AV-Comparatives: Anti-Tampering Certification Test
#1
Bug 
Quote:
[Image: avc-logo.png]

AV-Comparatives has published the results of the Anti-Tampering Certification Test on its website, complete with detailed information about the methodology and criteria used in the evaluation. Each year, AV-Comparatives offers a focus test, allowing vendors to apply for certification. This year, the emphasis was on “Defense Evasion” (Anti-Tampering). Both vendors and customers are encouraged to review the results and use them to make informed decisions regarding cybersecurity solutions.

https://www.av-comparatives.org/news/ant...tion-test/
 
After compromising a system within the targeted network, attackers often must contend with endpoint security products such as traditional antivirus or next-generation antivirus and endpoint detection and response (EDR) products. EDR products can be particularly problematic for tactics, techniques, and procedures (TTPs) such as credential dumping and lateral movement. Even if an attacker has already gained privileged user access (e.g., local admin), most endpoint security products can still pose significant challenges. As a result, attackers will attempt to disable or modify tools and remove key capabilities from endpoint security products to permanently avoid the risk of prevention or detection.

The AV-Comparatives Anti-Tampering Certification Test plays a vital role in the fight against tampering, ensuring that products can be trusted by consumers and are not compromised by malicious software. This certification also allows vendors to differentiate themselves by demonstrating that their products are tamper-proof to the extent tested.

This evaluation includes techniques to disable or modify user space and/or kernel space components of a product by attempting to tamper with, disable, or modify processes, threads, services, DLLs, agents, file systems, kernel drivers, and other components such as update services.
...
Full Report
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
NanaZip 6.0 Update 7 (6.0.1711.0)
NanaZip 6.0 Update...harlan4096 — 06:10
Vivaldi 7.9 Build 3970.64
Vivaldi 7.9 Build ...harlan4096 — 06:09
Thunderbird 150.0.2 & Thunderbird 140.10...
Thunderbird 150.0....harlan4096 — 06:08
Brave v1.90.121 (Chromium 148.0.7778.96)
Release v1.90.121 ...harlan4096 — 06:07
QOwnNotes
26.5.6 Note folde...Kool — 06:07

[-]
Birthdays
Today's Birthdays
avatar (39)omapek
avatar (48)Geraldtuh
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (38)owysykan
avatar (49)beautgok
avatar (39)axuben
avatar (45)talsmanthago
avatar (31)mocetor
avatar (46)piomaibhaict
avatar (51)kingbfef
avatar (38)izenesiq
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (41)axylisyb
avatar (44)tukrublape
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>