App Review Windows Defender vs Top 200 Ransomware (PC Security Channel)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
PC Security Channel

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,818
In the video Leo talks at length about the VMRay analysis of the malware. He shows in the analysis report how that malware uses multiple tactics, techniques, and procedures and Microsoft Defender does not detect them.

Any top AVs miss tenths of malware daily that use multiple tactics, techniques, and procedures. So, your argument is questionable.

Leo is good at what he does, but he is not exactly the best at explaining the points he is trying to make. Combine that with social media where people interpret whatever they read, view or hear in ways that are incorrect, and it is no surprise that there are those people who think Leo is the global leader of a conspiracy against Defender and Microsoft.

There is no conspiracy against Microsoft Defender. Leo's testing methodology is incorrect for all AVs. I usually discuss his tests related to Microsoft Defender, because I know it more thoroughly than other AVs.

You and I both know that testing behavioral detections is a complex subject, but there is sufficient proof available that Microsoft Defender behavioral detection is not one of its strengths. As a product feature, the behavioral detection is not the industry leading best nor is it the worst. Against certain types of threats it will be competitive with other solutions, but against other types of threats it will not do well.

I cannot prove or disprove the above.
Anyway, I could not agree with: "He is correct in that Defender has one of the weakest behavioral detection capabilities."

The real strength of Defender is that it can be combined with other Windows security features. The HUGE problem with that is that Microsoft intends that for managed endpoints, and not unmanaged home users.

With a few hardening tweaks (primarily default-deny), native Windows security quickly and easily surpasses the protection capabilities of all other default-allow security or security where the user has to make a decision.

I think so. :)
 
Last edited:

Vitali Ortzi

Level 30
Verified
Top Poster
Well-known
Dec 12, 2016
1,928
In the video Leo talks at length about the VMRay analysis of the malware. He shows in the analysis report how that malware uses multiple tactics, techniques, and procedures and Microsoft Defender does not detect them.

Leo is good at what he does, but he is not exactly the best at explaining the points he is trying to make. Combine that with social media where people interpret whatever they read, view or hear in ways that are incorrect, and it is no surprise that there are those people who think Leo is the global leader of a conspiracy against Defender and Microsoft. Still others claim he is an agent of a competitor. The negative viewpoints against Leo are unsubstantiated and so ridiculous that nobody with a shred of common sense can take them seriously.

If Leo made his demonstrations in-person where people were in front of him, and they could ask questions, and Leo could explain, then the interpretations made by people would be nothing like they are after watching his videos.

I quickly understood what Leo was saying about Defender's behavioral detections, but certainly most people missed it and just see the video as another "Here we go again... Leo hating on Microsoft Defender."

You and I both know that testing behavioral detections is a complex subject, but there is sufficient proof available that Microsoft Defender behavioral detection is not one of its strengths. As a product feature, the behavioral detection is not the industry leading best nor is it the worst. Against certain types of threats it will be competitive with other solutions, but against other types of threats it will not do well.

The real strength of Defender is that it can be combined with other Windows security features. The HUGE problem with that is that Microsoft intends that for managed endpoints, and not unmanaged home users.

With a few hardening tweaks (primarily default-deny), native Windows security quickly and easily surpasses the protection capabilities of all other default-allow security or security where the user has to make a decision.
You can definitely find a some av software even in enterprises that are weaker in their behavioral modules like watchguard and others
 

Szellem

Level 10
Verified
Well-known
Apr 15, 2020
457
Any top AVs miss tenths of malware daily that use multiple tactics, techniques, and procedures. So, your argument is questionable.



There is no conspiracy against Microsoft Defender. Leo's testing methodology is incorrect for all AVs. I usually discuss his tests related to Microsoft Defender, because I know it more thoroughly than other AVs.



I cannot prove or disprove the above.
Anyway, I could not agree with: "He is correct in that Defender has one of the weakest behavioral detection capabilities."



I think so. :)
I agree with what you wrote. I am not as expert as you, but I can understand what you write and say. Leo never tested correctly. He's a youtuber for a living, who eviscerates the Defender on a regular basis. His tests make no sense.
On the other hand, it's not cool here on the forum for someone to come on with their soundbite, seemingly knowledgeable posts and try to sound smart. I don't mean you.
I like to read the real knowledgeable people here (ie: you Andy) because I always learn something new and sensible.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top