Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
malwaretips.com
Leo said that there could be false positives before saying "the detection is decent."Although many malwares can be recognized by observing the created processes as presented in the video, many others can infect the system silently in a second. The test ended after running 484 samples, and 18 samples (3.73%) were allowed to run. Without detailed analysis, we cannot be sure how many of those 18 samples could infect the system. Using HitmanPro could help with known samples, but it cannot be used to identify many new malwares. So, we cannot be sure if the detection in the video was decent (as Leo concluded), or not.
He said there is "non-existent behavioral blocking unless things are turned-on in Group Policy."I can say, that after accepting all shortcomings, the video shows the results consistent with the professional tests made by (AV-Test, AV-Comparatives, SE Labs, etc.). Also, most of Leo's comments are probably true, although his meaning of behavioral protection is also from 10 years ago (offline, no telemetry, no heuristics, etc.).
![]()
Serious Discussion - Best AVs and Worst AVs in Behavioral Health
There are tons of AV tests everywhere. We also have many AV solutions on the market, which makes the choice not easy. Which antiviruses are currently at the forefront of behavioral protection? Which are not at the forefront but will provide at least good protection? And which are so weak that...malwaretips.com
Leo said that there could be false positives before saying "the detection is decent."
All the malware executed were "new" malware.., but old malware was dropped and yet, still, Microsoft Defender allowed malware for which signatures it already has were allowed to execute.
He said further that he has seen this happen - malware for which Microsoft already has signatures being allowed to execute - before.
He said there is "non-existent behavioral blocking unless things are turned-on in Group Policy."
Rewatch the video. Leo shows the malware in the Z:\Shared\Malware folder and looks-up the detections on VirusTotal - two times/twice. It clearly shows that Microsoft has signatures for the malware, and it executed. Leo discusses what happened.You are wrong. The video only shows that they were dropped, and the dropper probably tried to execute them many times.
During the video not a single Microsoft Security prompt appeared asking the user to make a decision. Every single alert that appears in the entire video from Microsoft Security is "MIcrosoft Defender Antivirus detected threats. Get Details."That is true for some PUAs. Microsoft Defender detects them and proposes the recommended actions. This also happened in the video, but Leo ignored those recommendations. Anyway, the parent process constantly tried to run the dropped files but failed (probably due to the signatures).
Leo says at 5:35 that Microsoft Defender "detection is not too bad, which is fairly decent considering these are brand new files" and at 6:30 he says "It is not any worse than other AVs in terms of signatures." At 7:00 Leo begins talking very positively about Microsoft Defender.Leo has an unbelievable obsession with MS Defender, but of course he needs the click-bait $$$.
All of this is true without any doubt. Nonetheless, he keeps pumping out Defender vids with essentially the same message, over and over. And I agree that one might as well not use any AV at all since they're all equally deficient in the long run.Leo says at 5:35 that Microsoft Defender "detection is not too bad, which is fairly decent considering these are brand new files" and at 6:30 he says "It is not any worse than other AVs in terms of signatures." At 7:00 Leo begins talking very positively about Microsoft Defender.
The criticism of Microsoft Defender's over-reliance upon the cloud, its poor heuristics and behavioral blocking, are accurate and fair criticisms.
Send Leo a "Get Well Soon" card with a note that includes a "mental bandaid" (a real bandaid with the word "Mental" written across it) advising him to take care of his Microsoft Defender obsessions.All of this is true without any doubt. Nonetheless, he keeps pumping out Defender vids with essentially the same message, over and over. And I agree that one might as well not use any AV at all since they're all equally deficient in the long run.
During the video not a single Microsoft Security prompt appeared asking the user to make a decision. Every single alert that appears in the entire video from Microsoft Security is "MIcrosoft Defender Antivirus detected threats. Get Details."
There are a few notifications from Microsoft Security instructing the user to restart the system.
So Leo is not ignoring any alerts where he had to make a decision to Allow or Block a program, as there are no notifications asking him to make a decision.
The criticism of Microsoft Defender's over-reliance upon the cloud, its poor heuristics and behavioral blocking, are accurate and fair criticisms.
I have access to the full E5 Government offering that includes every single part of Microsoft Security from Microsoft Defender to EDR to Sentinel to Compliance. And even with all those Microsoft Security components properly and securely configured there are systems that get breached and infected.
If it were Kaspersky or Bitdefender on Leo's same test system, the poor Defender showing is almost certainly would not have been replicated.
For users that know and prioritize security, should that matter? Perhaps, but most of the protections are coming from the user and not the security software. Nevertheless, Microsoft Defender as a standalone security solution is not adequate and sufficient for any household using Windows Home with downloading minions that know nothing about security.
I have a question so have big a difference does Automatic sample submission make?
Microsoft Defender allowed Unicorn to run. It is the malware that caused the system to freeze. Microsoft Defender has signatures for it but still it allowed Unicorn to run.Let's assume that those 17 samples were blocked similarly to Unicorn (although there is no evidence for that).
I clearly said "There were no Microsoft Defender alerts requiring the user to make a ALLOW or BLOCK decision."I do not agree. As you have noticed, two Microsoft Defender alerts required the user actions (restarting the device). Ignoring those alerts caused the system inoperable (which worried Leo). If Leo did restart the system, Microsoft Defender would kill all unwanted processes without problems.
Yeah, actually he is. He knows way more than people here suspect or realize. He is constantly criticized as "not knowing what he is talking about when it comes to Microsoft Defender", but actually, he does - very much so.There is no evidence for poor heuristics and behavior blocking. Leo is not an expert on Microsoft Defender.
I never argued that "all non-block-by-default solutions have poor heuristics and behavior blocking." I never said any such thing. You are putting words into my mouth.The same is true for other solutions, except default-deny. So according to your argumentation, all non-block-by-default solutions have poor heuristics and behavior blocking.
I did not say that Leo did. What I said was "If Leo had used Kaspersky or Bitdefender in the video instead of Microsoft Defender, either of those two solutions would not have resulted in a frozen/locked test system." Of course there is no absolute proof of this but the probability is very high that this statement is correct.Leo did not present poor Defender showing in his videos, except for some videos with disabled Internet.
Oh, I understand what you are saying and your perspective. Leo is 100% transparent on everything.@bazang,
I talk about apples and you answer about potatoes. So, it is time to rest.
I have spent a few hours explaining why something called by the author an "educational video" is really only an educational video.
I am unsure if I did it well, but I tried my best.![]()

Leo's videos can be called "entertainment."Although we do not agree on what makes an AV evaluation test reliable, we certainly agree on Leo's educational skills and transparency.![]()
Members who viewed this thread in the last 5 minutes