MRG Effitas 360 Degree Assessment & Certification Q4 2020

Discussion in 'other anti-virus software' started by waking, Mar 19, 2021.

  1. waking

    waking Registered Member

    Joined:
    Jan 25, 2016
    Posts:
    176
    MRG Effitas 360 Degree Assessment & Certification Q4 2020

    https://www.mrg-effitas.com/wp-content/uploads/2021/03/MRG_Effitas_360_2020Q4.pdf
     
  2. Charyb

    Charyb Registered Member

    Joined:
    Jan 16, 2013
    Posts:
    679
    On page 19 at the bottom of the performance test results it mentions that Malwarebytes was impacted due to unnecessary components enabled. Has anyone stumbled across what these unnecessary components are? I skimmed through the text and did not find the answer.
     
  3. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    Quote by Pedro Bustamante from Malwarebytes.

    MRG Effitas - MRG Effitas 360 Degree Assessment & Certification Q4 2020 | Page 2 | MalwareTips Community
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    A couple of things that I noticed is that Win Defender did pretty good but it couldn't block all malware. It did however block 100% of the financial malware and ransomware samples. It also blocked all of the exploit/fileless malware samples. I was also surprised by the good performance of Malwarebytes. And I wonder how the heck Sophos Intercept X failed to block the financial malware simulator.
     
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Note that WD ATP was tested w/all ASR rules enabled:
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    So you're saying that it would have probably failed to block the exploit/fileless samples? But from what I understood, with certain tools you can enable this setting for Win Defender AV, is this correct?
     
  7. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    WD ASR rules can be enabled various ways depending on which OS version you're using: https://docs.microsoft.com/en-us/wi...-defender-atp/enable-attack-surface-reduction . In Win 10 Home, the only option available is manually via PowerShell use: https://docs.microsoft.com/en-us/wi...fender-atp/customize-attack-surface-reduction . Use can also use ConfigureDefender: https://github.com/AndyFul/ConfigureDefender to enable ASR rules.
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    OK thanks, I still think it's weird that these settings aren't standard available in Win 10 Home.
     
  9. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    The answer is simple. WD ASR rules will block whatever activity they are monitoring. This in turn could block some legit apps. MS assumes that ASR rule application is being done by system admins. that know what they are doing and the implications of what they are doing.
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    OK I see, this makes sense. However, these settings should still be available for experienced users.
     
  11. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    o_O They are. Via PowerShell and Group Policy use.

    Also remember that WD is a "Band-Aid" product with many features not accessible via an integrated GUI as is the case for third party AV vendors.
     
  12. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I meant that it should be as easy as with certain third party tools that give access to these extra protection features. I don't want to mess around with PowerShell and Group Policy. In fact, I had to reset Win 10 because some PowerShell command broke all UWP apps.
     
  13. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Then use ConfigureDefender and set it to "MAX" setting and you're done:
    https://github.com/AndyFul/ConfigureDefender

    If your need further opinions on ConfigureDefender, go to Malwaretips where it is discussed extensively.
     
    Last edited: Apr 5, 2021
  14. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    That's the thing I didn't like it, I'm very picky when it comes to the GUI.
     
  15. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    It's a freebie. "Beggars can't be chosers."
     
  16. Azure Phoenix

    Azure Phoenix Registered Member

    Joined:
    Nov 22, 2014
    Posts:
    1,560
    Did you talked with Andy about what you want to change?
     
  17. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Well I actually can, so I chose not to use it.

    No, I just don't think it's smooth looking, I doubt he will redesign it just because one guy doesn't like it. I never use apps that don't look good.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.