App Review Windows Defender VS Ransomware, Controlled folder access feature tested

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Summary of video:

4:30 - Buran ransomware not blocked by Defender
  • Desktop items encrypted (Desktop was not added to Protected folders in this test).
  • Folders in the Protected folders list were safe/untouched.
8:15 - Jenkins ransomware not blocked by Defender
  • Jenkins ransomware runs in the background as the tester continues with the rest of the test.
  • 13:50 - Jenkins ransomware bypasses Controlled Folder Access and encrypts everything.
 
Hi,
Thanks for testing. The Buran and Jenkins are interesting ransomware samples. It is really hard to test the WD Controlled Access feature, because most samples are detected/blocked by WD local signatures and cloud protection.
What was the last Windows Update on the tested machine?
If I correctly recall, the Buran ransomware depends on Windows exploits.
I am not sure about Jenkins ransomware. Is it related to the Jenkins servers vulnerabilities?
Do you know something more about those two ransomware samples?
:)(y)
 
Last edited:
I would propose to change the author's comment under the video on the video website:
"Let's review the How effective is Controlled folder access Feature in Windows Defender"
It is hard to see how effective is Controlled folder access on 2 samples.

The author does not claim that WD is better (or worse) than other AVs and the results are similar to other tests that were already discussed on MT. This is a standard demonstration test with two interesting ransomware samples. (y)
 
Useless and pretentious comment.
Nobody is trying to discredit anything.

every single time someone posts something about Windows Defender or Windows Security
certain individuals some running to the thread and immediately start to pick the test apart and belittle it
that is a blatant effort to discredit
it is widely-known at this point across the web on different security forums that this forum has become a Windows Security echo chamber
 
every single time someone posts something about Windows Defender or Windows Security
certain individuals some running to the thread and immediately start to pick the test apart and belittle it
that is a blatant effort to discredit
it is widely-known at this point across the web on different security forums that this forum has become a Windows Security echo chamber

That's pure nonsense!

In fact, there are other forums that recommend Windows Defender. People use what they like, read what they like and believe what they like.
 
That's pure nonsense!

no it isn't
just look at every single thread here at MT where a test of Windows Defender has poor results
it's the same people that show up to discredit the test
other forums do not have members who actively defend Windows Security to no end
they are not Windows Security echo chambers
MT certainly is and it is discussed on other forums

look up the definition of "echo chamber"... it does not mean that the only discussed or promoted is one single thing
however, it does mean that certain beliefs and opinions keep getting expressed and the group (the hive) will focus
around those beliefs and opinions - and well - that sure does happen here quite a bit when it comes to Windows
Security
so, yes, this place is a Windows Security echo chamber
 
Last edited:
  • Like
Reactions: ksgsystem
@manchesterunited I don't see anyone trying to discredit this test in this thread. I only see people wanting to understand how/why Windows Defender wasn't able to block those two samples. It's a good question. Understanding what happened here will hopefully give us and others insight on what needs to be improved in Windows Defender or what it is lacking.

I enjoyed this video.
 
@manchesterunited I don't see anyone trying to discredit this test in this thread. I only see people wanting to understand how/why Windows Defender wasn't able to block those two samples. It's a good question. Understanding what happened here will hopefully give us and others insight on what needs to be improved in Windows Defender or what it is lacking.

I enjoyed this video.

having knowledge about what needs to be improved - really there is nothing you can do about it
only Microsoft can fix Windows Security

I am talking about the trend of every single time there is a thread about Windows Security where it is shown in a poor light
there are certain individuals that run to those threads and always have something to say or suggest in a way that undermines the test
there are threads here that span many pages because of back-and-forth about the validity of tests involving Windows Defender
at this point there are many such instances of this behavior here at MT
the perception out there is that his place is a Windows Security echo chamber
and it is
 
Summary of video:

4:30 - Buran ransomware not blocked by Defender
  • Desktop items encrypted (Desktop was not added to Protected folders in this test).
  • Folders in the Protected folders list were safe/untouched.
8:15 - Jenkins ransomware not blocked by Defender
  • Jenkins ransomware runs in the background as the tester continues with the rest of the test.
  • 13:50 - Jenkins ransomware bypasses Controlled Folder Access and encrypts everything.
Thanks, was lazy to watch it :p

@manchesterunited you are badmouthing, WD is da best, and invincible, it locks the system while online, all those biased failure youtests and criticizing posts are part of a larger conspiracy orchestrated by sponsored agents of 3rd party vendors whose opinion doesn't matter because they knows nothing about coding!!!!
 
Thanks, was lazy to watch it :p

@manchesterunited you are badmouthing, WD is da best, and invincible, it locks the system while online, all those biased failure youtests and criticizing posts are part of a larger conspiracy orchestrated by sponsored agents of 3rd party vendors whose opinion doesn't matter because they knows nothing about coding!!!!

agents !

th.jpg


non-coders !

i-will-not-write-any-more-bad-code.gif


hah... we can code... even using laptops with dead batteries... get lost losers

th (1).jpg
 
  • HaHa
Reactions: RKRN3 and roger_m
Summary of video:

4:30 - Buran ransomware not blocked by Defender
  • Desktop items encrypted (Desktop was not added to Protected folders in this test).
  • Folders in the Protected folders list were safe/untouched.
8:15 - Jenkins ransomware not blocked by Defender
  • Jenkins ransomware runs in the background as the tester continues with the rest of the test.
  • 13:50 - Jenkins ransomware bypasses Controlled Folder Access and encrypts everything.
Exactly, perfect summary
 
Hi,
Thanks for testing. The Buran and Jenkins are interesting ransomware samples. It is really hard to test the WD Controlled Access feature, because most samples are detected/blocked by WD local signatures and cloud protection.
What was the last Windows Update on the tested machine?
If I correctly recall, the Buran ransomware depends on Windows exploits.
I am not sure about Jenkins ransomware. Is it related to the Jenkins servers vulnerabilities?
Do you know something more about those two ransomware samples?
:)(y)
Windows 10 is up to date, i forgot to show it on test.. jenkins detected by almost all famous av vendors not by defender