App Review Microsoft Defender Antivirus feat Hawk Eye Hardening

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
Shadowra

Shadowra

Level 42
Thread author
Verified
Top Poster
Content Creator
Malware Tester
Well-known
High Reputation
Forum Veteran
Sep 2, 2021
3,139
40,153
4,080
29
France
Microsoft Defender Antivirus is Microsoft’s built-in security solution for Windows, providing real-time protection against malware, ransomware, viruses, and other threats.
It integrates directly into Windows Security and offers multiple layers of protection, including real-time scanning, cloud-based protection, behavioral detection, web protection, and attack-surface reduction features.

For this test, we go a step further by adding Hawk Eye from @Trident , a dedicated hardening solution designed to strengthen Microsoft Defender and improve its security configuration.
The goal is to see how far Defender can be pushed when properly hardened, while keeping its native protection features.

Let’s take a closer look at all of this.



Interface :

The MS Defender interface is as intuitive as ever and well integrated into the Windows ecosystem.
By default, it runs before Hardening.

Hawk Eye greets us with a very high-tech interface. For this test, I’m letting its little AI fine-tune the settings it deems important.

Malware URL : 9/9
All malware download has been blocked by MS Defender.

Malware Pack : 26 (27 - 1) out of 168 threats remain
When I access the folder, MS Defender detects a new Trojan, bringing the total to 26.
Overall, the solution performed well by blocking several payloads and quite a few attacks.
But it isn’t foolproof—in the end, two pieces of malware remained, one of which patched the CasPol.exe process and another that tinkers with aspnet (which is part of the .NET Framework) and file attributes...

Final scan :
MS Defender : 0
Helios (Hawk Eye) : 6
KVRT : 3 (Memory Infected - RemcosRAT)
Symantec : 1 (XMRing)

Final opinion:

Microsoft Defender offers excellent protection overall.
Hawk Eye allows you to set strict protection rules and also includes a good scanner called Helios to scan your computer.
However, even though it blocked several script-based attacks, it is still vulnerable to them. RemcosRAT is present at the end along with another Trojan.
Despite this setback, it is recommended.
 
Is Hawkeye still be developed?
I am busy working on a platform for hotels called Auberly (tm) for Axiom/ Pyramid Hamilton and it is a massive project but yes, it is still being developed. There will be updates.

IMG_4628.png

IMG_4624.png

8D9B5C44-363A-4DB7-B217-8678870C7C7E-COLLAGE.jpeg
 
Helios (Hawk Eye) : 6 how is it that hawk eye own scanner found malware?,isn't. It part of Hawk eyes protection?
Helios is an engine that I developed myself, it does find malware and it is integrated with other vendors as well through the cloud. It’s available in the free DHC.
 
Microsoft Defender Antivirus is Microsoft’s built-in security solution for Windows, providing real-time protection against malware, ransomware, viruses, and other threats.
It integrates directly into Windows Security and offers multiple layers of protection, including real-time scanning, cloud-based protection, behavioral detection, web protection, and attack-surface reduction features.

For this test, we go a step further by adding Hawk Eye from @Trident , a dedicated hardening solution designed to strengthen Microsoft Defender and improve its security configuration.
The goal is to see how far Defender can be pushed when properly hardened, while keeping its native protection features.

Let’s take a closer look at all of this.



Interface :

The MS Defender interface is as intuitive as ever and well integrated into the Windows ecosystem.
By default, it runs before Hardening.

Hawk Eye greets us with a very high-tech interface. For this test, I’m letting its little AI fine-tune the settings it deems important.

Malware URL : 9/9
All malware download has been blocked by MS Defender.

Malware Pack : 26 (27 - 1) out of 168 threats remain
When I access the folder, MS Defender detects a new Trojan, bringing the total to 26.
Overall, the solution performed well by blocking several payloads and quite a few attacks.
But it isn’t foolproof—in the end, two pieces of malware remained, one of which patched the CasPol.exe process and another that tinkers with aspnet (which is part of the .NET Framework) and file attributes...

Final scan :
MS Defender : 0
Helios (Hawk Eye) : 6
KVRT : 3 (Memory Infected - RemcosRAT)
Symantec : 1 (XMRing)

Final opinion:

Microsoft Defender offers excellent protection overall.
Hawk Eye allows you to set strict protection rules and also includes a good scanner called Helios to scan your computer.
However, even though it blocked several script-based attacks, it is still vulnerable to them. RemcosRAT is present at the end along with another Trojan.
Despite this setback, it is recommended.

disappointing to see defender struggle against a well known .NET malware family