Jump to content

Recommended Posts

Posted

Hello all,

 

As many of you know, Windows Defender is included by default in Windows 10 and this scans for both Viruses as well as Malware. So my question is, is there any point installing/subscribing to a third party Anti-Virus solution, such as Sophos used by many LAs?

 

- It's installed/enabled by default

- Fully manageable via Group Policy - Computer Config > Admin Templates > Windows Components > Windows Defender

- Updates deployed managed via WSUS/SCCM

 

What are your thoughts on this?

Posted

I'd keep with Defender in all honesty (It's effectively the same as SCEP that comes with SCCM)

 

I tried Sophos on Windows 10 and found it to be a bugger of a thing.

Posted (edited)

I agree with @Gatt. Windows Defender has improved significantly in recent months in terms of protection so there's less of a need to buy third-party anti-virus software.

 

Microsoft's antivirus software sees massive improvement in tests

 

For the longest time, Microsoft's antivirus programs have brought up the rear in tests, usually ranking near or in dead last. But recent tests from two respected antivirus testers show Microsoft has greatly improved its antivirus product and in a very short time.

 

Germany's AV-Test Institute is something like Consumer Reports for antivirus software. It is the gold standard for AV software testing, and a good review from them can make your product a success. And for quite some time, Microsoft Security Essentials has been a laggard. But for the August tests, the scores improved.

 

AV-Test doesn't just grade on the ability to detect malware. It also grades based on how few false positives there are both in malware and in claiming legitimate apps are malware, as well as performance and whether or not the AV program slows down the system.

 

So the AV scores are broken down by a maximum of six points in three categories. In order to receive AV-Test certification, the product needs a total of at least 10 points and can't have a zero in any of the three criteria.

 

Of the 22 products rated in the month of August, only one, Bitdefender, scored a perfect 18 points. In July, Microsoft scored 9.5 points, so it didn't even make the AV-Test certification cutoff. This time, thanks to improved detection of new malware samples, Microsoft jumped to 14 points.

 

The improvement wasn't across the board. In the area of zero-day protection, MSE fell from 91% detection in July to 87% detection in August. The industry average was 98%, so in that regard, MSE is still a considerable laggard. But its detection of widespread malware discovered in the last four weeks got better, from 98% in July to 100% in August, putting Microsoft on par with the industry average.

 

In usability, like false positives and false warnings, Microsoft is equal to or, in the case of false detections of legitimate software as malware, it did better than the industry average.

 

It's an improvement, but there is still room for growth. The top performers were all in the 17-point range: Avira, BitDefender, F-Secure, McAfee, Kaspersky and Panda Security, the latter of which is a free product. Microsoft is still down with the also-rans, it's just not dead last anymore. So it's good to see MSE getting better, but it still is no replacement for the top AV products.

 

^ To improve Windows Defender's zero-day protection I would also install EMET.

 

Windows Defender dramatically improves antivirus protection scores

 

Providing some additional comfort to those who decide to rely on Windows Defender, another lab, Dennis Technology Labs, gave Microsoft’s offering AA rating in a recent test. That’s a very significant improvement from the failing grade received by Windows Defender the last time around.
Edited by Arthur
  • Thanks 3
Posted
I'm interested. Would you run your network without paid endpoint protection? I am a big fan of defender/essentials and do think the days of paying for these things is coming to an end but just need the proof.
Posted

Windows defender comes a distant bottom on virtually all detection tests. At the moment its a good extra but not good enough to be used on its own

ImageUploadedByEduGeek1444508365.120022.jpg

Posted

In AV-Test's latest test MSE/Defender is much better than it used to be, only let down by the zero-day protection score which could be mitigated by installing EMET or MBAE.

 

In the report (av-test.org/en/pdfreport/9235) Defender detected 100% of all malware samples and was better than the industry average in terms of performance and false positives.

 

http://vgy.me/t3o8Sh.jpg http://vgy.me/XqA2OD.jpg

 

I wonder if the zero-day protection score would improve if AV-Test actually performed their tests on 64-bit Windows 10 instead of 32-bit Windows 7? Microsoft have added a huge number of security-related features to the operating system since Windows 7 was released over six years ago. :confused:

  • Thanks 2
Posted

Regardless of which antivirus you choose, protection scores don't mean anything if the software is full of vulnerabilities itself. :(

 

Security wares like Kaspersky AV can make you more vulnerable to attacks « Ars Technica

 

Antivirus applications and other security software are supposed to make users more secure, but a growing body of research shows that in some cases, they can open people to hacks they otherwise wouldn't be vulnerable to.

 

The latest example is antivirus and security software from Kaspersky Lab. Tavis Ormandy, a member of Google's Project Zero vulnerability research team, recently analyzed the widely used programs and quickly found a raft of easy-to-exploit bugs that made it possible to remotely execute malicious code on the underlying computers. Kaspersky has already fixed many of the bugs and is in the process of repairing the remaining ones. In a blog post published Tuesday, he said it's likely he's not the only one to know of such game-over vulnerabilities.

 

"We have strong evidence that an active black market trade in antivirus exploits exists," he wrote, referring to recent revelations that hacked exploit seller Hacking Team sold weaponized attacks targeting antivirus software from Eset.

 

He continued: "Research shows that it’s an easily accessible attack surface that dramatically increases exposure to targeted attacks. For this reason, the vendors of security products have a responsibility to uphold the highest secure development standards possible to minimise the potential for harm caused by their software. Ignoring the question of efficacy, attempting to reduce one’s exposure to opportunistic malware should not result in an increased exposure to targeted attacks."

 

As Ormandy suggested, the bugs he found in Kaspersky products would most likely be exploited in highly targeted attacks, such as those the National Security Agency might carry out against a terrorism suspect or spies pursuing an espionage campaign might carry out against the CEO of a large corporation. That means most people are probably better off running antivirus software than foregoing it, at least if their computers run Windows. Still, the results are concerning because they show that the very software we rely on to keep us safe in many cases makes us more vulnerable.

 

Kaspersky: Mo Unpackers, Mo Problems « Google Project Zero Blog

 

Many of the reports I’ve filed are still unfixed, but Kaspersky has made enough progress that I can talk about some of the issues. One notable observation from this work was that some of the most critical vulnerabilities I’ve been submitting were simply too easy to exploit, and I’m happy to report that Kaspersky are rolling out some improved mitigations to resolve that.

 

Some of the bugs Kaspersky has already resolved include vulnerabilities parsing everything from Android DEX files and Microsoft CHM documents to unpacking UPX and Yoda’s Protector. We’ve sent dozens of reports to Kaspersky to investigate, any of which could result in a complete compromise of any Kaspersky Antivirus user.

Posted

At the Uni I work in we used to used McAfee on the desktops (Sophos on the Servers)

Until last year when we had a cryptolocker outbreak and found that McAfee had detected Cryptolocker, but let it through!

 

SCEP killed it as did Sophos. So we went with SCEP since we had just rolled out SCCM 2012 at the time

 

So far so good..

Posted
SCEP has been awesome for us, and since it's rollout with SCCM a few years ago we have had absolutely zero infections cause anything further than a "infection removed" message on SCCM's monitor.
Posted

It's interesting reading people's thoughts/ideas on this. I can remember with older versions of Windows that no firewall of any kind existed, so many of us installed the likes of Zone Alarm, but how many of us still install firewalls today, bearing in mind Windows has had its own since Windows XP SP2 switched on by default?

 

You could argue even the firewall in Windows 10 is probably not perfect, but certainly good enough for most purposes. I personally think that Windows Defender has also got to a point where it's good enough for most purposes... hence why else would Microsoft include it as standard?

  • 1 year later...
Posted
Sorry to raise an old thread. We are renewing our antivirus and are currently looking at our options and have been having a chat in the office about different solutions including Windows Defender. I was just wondering how people are finding it in 2017? My understanding of it was that it slowed down older hardware running Windows 10 so we have it turned off via Group Policy and currently use Sophos.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...