AV-Comparatives: Anti-Tampering Certification Test
#1
Bug 
Quote:
[Image: avc-logo.png]

AV-Comparatives has published the results of the Anti-Tampering Certification Test on its website, complete with detailed information about the methodology and criteria used in the evaluation. Each year, AV-Comparatives offers a focus test, allowing vendors to apply for certification. This year, the emphasis was on “Defense Evasion” (Anti-Tampering). Both vendors and customers are encouraged to review the results and use them to make informed decisions regarding cybersecurity solutions.

https://www.av-comparatives.org/news/ant...tion-test/
 
After compromising a system within the targeted network, attackers often must contend with endpoint security products such as traditional antivirus or next-generation antivirus and endpoint detection and response (EDR) products. EDR products can be particularly problematic for tactics, techniques, and procedures (TTPs) such as credential dumping and lateral movement. Even if an attacker has already gained privileged user access (e.g., local admin), most endpoint security products can still pose significant challenges. As a result, attackers will attempt to disable or modify tools and remove key capabilities from endpoint security products to permanently avoid the risk of prevention or detection.

The AV-Comparatives Anti-Tampering Certification Test plays a vital role in the fight against tampering, ensuring that products can be trusted by consumers and are not compromised by malicious software. This certification also allows vendors to differentiate themselves by demonstrating that their products are tamper-proof to the extent tested.

This evaluation includes techniques to disable or modify user space and/or kernel space components of a product by attempting to tamper with, disable, or modify processes, threads, services, DLLs, agents, file systems, kernel drivers, and other components such as update services.
...
Full Report
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Firefox Browser 149.0.2
149.0.2 Firefox Re...harlan4096 — 07:52
Tor Browser 15.0.9
Tor Browser 15.0.9...harlan4096 — 07:50
Report: Windows has a new 0-day vulnerab...
The next Windows P...harlan4096 — 07:48
Microsoft Begins Automatic Windows 11 25...
Microsoft has begu...harlan4096 — 07:47
Linux Kernel 7.1 Moves to Drop i486 Supp...
A patch proposed b...harlan4096 — 07:46

[-]
Birthdays
Today's Birthdays
avatar (39)vemedProkbior
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (38)RobertUtelt
avatar (36)Kiran78

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>