Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
AV-Test.org - Advanced Endpoint Protection: Fileless Threats Protection test - Sept19
#1
Quote:
[Image: avtest_logo_300_113.png]
The test is commissioned by Kaspersky and performed by AV-TESTGmbH. Date of the report: September27th2019All rights to the test results and the report belong to Kaspersky.

Executive Summary

In May 2019 AV-TEST performed a test of Fileless Threats Protection by different endpoint security products.In total 33 different fileless attacks, divided into four categories have been used to test 14products. The test aimed to reveal ability of the products to detect fileless threats (so to measure Detection Rate) and ability to Protect and Remediate all malicious actions by fileless threats (Protection Rate).

The test cases were created in-house by using well known frameworks and publicly well documented attacking techniques with intention to cover as much fileless techniques as possible.The used techniques included malware execution from WMI storage and via the Task Scheduler as well as Powershell and other scripts. Additionally, a false positive test was carried out. All tests were performed on Windows 10, with Microsoft Office installed.

During the test, the products were expected to detect the different attacks and prevent or remediate the malicious actions.The best Detection results were achieved by Kaspersky with a 100% detection rate while the average detection of all products was at 67.75%. The best Protection Rate of 94.12% was achieved again by Kaspersky while the average protection level of all products turned out 59.10%. 11 out of 14 products finished with zero False Positives in both Detection and Protection parts. For more detailed information refer to section ‘Test Results’ of the report.

The test results show that nowadays not all vendors are able to detect fileless threats and protect endpoint systems. Keeping in mind the proliferation of fileless techniques utilization from only targeted attacks to attacks onto regular users, we consider important for security vendors to improve their technologies significantly, no matter what they promise by their marketing.

No product results were excluded from the report to keep the security picture complete.   
Full PDF Report
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Messages In This Thread
AV-Test.org - Advanced Endpoint Protection: Fileless Threats Protection test - Sept19 - by harlan4096 - 10 October 19, 13:40

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
360 Total Security 11.0.0.1099
 11.0.0.1099 Apr 2...harlan4096 — 09:42
NVIDIA RTX Remix gets DLSS 3.5 Ray Recon...
Ray Reconstruction...harlan4096 — 09:30
Google Chrome 124.0.6367.118/.119
Google Chrome 124....harlan4096 — 09:29
Windows Repair Toolbox 3.0.4.0
An updated version...harlan4096 — 16:25
SecureAPlus 6.8.1
SecureAPlus 6.8.1:...harlan4096 — 16:22

[-]
Birthdays
Today's Birthdays
avatar (72)divinenews
avatar (49)plajhunTat
Upcoming Birthdays
avatar (26)akiratoriyama
avatar (46)Jerrycix
avatar (38)awedoli
avatar (80)WinRARHowTo
avatar (36)owysykan
avatar (47)beautgok
avatar (37)axuben
avatar (43)talsmanthago
avatar (29)mocetor
avatar (44)piomaibhaict
avatar (49)kingbfef
avatar (36)izenesiq
avatar (43)centfootadoni
avatar (38)ihijudu
avatar (43)tiojusop
avatar (40)Damiennug
avatar (38)acoraxe
avatar (47)contjrat
avatar (39)axylisyb
avatar (42)tukrublape
avatar (39)iruqi
avatar (40)saitetib
avatar (34)ypasodiny
avatar (37)omapek
avatar (46)Geraldtuh
avatar (42)knigiJow
avatar (44)1stOnecal
avatar (48)Mirzojap
avatar (34)idilysaju
avatar (43)xclubDum
avatar (39)Stewartanilm
avatar (42)nikitaxople
avatar (38)GregoryRog
avatar (43)mediumog
avatar (38)odukoromu
avatar (44)Joanna4589

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>