating Yara but from my tests I don’t see the benefit of Yara rules at the moment.
 
There's a lot of reasons that AMSI or general script detection can "regress" - that have nothing to do with AI Defender.

1. False Positive "Tuning" Problems
2. Model "Drift" and AI Retraining
3. Component and Versioning Mismatch
4. Bypassing the "Bypass Detection"
5. Others

AMSI and general script detection is highly dynamic and what is detected at 11 AM HKT might not be detected by 3 PM GMT. Microsoft is constantly doing "stuff" to AMSI and script detection plus the Microsoft backend that performs all of this does its own "stuff" without human interaction.

There is nothing definitive at this point to support a connection between the statement "a decline in script detection" and AI Defender.
 
Thank you for the test Shadow.

I am happy to see AiDefender (DHC) is a useful addition as a second opinion scanner, and helps guide the users through the nooks and crannies of MS Defender.

To the users of AiDefender, since that version, reputation and cloud-based AI have been integrated and there is PUP detection coming soon.

With these changes, AiDefender may become another second opinion scanner often used in tests.
Will you release a standalone second opinion scanner with full system scan maybe? I would really be excited for this.
 
Up until now, my only complaint with MSD has been it slows down PC / file transfer. I use this a lot synching drives with Directory Opus.

For ex: with MSD I get about 65 MB but with my current set up which is PCMatic and SiriusGPT I get 135 MB
 
Up until now, my only complaint with MSD has been it slows down PC / file transfer. I use this a lot synching drives with Directory Opus.

For ex: with MSD I get about 65 MB but with my current set up which is PCMatic and SiriusGPT I get 135 MB

I would have liked to test PCMatic, but I didn't get any response...
 
I would have liked to test PCMatic, but I didn't get any response...
Maybe we can help? see this from other post:

How do you like Pc Matic? Is its protection good? I'd appreciate it if you could write a review-style piece about it. Are lifetime memberships still being sold?

Well, it is very nice, no ads, or popups, I don't even know it's there, same for Sirius.

PC still very fast, possibly even faster than Eset, going from memory Eset, Kaspersky, Avast One, and McAfee are very fast on my PC. PCMatic and Sirius are at least as fast possibly faster.

The cost for PCMatic for one year is 50 US dollars for 5 devices, that is 10.00 each.

Concerning the Lifetime License, this is what "Terms and Conditions" states below:

18. Lifetime License (aka Evergreen License)
18.1 A Lifetime perpetual license will allow the customer to use the licensed full version of the software indefinitely - for non-commercial purposes.

18.2 The Lifetime perpetual license is nontransferable.

18.3 The Lifetime perpetual license includes all future product and security updates.

The price is and I believe still is 150.00 dollars for the lifetime license and I am pretty sure it was for 5 devices. Please double check that lifetime purchase info before you buy.

For a professional review, possibly Shadowra could do this, and maybe those of us here who are members are MWT could chip in to cover the 50 dollars so he can test it, via maybe gofundme... 5 dollars from 10 people would not hurt anyone
 
I would have liked to test PCMatic, but I didn't get any response...

Shadowra:

I don't think anyone would mind if you made a testing security products "gofundme" to cover time and costs...

IF you make one, I will donate. I guess you could use PayPal. You need to give a link, and I will help cover cost to purchase PCMatic, and possibly others in the future too
 
Will you release a standalone second opinion scanner with full system scan maybe? I would really be excited for this.
I could, my data oriented design makes it easy to integrate different solutions in different projects quickly as there is no spaghetti code.

As long as it covers the standards that I seek to provide.
 
Shadowra:

I don't think anyone would mind if you made a testing security products "gofundme" to cover time and costs...

IF you make one, I will donate. I guess you could use PayPal. You need to give a link, and I will help cover cost to purchase PCMatic, and possibly others in the future too
Maybe he could use Patreon and offer a subscription to his content.