Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
Wouldn't it have been better to present this test in a video? Or would it not add much?There is a certain limitation to what degree you can attribute the failure to the lack of proper testing, attack replication and so on.
After that, it starts looking suspicious.
It would add nothing. The discussion back and forth here is about whether the way the test was conducted presents any real value.Wouldn't it have been better to present this test in a video? Or would it not add much?![]()
Sure they can. It just requires a willingness to do so, time, and effort.The author argues so many samples can't be executed one by one.
I call it "gang banging the security solution." I don't care that the phrase is considered inappropriate, suggestive, and "politically incorrect."My position is in the middle. I don't like tests with many samples (not curated) and I don't like auto-execution tools.
The bigger the brain, the greater the need for a big brain outlet.Lots of big brains here
Yeah, I wouldn't. But in this case the argument is that you are testing against 2 drops from the whole ocean (randomness, statistically insignificant). So there is no satisfaction.Sure they can. It just requires a willingness to do so, time, and effort.
Perhaps not use 10,000+ samples as a wiser decision?
“How safe am I if I install this AV and use my computer normally?”
→ Full-stack, real-world testing is the gold standard.
“Which vendor has the strongest detection engine?”
→ You need sample-based corpus testing.
| Scenario | Attack Vector | Expected Protection Layer |
|---|---|---|
| Malicious website drive-by | Exploit kit via browser | URL filter, exploit mitigation |
| Phishing email attachment | Malicious Office macro | Heuristics + behavior blocker |
| Executable download | EXE via HTTPS link | Cloud reputation + signatures |
| Fileless attack | PowerShell abusing LOLBins | Script control + behavioral AI |
| Malvertising campaign | Malicious iframe injection | URL filter + runtime memory protection |
Highlight: CyberLock’s behavioral engine + WDAC integration should outperform signature-heavy AVs here.
90% = Excellent
Note: This test isn’t as relevant for marketing, but some enterprise customers expect to see these numbers.
0.5% = Needs tuning
| Metric | Test Method |
|---|---|
| Boot time impact | Average Windows boot time ± AV installed |
| File operations | Copying, extracting, and deleting 10GB dataset |
| App launch delay | Opening large apps (Office, Photoshop, browsers) |
| CPU & RAM usage | Idle + scanning + active blocking |
| Category | Weight (%) | Why It Matters |
|---|---|---|
| Real-world protection | 35% | Directly reflects user experience |
| Ransomware defense | 25% | High-impact threat, key differentiator |
| Zero-day blocking | 15% | Shows proactive security |
| Static detection | 10% | Benchmark transparency |
| False positives | 5% | Avoids usability issues |
| Performance impact | 10% | User satisfaction & adoption |
Create a test script, tool, or automation workflow that launches a malware sample and then waits for 5 minutes to execute the next sample until the entire "pack" is tested or a malware borks the system, whichever comes first. Keep the testing to 100 or less malware samples.Yeah, I wouldn't. But in this case the argument is that you are testing against 2 drops from the whole ocean (randomness, statistically insignificant). So there is no satisfaction.
It's much better to study and curate them, and ensure you are testing against a broad range (if you really want meaningful results). But the problem is, on forums, there are beehives for every product. When you don't show them the results that they want to see, the test is criticised.Create a test script, tool, or automation workflow that launches a malware sample and then waits for 5 minutes to execute the next sample until the entire "pack" is tested or a malware borks the system, whichever comes first. Keep the testing to 100 or less malware samples.
This test method is not difficult.
Notes about the significance of the results.
As can be seen from similar tests conducted by AV-Comparatives, one test is not sufficient to find winners in a reliable (statistically significant) way.
However, you can conduct your tests systematically as long as you want (a few times a year) and post the results on MT.
After a year, we can analyze the results and choose the winners. This will require testing the same group of AVs during one year.
Agreed on all points. Testing procedure that is. My interest although most if not ALL points are of ACCURATE consideration OF COURSE- But A useful AV TEST TOOL to combine and/or separate samples like this needs some additional fine tuning and MORE OPTIONS.The problem can be if there is no winner. This is possible because in such a test, AV can miss on average 1 sample per 2000 samples.
The solution would be to decrease the number of samples to 2000 (more or less) and conduct the test more frequently (one test per month).
Maybe add a heuristic that calculates the system load in real time and decides when to execute the next sample… monitor for cpu spikes (which suggest the solution could be remediating malware). Do not try to target specific processes, as unsigned tool containing AV process names as strings could be highly suspicious.Agreed on all points. Testing procedure that is. My interest although most if not ALL points are of ACCURATE consideration OF COURSE- But A useful AV TEST TOOL to combine and/or separate samples like this needs some additional fine tuning and MORE OPTIONS.
You can try sending to OpenPhish whose feeds are more or less utilised by everyone nowadays, you can report to PhishTank as well. I can create either a small html page with a JS that quickly takes the URL from you and composes an email which you have to send, or a document with macro (one click operation) which plays well with desktop Outlook client.@Trident Every day, I receive spam, and often it contains phishing URLs. I submitted a phishing URL on August 27, 2025, and Netcraft classified that it found no threat in the URL I submitted. This has happened twice, and today I received an email from Netcraft saying that it had been reanalyzed and classified as malicious. Whenever I find a phishing or malware URL, whether in an email or while browsing the web, I report it to Netcraft, McAfee, Kaspersky, Emsisoft, Bitdefender, Microsoft, and Google Safe Browsing.
Yes, that's right. What's more, phishing is still online, so I also send it to PhishTank. It's even easier with PhishTank because I can forward the email directly to them, which is more practical and faster.You can try sending to OpenPhish whose feeds are more or less utilised by everyone nowadays, you can report to PhishTank as well. I can create either a small html page with a JS that quickly takes the URL from you and composes an email which you have to send, or a document with macro (one click operation) which plays well with desktop Outlook client.
![]()
Report phishing to OpenPhish - phish.report
Detect, disrupt, and deter consumer phishing attacks. Phish Report gives your team the same capabilities as leading brand protection services.phish.report
Sadly Phishtank API doesn’t support uploading a URL, so I can not provide any automation for you… not sure about the rest that you are reporting to. By the time you report to everyone one by one, the URL will be dead![]()
Members who viewed this thread in the last 5 minutes