App Review Windows Defender vs Ransomware in 2022

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
The PC Security Channel

Jan Willy

Level 12
Verified
Top Poster
Well-known
Jul 5, 2019
565
MS Defender just gained confidence. See:
Now it seems I can't trust it anymore. ;)
 

Kongo

Level 36
Thread author
Verified
Top Poster
Well-known
Feb 25, 2017
2,504
Screenshot 2022-07-20 220755.jpg

:eek: @Andy Ful
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,142
MS Defender just gained confidence. See:
Now it seems I can't trust it anymore. ;)
Leo knows it. He was surprised that one sample managed to compromise the Defender's online protection.
Anyway, the AV-Test test is very different from this presentation. Here is an important difference:

[..] All the products have to successfully defend against ransomware in 10 real-life scenarios under Windows 10. The test involves threats such as files containing hidden malware in archives, PowerPoint files with scripts or HTML files with malicious content.

[..] The following images show the performance of Defender for home users in the 10 tested scenarios. Defender was able to detect the infection in the very first initial access phase in all but one case.

The above fragments are from the AV-Test. They mean that Defender was able to stop the ransomware attacks in the real-life scenario by blocking the attacks mostly at the initial stage. This usually happens when the malicious or suspicious actions of the weaponized documents, scripts, etc. are detected/blocked before the ransomware executable could be delivered or executed. In Leo's test, the initial stage is skipped, because such tests are not related to the real-life scenario. The tests with many EXE files cannot be interpreted in the context of real life - they are more appropriate for the Enterprise scenario when the environment is already compromised and ransomware is delivered/executed by another malware.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top