Or maybe because its 80% of users use MD.80% of the times
Or maybe because its 80% of users use MD.80% of the times
You have good knowledge of statisticsOr maybe because its 80% of users use MD.![]()
You have a unique experience; I think @TairikuOkami shares the same experience, as far as I can recall.
Agree; the attack surface area increased, and during the same period, the protection tools improved.The risks today I feel should you get infected are higher than years ago, online banking, social media, all our info online to me this is pretty recent, this was not the case 20 years ago, there is better protection for everyone but there is much more to lose than in the past & less evildoers back then I think, you may 20+ years ago get a virus but not your identity.
Not using antivirus is the worst thing you can do as a user, whether you are an expert or not. It's like getting into a car and not wearing a seat belt, because you think you will never have an accident. It doesn't happen until it happens. Getting infected is the same. It doesn't happen to you until it happens. And it doesn't matter exactly what your level is.I bought the PC I currently use on 07/23/2021 and have never seen AV intervention unless I initiated it myself.
My previous OS was Windows XP.
Contrary to all the doomsday predictions, I used the PC with Pos Ready2009 updates until 2019, and after support ended, I continued to use the PC until 2021 (when it finally died of old age).
In all these years (2014-2021), I never had an infection without real-time AV.
I use WD mainly for the AE module, which is derived from EMET.
For me, AV is therefore not as essential a component as it is for other users.
When Vistax64 came around, 80% malware literally was not compatible. Windows itself has become so secure, that the attack surface has shifted to browsers and phishing.The risks today I feel should you get infected are higher than years ago, online banking, social media, all our info online to me this is pretty recent
Seat belts can actually kill at high speeds, they are designed for cities. Nothing is just black or white as portraited by media.Not using antivirus is the worst thing you can do as a user, whether you are an expert or not. It's like getting into a car and not wearing a seat belt,
And that is another issue, majority think that AV will protect them 100% and they act surprised, if they get infected.because you think you will never have an accident. It doesn't happen until it happens.
I didn't use real-time AV on my old PC running Windows XP.Not using antivirus is the worst thing you can do as a user, whether you are an expert or not. It's like getting into a car and not wearing a seat belt, because you think you will never have an accident. It doesn't happen until it happens. Getting infected is the same. It doesn't happen to you until it happens. And it doesn't matter exactly what your level is.
in fact it is totally the opposite. It has been proven that the seat belt would save your life in the event of a fatal blow, something that exists in all cars.When Vistax64 came around, 80% malware literally was not compatible. Windows itself has become so secure, that the attack surface has shifted to browsers and phishing.
Seat belts can actually kill at high speeds, they are designed for cities. Nothing is just black or white as portraited by media.
And that is another issue, majority think that AV will protect them 100% and they act surprised, if they get infected.
I do not expect it, I do not trust anything, I have multiple banks, backups and I can redo everything within hours.
Moderation is key.in fact it is totally the opposite. It has been proven that the seat belt would save your life in the event of a fatal blow, something that exists in all cars.
Saying that is like seeing that your antivirus is going to infect you. Nothing is infallible, but it is better to have it than not.
Life is yours and so is the data, you decide.
There was malware that literally used AVs to infect, because AVs use SYSTEM by default, all popular brands were affected. AV is like VPN, people trust it 100%.Saying that is like seeing that your antivirus is going to infect you.
That is media talking, you will not get magically infected, we do not live in Harry Potter world. It is all ABC. Break the chain, break the infection. It is a simple as that. Media say that if you connect to the internet without AV, you will get infected within seconds, well not anymore. I was infected by Sasser worm, during a clean install, several times in a row.Moderation is key.
No AV at all is an extreme.
You're right: infection is not magic.There was malware that literally used AVs to infect, because AVs use SYSTEM by default, all popular brands were affected. AV is like VPN, people trust it 100%.
That is media talking, you will not get magically infected, we do not live in Harry Potter world. It is all ABC. Break the chain, break the infection. It is a simple as that. Media say that if you connect to the internet without AV, you will get infected within seconds, well not anymore. I was infected by Sasser worm, during a clean install, several times in a row.
Exist, but represent a minor percentage; if so frequent, we will find a large percentage of MT members asking for help dealing with infections everyday.There are still realistic infection paths:
- Supply-chain compromises (remember CCleaner case back in 2017)
- Malicious browser extensions
- Zero-day browser exploits
Blocking LOLbins at the firewall level may provide mitigation; the rest relis on AMSI (available for MD as for most 3rd party AVs) and behavioral protection (which can miss with both MD and 3rd party AVs, or can detect but late enough letting damage to occur).Also, drive-by isn't dead, it's just different (to say it that way).
- LOLbins
- PowerShell abuse
- mshta abuse
- Rundll32 injection
- Signed vulnerable driver abuse
Available for both MD (both in security center and by ASR rules) and 3rd party AVs.An AV with kernel telemetry can detect:
- Driver loading anomalies
- Credential dumping patterns
- Suspicious memory reads of LSASS
Power user need not to live in fear monitoring everything and lose the joy of using his/her machine; just to be cautious to avoid exposure to infection.Even power users cannot manually monitor all that in real time.
There's a fine line between avoiding paranoia and falling into complacency. For many, overconfidence is the fatal flaw that eventually invites the very issues they thought they were too smart to catch, and frankly, calling oneself a 'power user' like a title is usually just the beginning of that descent.Power user need not to live in fear monitoring everything and lose the joy of using his/her machine; just to be cautious to avoid exposure to infection.