Legitimate and trusted software and built-in components in Windows are often used by cybercriminals to hide malicious activity. The so-called “Living off the Land Binaries” (LOLBin) are necessary for the proper functioning of the operating system. During a cyberattack, it can be difficult or impossible to block them, making them a very attractive method for malware developers. Below we present the most commonly used LOLBin in this edition of the test.
The following summary shows a comparison of tested solutions to protect workstations against malware. We encourage you to become familiar with a detailed description and read our testing methodology in order to understand the results.
PRE-LAUNCH: The classification concerns detecting malware samples before they are launched in the system.
POST-LAUNCH: The analysis level, i.e. a virus has been run and blocked by a tested product.
FAIL: The failure, i.e. a virus hasn’t been blocked and it has infected a system.
Sandbox Column: Number of indicators, i.e. malicious changes made to the system without the anti-virus installed.
Automatic Average Remediation Time (RT): The time expressed in seconds counted from the introduction of malware into the system by the browser, through the launch to the detecting and resolving a security incident.
Certificates are granted to solutions that are characterized by a high level of security, with a rating of at least 99% of blocked threats in the Advanced In-The-Wild Malware Test.
Our tests comply with the guidelines of the Anti-Malware Testing Standards Organization.
Details about the test are available at this website as well as in our methodology.
Blocked: 958/958
Total: 100%
RT: 7.2 seconds
Blocked: 957/958
Total: 99.9%
RT: 1.87 seconds
FAIL: 1
Blocked: 958/958
Total: 100%
RT: 167 seconds
Blocked: 958/958
Total: 100%
RT: 184 seconds
Blocked: 957/958
Total: 99.9%
RT: 2.2 seconds
FAIL: 1
Blocked: 958/958
Total: 100%
RT: 1.34 second
Blocked: 958/958
Total: 100%
RT: 54 seconds
Blocked: 958/958
Total: 100%
RT: 206 seconds
Blocked: 958/958
Total: 100%
RT: 33 seconds
Blocked: 958/958
Total: 100%
RT: 29 seconds
Blocked: 958/958
Total: 100%
RT: 48 seconds
Blocked: 958/958
Total: 100%
RT: 113 seconds
Blocked: 958/958
Total: 100%
RT: 69 seconds
Dive into our latest publication, dedicated to security test against malware. Uncover analyses, methodology, and results that provide invaluable insights into the latest edition of the Advanced In-The-Wild Malware Test.
You can always go back in time and check how each individual security product performed during previous editions of the test. We make the results from all previous tests available to you to verify if your favorite developer has improved protection against latest malware in his security software.