Hier haben wir die Struktur der folgenden Produktbewertungen für jedes der Programme in diesem Test skizziert. Für die Unternehmensprodukte haben wir ein etwas anderes Testformat verwendet, das eine kurze Produktzusammenfassung und Abschnitte über die Cloud-basierte Verwaltungskonsole (z.B. dashboard, host management, detections, policies, investigation) sowie den Endpunktschutz-Client (z.B. deployment, general handling, alerts) umfasst. Zusammenfassung: Wir beschreiben kurz die Art des Produkts und heben ausgewählte Schlüsselaspekte hervor, z.B. ob es kostenlos oder kostenpflichtig ist, wichtige Sicherheitsfunktionen und unsere allgemeinen Erfahrungen mit dem Produkt. Bitte beachten Sie, dass alle Produkte auf die gleiche Weise vor Ransomware schützen wie vor anderen Arten von Malware. Wenn wir ausdrücklich von "Ransomware-Schutz" sprechen, bedeutet dies, dass bestimmte Benutzerordner überwacht werden, um unbefugte Änderungen zu verhindern. Installation, Einrichtung und Deinstallation: Wir beschreiben, wie Sie das Produkt auf Ihrem Mac zum Laufen bringen, beginnend mit dem Herunterladen des Installationsprogramms und endend mit allen Aufgaben, die nach der Installation anfallen, wie z. B. die Installation und Aktivierung von Browser-Erweiterungen. Wir halten fest, welche Optionen zur Verfügung stehen und ob Sie während der Installation irgendwelche Entscheidungen treffen müssen. Es gibt auch einen Hinweis darauf, wie Sie das Produkt bei Bedarf deinstallieren können. Bitte beachten Sie, dass es bei der Installation eines Antivirenprodukts unter macOS Sequoia (das für die Tests und Bewertungen verwendet wurde) notwendig ist, in die macOS-Systemeinstellungen zu gehen und die Systemerweiterungen des Programms zu aktivieren sowie dem Programm bestimmte Berechtigungen zu erteilen, z. B. Benachrichtigungen oder vollen Festplattenzugriff. Da dieser Vorgang bei allen Produkten im Wesentlichen identisch ist, haben wir ihn in den einzelnen Testberichten nicht erwähnt. Allgemeine Handhabung und wesentliche Merkmale: Wir prüfen, wie einfach die wichtigsten Funktionen zu finden sind: Schutzstatus, verschiedene Scan-Optionen, Schutzfunktionen, Quarantäne, Abonnementinformationen (gilt nicht für kostenlose Programme), Update, Einstellungen und Hilfe. Schutz: We describe the available scan options, including smart/full/custom scan, external storage scan, and scheduled scans, how and where to trigger them, and briefly mention any special detection settings that are enabled by default, e.g., detection of potentially unwanted applications (PUA) or stalkerware. We might also give additional information about third-party detection engines and other relevant malware protection features, such as browser/email/ransomware protection. Warnhinweise: Wir sehen uns an, wie der aktuelle Schutzstatus angezeigt wird, welche Art von Warnung angezeigt wird, wenn der Echtzeitschutz oder eine andere Schutzfunktion deaktiviert ist, und wie dies korrigiert werden kann. Wir beachten auch, welche Art von Warnung angezeigt wird, wenn Malware entdeckt wird, und ob in diesem Fall etwas unternommen werden muss. Quarantäne und Protokolle: Wir prüfen die Funktionen, die Ihnen anzeigen, welche bösartigen Objekte gefunden wurden, welche Informationen über sie bereitgestellt werden und welche Maßnahmen zu ihrer Beseitigung ergriffen werden können. Falls im Programmfenster verfügbar, notieren wir auch die Arten von Daten und Ereignissen, die vom Programm protokolliert werden. Erweiterte Optionen: Wir prüfen, ob nur Benutzer mit einem macOS-Administrator-Account die Schutzfunktionen deaktivieren, das Programm deinstallieren oder Objekte aus der Quarantäne wiederherstellen/löschen können. Wir halten es für ideal, wenn nur Administratoren (nicht normale macOS-Benutzer) zumindest die ersten beiden Aufgaben ausführen können.
Zusammenfassung
Avast One Free for Mac is a free antivirus product aimed primarily at non-expert users. It provides essential security features, including a basic email guard and an AI assistant for scam checking. Some of its key aspects are:
- Simple installation and setup of core features.
- Clearly structured interface for easy navigation.
- Multiple scan options and settings, including scheduled and external storage scans.
- Clear and persistent alerts that keep users informed of detected issues.
- Administrative Sicherheitsvorkehrungen zur Verhinderung unbefugter Änderungen.
Please note that Avast, like AVG and Norton, is a product of Gen Digital. These products share identical core functionality, though there are some differences in their user interfaces.
Installation, Einrichtung und Deinstallation
The program is installed by downloading and running the installer file from the vendor’s website. The setup process walks the user through each step with brief on-screen explanations. The program can be uninstalled via the macOS menu bar or by running the Avast One Uninstaller direkt in dem macOS-Programmordner starten.
Allgemeine Handhabung und wesentliche Merkmale
The main program window displays the current Protection status, alongside access to Smart scan, core Protection features (Kostenloses Antivirus), and additional tools for quick system check-ups. The Quarantine and other security-related components (e.g., Mail Shield, Traffic Monitor, Network Inspector) can be found under Kostenloses Antivirus. Settings (Preferences) sind über das Programmmenü oder die macOS-Menüleiste zugänglich. Subscription information is not applicable, as the program is free. Manual Updates kann durch Klicken auf Check for Updates under the system tray icon or program name in the macOS menu bar. Online Help ist verfügbar über die Help menu, which directs users to the vendor’s support resources.
Protection
Über Scan Center auf der Kostenloses Antivirus Seite können die Benutzer intelligente Scans, Tiefenscans covering all drives and system memory, externe Speicherscans für angeschlossene Geräte, oder gezielte Scans of specific files and folders, and set up Scheduled scans. Targeted scans can also be initiated from the Finder context menu. Detection behaviours and Scan exceptions are configurable under Preferences; detection of PUA is enabled by default. Web protection is provided by the integrated Web Guard, which scans web traffic in real time to block malicious websites, downloads, and scripts. The Mail Shield scans emails of specified mail accounts for suspicious content; in the free version, this is limited to mail applications installed locally on the Mac, such as Apple Mail, Microsoft Outlook, and Mozilla Thunderbird. The Traffic Monitor provides an overview of data transmission across applications, including the geographic locations of connected servers displayed on an interactive map. Users can submit content, including text messages, links, or images, to the AI-powered Avast Assistant directly from within the program to check for potential scams.
Alerts
Wenn der Echtzeitschutz (File Shield) or other core shields (Mail Shield, Web Guard) unter Kostenloses Antivirus are disabled, Avast displays a persistent alert in the main program window. Protection can be re-enabled by clicking the Turn On entfernen.
When malware was detected during the protection test, an alert window appeared as shown below. No user action was required, and the alert persisted until manually closed. Multiple detections are consolidated into a single alert window, navigable via on-screen arrows. Expanding the details section at the bottom of the alert displays further information, including the threat name, severity, file name/path, and associated process.
Quarantine & Logs
The quarantine is accessible from the Kostenloses Antivirus page and lists all isolated threats, along with details such as the threat name, file name/path, and detection date. Users can delete items or restore them with administrative privileges.
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Kostenloses Antivirus).
- Uninstalling the program.
- Deleting and restoring items from quarantine.
Werbung
The program promotes additional paid applications (e.g., Cleanup, VPN, Breach Guard) and displays in-app messages notifying users of flagged issues, such as ransomware vulnerability, network threats, and fake websites. When users attempt to address these issues, Avast presents an offer to upgrade to Avast Premium Sicherheit. If the initial offer is declined, a follow-up prompt appears offering a 60-day free trial of the paid product. Upgrade options may also appear within detection alerts.
Zusammenfassung
AVG AntiVirus Free for Mac is a free antivirus solution aimed primarily at non-expert users. It provides a straightforward setup process, a clearly structured interface, and malware protection. Some of its key aspects are:
- Simple installation and setup of core features.
- Tile-based interface for easy navigation.
- Multiple scan options and settings, including scheduled and external storage scans.
- Clear and persistent alerts that keep users informed of detected issues.
- Administrative Sicherheitsvorkehrungen zur Verhinderung unbefugter Änderungen.
Please note that AVG, like Avast and Norton, is a product of Gen Digital. These products share identical core functionality, though there are some differences in their user interfaces.
Installation, Einrichtung und Deinstallation
The program is installed by downloading and running the installer file from the vendor’s website. The setup process walks the user through each step with brief on-screen explanations. The program can be uninstalled via the macOS menu bar or by running the AVG AntiVirus Uninstaller direkt in dem macOS-Programmordner starten.
Allgemeine Handhabung und wesentliche Merkmale
The main program window displays the current Protection status an prominenter Stelle, neben dem schnellen Zugang zu Smart scan, weiterer scan options (Run Other Scans), und protection feature tiles (Computer, Web & E-Mail). Die Website Quarantine is accessible under Computer, und Settings (Preferences) are available via the program menu or the macOS menu bar. Subscription information is not applicable, as the program is free. Virus definition Updates can be initiated manually by clicking Virus-Definitionen on the home page, or via Check for Updates under the system tray icon or the program name in the macOS menu bar. Online Help is accessible through the Help menu, which directs users to the vendor’s support resources.
Protection
Über Run Other Scans on the home page, users can initiate intelligente Scans, Tiefenscans covering all drives and system memory, externe Speicherscans für angeschlossene Geräte, oder gezielte Scans of specific files and folders. The latter can also be launched from the Finder context menu. Scheduled scans and detection behaviours are configurable under Preferences; detection of PUA is enabled by default. Web protection is provided by the integrated Web Shield, which scans web traffic in real time to block malicious websites, downloads, and scripts.
Alerts
Wenn der Echtzeitschutz (File Shield) unter Computer, web protection (Web Shield), or email protection under Web & E-Mail is disabled, AVG displays a persistent alert in the main program window. To re-enable a protection feature, users must navigate to the respective menu tile and turn it back on manually.
When malware was detected during the protection test, an alert window appeared as shown below. No user action was required, and the alert remained visible until manually closed. Multiple detections are consolidated into a single alert window, navigable via on-screen arrows. Expanding the details section at the bottom of the alert displays further information, including the threat name, severity, file name/path, and associated process.
Quarantine & Logs
Die Quarantäne ist zugänglich über Computer on the home page and lists all isolated threats, along with details such as the threat name, file name/path, and detection date. Users can delete items or restore them; the latter requires administrative privileges.
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Computer und Web & E-Mail).
- Uninstalling the program.
- Restoring items from quarantine.
Werbung
The application displays in-app messages notifying users of flagged issues, such as ransomware vulnerability, network threats, and fake websites. When users attempt to address these issues, AVG presents an offer to upgrade to AVG Internet Security. If the initial offer is declined, a follow-up prompt appears offering a 60-day free trial of the paid product. Upgrade options may also appear within detection alerts.
Zusammenfassung
Bitdefender Antivirus for Mac is a paid antivirus product that includes malware protection, a custom VPN, browser security extensions, and chat protection for popular messaging applications. It is suited to both novice and advanced users. Some of its key aspects are:
- Straightforward installation and setup of core features.
- Well-structured interface providing access to all features.
- Multiple scan options, including automatic external storage scans, ransomware protection, a data-limited VPN, browser protection addons, and chat protection for popular messaging apps (e.g., macOS Messages, WhatsApp, Telegram).
- Clear alerts that keep users informed of detected issues.
- Administrative Sicherheitsvorkehrungen zur Verhinderung unbefugter Änderungen.
Installation, Einrichtung und Deinstallation
To install the program, the user must log into their Bitdefender account at central.bitdefender.com and download the installer file. Once the installer is launched, the setup wizard guides the user through each step. After installation, users are prompted to create or sign in to a Bitdefender account. An optional tour introduces the key features, and the program recommends enabling app notifications in the macOS system settings, installing the browser extension (Traffic Light), die Konfiguration des Ransomware-Schutzes (Safe Files), die Einrichtung von Time Machine Protection, and initiating a system scan. The interface supports macOS dark and light modes. The program can be uninstalled via the Bitdefender Uninstaller im macOS-Programmordner zu finden.
Allgemeine Handhabung und wesentliche Merkmale
Die Dashboard displays the current Protection status and provides access to scan options (Quick Scan und System Scan), Protection features, Settings, Subscription Information (My Account), und Help Ressourcen. Die Website Quarantine und Scan exceptions befinden sich unter Protection. Handbuch Updates kann von Actions menu in the macOS menu bar. The Privacy section includes the data-limited Bitdefender VPN und den Anti-Tracker browser extension. A PDF user manual and online support are accessible via Help. The user manual is dated November 2022 and may not reflect features introduced in subsequent updates, such as Chat Protection. Bitdefender should consider revising this document accordingly.
Protection
Von dem Protection Menü können Benutzer eine Quick scan of critical system areas, a System scan covering all files and folders, or a Custom Scan targeting specific files or folders. The latter can also be initiated from the Finder context menu. External storages are automatically scanned when connected to the Mac. Web protection is provided through the Traffic Light browser extension, which is compatible with Safari, Chrome, and Firefox, and adds safety ratings to search engine results. The ransomware protection feature monitors user-specified folders and Time Machine backups for unauthorised changes. The Chat Protection feature monitors conversations in macOS Messages, WhatsApp, Facebook Messenger, Telegram, Discord, and LinkedIn for malicious links and scam content. Depending on the application, protection is available either in the native app, in the browser, or both. Detection behaviours and protection settings are configurable under Settings.
Alerts
Wenn der Echtzeitschutz über Settings or the system tray icon in the macOS menu bar, Bitdefender displays a persistent alert on the main program window. Protection can be re-enabled by clicking the Enable entfernen.
When malware was detected during the protection test, an alert window appeared as shown below. No user action was required, and the alert remained visible until manually closed. Multiple detections are consolidated into a single alert window, navigable via on-screen arrows. Expanding the details section at the bottom of the alert displays further information, including the threat name, severity, file name/path, and associated process.
Quarantine & Logs
Die Quarantine lists all isolated threats with details including the threat name, file name, and detection date. Deleting and restoring quarantined items requires administrative privileges. The Notifications page logs events such as signature updates, component activations, and malware detections; entries can be filtered by severity level (Critical, Warning, Information).
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Settings).
- Uninstalling the program.
- Deleting and restoring items from the quarantine.
Zusammenfassung
CrowdStrike Falcon Enterprise is an enterprise-grade endpoint security solution for medium to large organisations. It provides centralised, cloud-based management, advanced detection and response capabilities, and real-time protection through a lightweight endpoint protection client. Some of its key aspects are:
- Well-structured cloud console with access to granular details.
- Ermittlungsfunktionen für die Analyse von Angriffen und die Reaktion auf Vorfälle.
- Advanced search capabilities for threat hunting and correlation.
- Containment-Funktion zur Isolierung gefährdeter Endpunkte.
- User-level alerts on endpoints and prioritised threat notifications for administrators.
Management Console
The cloud console is navigable via the menu in the top-left corner, providing access to all EDR/XDR functions ranging from incident response, threat detection and remediation, and forensic analysis to endpoint administration, policy management, and reporting. Pages can be bookmarked for quick navigation via the Bookmarks section using the icon beside each page title. The most relevant sections and pages are described below.
Endpoint Security > Activity Dashboard page
The landing page displays key threat metrics in large panels, including a list of recent detections categorised by severity and detection method (Tactic & Technique), SHA-based detections, prevented malware by host, a monthly bar chart of detections by tactics, and several OverWatch statistics reflecting managed threat hunting activity by OverWatch analysts within the organisation’s environment and across all CrowdStrike customers. All dashboard items are clickable and redirect to the relevant detail pages with the respective filters applied.
Counter Adversary Operations > OverWatch
Falcon OverWatch is a managed threat hunting service operated by a dedicated team of CrowdStrike analysts, which proactively and continuously searches for sophisticated adversary activity. When potential threats are identified, designated administrators receive email notifications with remediation guidance. The OverWatch Home und OverWatch Hunting Leads pages provide visibility into OverWatch activity and investigated detections within the organisation’s environment over the preceding 30 days, as well as global trends in intrusions by adversary category, industry, and MITRE ATT&CK tactics, techniques, and procedures (TTPs).
Endpunktsicherheit > Seite Endpunkt-Erkennungen
This page provides granular control for analysing detections. Administrators can filter detection entries using a wide range of parameters, including severity, tactic, technique, date and time, host, and more. Selecting an entry opens a comprehensive timeline alongside a details panel, from which key actions can be taken, such as editing the detection status, assigning a user for remediation, immediately containing the affected host, initiating investigation tasks, and accessing the full detection details page. The detection details page presents information across five views. The Details view includes general detection and host information, prevention actions taken, quarantined files, network indicators, associated file hashes, commands and executables involved, a status log, and additional context such as host vulnerabilities or misconfigurations, and indicators of compromise (IOCs). The Process Table, Process Tree, und Process Graph present associated processes in tabular form or as an interactive tree or graph, where entries and nodes can be inspected for details on network, files, disk operations, and command-line history. The Zeitleiste der Ereignisse lists all relevant events in chronological order.
Endpoint Security > Seite für unter Quarantäne gestellte Dateien
Quarantined items are listed with metadata including timestamp, file name, hostname, logged-on user, and status. Administrators can release, delete, or download files in password-protected archives. Clicking on an entry opens a panel with additional information such as file path, file hash, detection method, and severity. Filters are available to narrow results for faster triage.
Seite Endpoint Security > Präventionsrichtlinien
This page allows administrators to create and configure prevention policies across supported platforms, defining how endpoint protection clients detect and respond to threats. For macOS, configurable components include Sensor Capabilities, Sensor Visibility, Next-Gen Antivirus (On Write, Quarantine, Cloud Machine Learning, Sensor Machine Learning), Malware Protection (Execution Blocking), and Behaviour-Based Prevention (Unauthorised Remote Access IOAs, Credential Dumping IOAs). Machine learning components have adjustable sensitivity levels, ranging from Disabled bis Extra Aggressiv. Custom host groups and indicators of attack (IOA) rule groups can be assigned per policy; a policy hierarchy determines which one takes precedence.
Host-Setup und -Verwaltung > Seite Host-Verwaltung
All registered endpoints are listed here, with customisable columns displaying attributes such as hostname, status, OS version, IP addresses, sensor version, and assigned policies. Clicking on an entry opens the details panel, and advanced filtering allows administrators to search for specific systems.
Investigate section
This area provides forensic investigation and threat hunting capabilities. Administrators can search for hosts, events, users, file hashes, IP addresses, and activities related to detections or files. Additional tools include host and process timelines, as well as reports on remote access and geolocation activity.
Endpoint Protection Client
Deployment
The recommended method is to deploy the Falcon Sensor via an MDM server using a configuration profile supplied by CrowdStrike, which streamlines deployment and avoids manual authorisation steps on endpoints. Alternatively, standalone installers can be used for manual setup. Sensor packages are downloadable under Host Setup and Management > Sensor Downloads, wobei mehrere ältere Versionen aus Kompatibilitätsgründen verfügbar sind. Der Installationsprozess umfasst eine schrittweise Anleitung für die lokale Einrichtung.
Allgemeine Handhabung
The Falcon Sensor runs with a minimal interface, displaying only status information. Administrative interaction is conducted via the falconctl Befehlszeilen-Dienstprogramm. Beispielhafte Befehle sind falconctl stats for sensor information and statistics, and falconctl uninstall for removal. With the settings used for the protection test, detected threats are quarantined in situ rather than deleted.
Alerts
When malware was detected during the protection test, an alert appeared as shown below, providing minimal information about the detection and action taken. No user action was required, and the alert closed automatically after a few seconds.
Zusammenfassung
ESET Home Security Essential is a paid, cross-platform security subscription that delivers malware protection on macOS through ESET Cyber Security. The product is managed and deployed via the ESET HOME web portal. Some of its key aspects are:
- Straightforward installation and setup of core features.
- Clearly structured interface providing access to all core features.
- Multiple scan options, including scheduled and external storage scans.
- Clear alerts that keep users informed of detected issues.
- Administrative Sicherheitsvorkehrungen zur Verhinderung unbefugter Änderungen.
Installation, Einrichtung und Deinstallation
To install the program, users must log into their ESET HOME account at home.eset.com and download the installer. The setup wizard guides the user through each step with on-screen instructions. The program can be uninstalled by re-running the installer and clicking Uninstall, or via the Deinstallationsprogramm found under ESET Cyber Security > Contents > Helpers in the macOS Applications folder.
Allgemeine Handhabung und wesentliche Merkmale
The main program window is divided into several sections providing quick access to the Protection status (Überblick), scan options (Scan), Protection features (Protections), und Subscription Information (Help & Support). Die Website Quarantine is accessible under Tools., and manual Updates can be initiated via Update. Online Help is available via Help & Support or the Help Menü einzeln oder alle zusammen ausgewählt und aus der Liste der erkannten Bedrohungen gelöscht oder wiederhergestellt werden. Settings can be accessed via the macOS menu bar.
Protection
Über Scan, users can perform a System scan of all local drives or a Custom Scan targeting specific files and folders. Scheduled scans (Planer) und Scan exceptions (Detection Exclusions) are configurable under Settings. Further options allow for extensive configuration of alert, update, logging, and detection behaviours, including externe Speicherscans and device control, both disabled by default. PUA detection can be enabled during program setup, which is the recommended option. Under Protections, the program also provides web and email protection (Web and Email) und eine Firewall (Network Access), with customizable URL lists and app rules. The Applications Seite unter Tools. gives information on installed applications and system processes, including whether inbound/outbound network traffic is permitted, the current status, a reputation score, and current/total internet usage.
Alerts
If real-time or web protection is disabled via Protections oder Settings, ESET displays a persistent alert in the main program window. Protection can be re-enabled by clicking the Enable Link.
When malware was detected during the protection test, an alert appeared as shown below, displaying the threat name, file name, and action taken. No user action was required, and the alert closed automatically after a few seconds.
Quarantine & Logs
Die Quarantine lists all isolated threats with details such as the threat name, file name, detection date/type, reason, and file size. Users can delete and restore items with administrative privileges. The Logs Files Seite unter Tools. records security events with detailed metadata; entries can be filtered by category such as Detections, Computer Scan, Filtered Websites, and Firewall.
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Protections oder Settings).
- Uninstalling the program.
- Accessing, deleting, and restoring items from quarantine.
- Accessing log files.
- Changing program settings.
Zusammenfassung
Intego ONE Complete is a paid Mac security application that consolidates malware protection, a firewall, system optimisation (SmartClean), and a VPN into a single interface. Features available depend on the plan purchased. Some of its key aspects are:
- Simple installation and setup of core features.
- Unified interface providing access to all components in one place.
- Multiple scan options, including scheduled and external storage scans.
- Clear and persistent alerts that keep users informed of detected issues.
- Administrative Sicherheitsvorkehrungen zur Verhinderung unbefugter Änderungen.
Installation, Einrichtung und Deinstallation
To install the program, the user must log into their Intego account at account-v2.intego.com, download the installer file, and run it on their Mac. The setup wizard guides the user through each step with brief explanations. The interface supports macOS dark and light modes. The program can be uninstalled by selecting Uninstall auf der Help Menü einzeln oder alle zusammen ausgewählt und aus der Liste der erkannten Bedrohungen gelöscht oder wiederhergestellt werden.
Allgemeine Handhabung und wesentliche Merkmale
The main program window displays the current Protection status and provides access to all core components (Antivirus, Firewall, VPN, and SmartClean) and Settings. A ONE Scan can be started from the home page, which performs a combined protection and system performance check. Quarantine (Quarantined Files) und Scan exceptions (Safe List) are accessible within the Antivirus sehen. Updates can be initiated via Check for Updates in the macOS menu bar or from Settings. Subscription information is accessible via the profile icon in the top-right corner of the program window and online Help resources are available via the Help Menü einzeln oder alle zusammen ausgewählt und aus der Liste der erkannten Bedrohungen gelöscht oder wiederhergestellt werden.
Protection
Von dem Antivirus menu, users can perform Schnellscans of key system areas, vollständige Scans of the entire disk, and benutzerdefinierte Scans of specific files or folders, and configure Scheduled scans. Custom scans can also be initiated from the Finder context menu. Detection behaviours, including the option to scan volumes on mount, can be changed under Settings > Antivirus. The program employs Intego’s proprietary detection engine for macOS malware and Avira’s engine to identify Windows malware. Note that protection against malicious or fraudulent websites during browsing is not supported. The Firewall allows users to monitor and control the network activity of installed applications. Custom rules can be created for individual or all applications, and the Security Switch can be enabled to immediately block all network traffic. The integrated VPN is only included in the Complete plan and offers 50+ server locations worldwide as well as a kill switch.
Alerts
If real-time protection or the firewall is disabled, Intego displays a persistent alert in the main program window. Protection can be re-enabled by clicking the respective power button.
When malware was detected during the protection test, an alert appeared as shown below, displaying the file name and action taken. No user action was required, and the alert closed automatically after a few seconds. Clicking Review opens the program window, where users can handle the detected threat.
Quarantine & Logs
Die Quarantine lists all detected threats with details including the threat name, file name/path, and detection date. Users can delete (Repair), ignore, or restore (Vertrauen) items. The Antivirus History page provides a chronological record of system events, including scans, detections, protection status changes, and quarantine actions.
Advanced Options
By default, password protection for modifying program settings is disabled but can be enabled under Settings. Once activated, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Antivirus und Firewall).
- Manually adding items to scan exceptions (Safe List).
Deleting and restoring items from quarantine do not require administrator credentials, while uninstalling the program always does.
Zusammenfassung
Kaspersky Premium for Mac is a paid antivirus product that includes security and privacy features in a structured interface. Some of its key aspects are:
- Straightforward installation and setup of core features.
- Well-organised interface providing access to all features.
- Multiple scan options and configurable settings, including scheduled and external storage scans, as well as browsing-protection addons.
- Clear alerts that keep users informed of detected issues.
- Administrative Sicherheitsvorkehrungen zur Verhinderung unbefugter Änderungen.
Installation, Einrichtung und Deinstallation
Setup begins by logging into the Kaspersky account at my.kaspersky.com, followed by downloading and running the installer. The process provides step-by-step guidance with brief explanations throughout. Additional protection features, such as Wi-Fi network protection and browser extensions for Safari, Chrome, and Firefox, can optionally be enabled during setup. Once installed, the main program window displays several recommendations, such as enabling automatic macOS updates, activating location services, and installing missing browser extensions, as well as supplemental apps such as Kaspersky VPN and Password Manager (both included in the Premium plan). The program can be uninstalled by navigating to Help > Support > Uninstall in the macOS menu bar, or by deleting it from the macOS Applications folder.
Allgemeine Handhabung und wesentliche Merkmale
The main program window provides an overview of the Protection status, scan options (Scan), Subscription Information, system insights, and quick actions for privacy and system monitoring tools. Settingsdie Protection features und Scan exceptions (Trusted Zone), Quarantine (Detected Objects), and online Help are accessible via the macOS menu bar. Manual Updates can be triggered from the main program window via Database Update or from the macOS menu bar.
Protection
Über Scankönnen Benutzer Folgendes durchführen Schnellscans, vollständige Scans, oder benutzerdefinierte Scans of specific files and folders. The latter can also be initiated from the Finder context menu. Scans can be Scheduled Option von Scan or from Settings. Detection behaviour and further scan options, including externe Speicherscans, are also configurable under Settings; detection of stalkerware is enabled by default. The Kaspersky Protection browser extension provides additional protection against malicious and phishing websites. The Privacy und Identity sections provide additional features, including a data leak checker and an identity theft checker, which scan for personal data associated with the user’s email address or phone number in known data breaches. Further options include blocking applications from accessing the device’s webcam and preventing websites from tracking browsing activity.
Alerts
Wenn eine Schutzfunktion über Settings > Protection, Kaspersky displays a persistent alert on the main program window. Real-time protection can also be disabled from the system tray icon in the macOS menu bar. Protection can be re-enabled by clicking the Enable entfernen.
When malware was detected during the protection test, an alert appeared as shown below, displaying the threat file path and action taken. No user action was required, and the alert closed automatically after a few seconds. A shortcut to the quarantine is also displayed on the home page of the main program window.
Quarantine & Logs
Die Detected Objects page lists all isolated threats with their threat names and file paths. Clicking the “…” menu next to an item allows the user to delete or restore it. A Delete All option is available for bulk removal. Detailed logs of processed objects (detections), updates, scans, and protection feature activity are accessible under Protection > Reports in the macOS menu bar.
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Settings or the system tray icon).
- Uninstalling the program.
Deleting and restoring items from quarantine do not require administrator credentials, while uninstalling the program always does.
Zusammenfassung
Norton AntiVirus Plus for Mac is a paid antivirus product that provides essential security features, including AI-powered scam protection. Additional safeguards, such as browser extensions, are available separately. Some of its key aspects are:
- Straightforward installation and setup of core features.
- Clearly structured interface for easy navigation.
- Multiple scan options and configurable settings, including scheduled and external storage scans.
- Clear and persistent alerts that keep users informed of detected issues.
- Administrative Sicherheitsvorkehrungen zur Verhinderung unbefugter Änderungen.
Please note that Norton, like Avast and AVG, is a product of Gen Digital. These products share identical core functionality, though there are some differences in their user interfaces.
Installation, Einrichtung und Deinstallation
To install the program, the user must log into their Norton account at mein.norton.de, download the installer file, and run it on their Mac. Users are guided through a step-by-step wizard with brief explanations. The program can be uninstalled via the macOS menu bar or by running the Norton-Deinstallationsprogramm direkt in dem macOS-Programmordner starten.
Allgemeine Handhabung und wesentliche Merkmale
The main program window displays the current Protection statussowie einen schnellen Zugang zu Smart scan, weiterer scan options (Scans), Protection features (Security), Settings, und Subscription Information. Mit Quarantine is accessible under Sicherheit > Quarantäne und Scan exceptions finden Sie unter Sicherheit > Antivirus. Handbuch Updates kann über die Funktion LiveUpdate Komponente oder durch Auswahl von Check for Updates from the macOS menu bar. Online Help ist verfügbar über die Help menu, which directs users to the vendor’s support resources.
Protection
Unter Scans auf der Home, Security, oder Settings Seite können die Benutzer intelligente Scans, Schnellscans, vollständige Scans, oder gezielte Scans of specific files and folders. The latter can also be initiated from the Finder context menu. Scheduled scans are configurable under the Custom Scans Tab. External Drive Protection can be toggled under Antivirus > Real-Time Protection to automatically check for malware on mounted devices. Web protection is provided by the integrated Sicheres Netz Komponente, während die Eindringungsschutz Modul schützt vor netzwerkbasierten Angriffen, die z. B. verwundbare Programme ausnutzen oder von kompromittierten Netzwerkgeräten ausgehen. Das Modul Intelligente Firewall allows users to monitor and control the network activity of installed applications, including the geographic locations of connected servers displayed on an interactive map. The Schutz vor Betrug feature uses AI to help identify and block scams across web browsing, emails, text messages, and calls. On macOS, scam protection within the product itself is limited to Sicheres Netz, which detects phishing sites and fraudulent online stores. Additionally, users can submit content, including text messages, images, URLs, or YouTube video links, to Norton Genie, the vendor’s AI assistant, directly from within the program to check for potential scams.
Alerts
Wenn der Echtzeitschutz (Auto-Schutz) unter Sicherheit > Antivirus or other core shields (Intelligente Firewall, Sicheres Netz) unter Security are disabled, Norton displays a persistent alert in the main program window. Protection can be re-enabled by clicking the Enable entfernen.
When malware was detected during the protection test, an alert window appeared as shown below. No user action was required, and the alert persisted until manually closed. Multiple detections are consolidated into a single alert window, navigable via on-screen arrows. Expanding the details section at the bottom of the alert displays further information, including the threat name, severity, file name/path, and associated process.
Quarantine & Logs
Die Quarantäne ist zugänglich über Sicherheit > Quarantäne and lists all isolated threats, along with details such as the threat name, file name/path, and detection date. Users can delete items or, with administrative privileges, restore them.
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Sicherheit > Antivirus).
- Uninstalling the program.
- Restoring items from quarantine.
Zusammenfassung
Trellix Endpoint Security (HX) is an enterprise-grade endpoint protection solution designed for large-scale deployments, supporting up to 100,000 endpoints per appliance. It provides a centralised management console available in multiple deployment formats (cloud-hosted, appliance-based, or Amazon-hosted) and includes advanced investigative and containment capabilities. Some of its key aspects are:
- Well-organised cloud console with drill-down views.
- Investigation and remediation tools for detailed threat analysis.
- Flexible search facility across endpoints and event data.
- Containment-Funktion zur Isolierung gefährdeter Endpunkte.
- Prioritised threat notifications for administrators.
Management Console
The console is navigated via a top-page menu, providing access to key components such as threat monitoring, host management, search tools, and administrative controls. The most relevant sections and pages are described below.
Dashboard
Upon login, administrators are presented with an overview of system health and threat activity. This includes metrics such as the total number of hosts with alerts, split into four categories, along with summaries of recent file acquisitions and the status of contained, active, and inactive hosts.
Hosts > Hosts with Alerts page
This page lists all protected hosts with unresolved security alerts. Expanding an entry reveals a chronological breakdown of alerts, including detection type (e.g., signature-based), timestamps, scan type (on-access, on-demand), malware type and name, file status (e.g., quarantined), file attributes (path, hashes, size, modification and access times), and process information (e.g., PID, process path, associated user). Administrators can perform actions such as marking alerts as acknowledged or false positives, adding investigation comments, or managing quarantined items via the Quarantines Tab.
Alerts page
This page provides a threat-centric view, displaying all detected threats across the organisation’s network. Threats can be sorted or filtered by attributes such as name, file path, file hash, hostname, host IP address, or event timestamps. Available actions include Acknowledge, Als falsch positiv markieren, Delete, und Add Comment. Wenn Sie auf den Namen eines Eintrags klicken, gelangen Sie zur Detailansicht des Eintrags unter dem Menüpunkt Hosts with Alerts Seite.
Acquisitions page
Auf dieser Seite werden alle Dateien aufgelistet, die von Endgeräten erworben wurden, in der Regel zu forensischen Zwecken. Erfassungen werden in der Regel von der Seite Hosts with Alerts Seite und können sicher für die Offline-Analyse heruntergeladen werden.
Rules page
This page contains preconfigured and custom detection logic for identifying specific threats or suspicious behaviours. Rules include indicators of compromise (IOCs), exploit patterns, and known false positives, managed largely by Trellix’s Dynamic Threat Intelligence (DTI) cloud. Administrators can also create custom rules with specific detection conditions for their organisation’s environment.
Enterprise Search page
This search feature enables forensic investigation and threat hunting across all connected endpoints using predefined criteria. Supported search terms include application names, file and executable attributes (e.g., name, path, type, hash), network and web-related details (e.g., IP address, port, URL, DNS, browser, cookie, page), usernames, registry keys, process and service information, timestamps, system events, and more.
Verwaltungsbereich
This section provides controls for managing hosts, policies, and agents, as well as configuring data acquisition, appliance settings, and other system options. On the Policies page, administrators can define and configure endpoint protection policies, covering Exploit Guard Protection (Windows only), Malware Scans (e.g., scan on install, scheduled scan), polling intervals, Malware Protection (e.g., detection options, definition updates, exclusions, quarantine actions), Removal Protection, Tamper Protection, logging behaviours, and further agent settings. On the Host Sets page, hosts can be grouped dynamically based on defined criteria or manually via drag-and-drop. Policies can then be assigned to each host set.
Endpoint Protection Client
Deployment
Die neuesten Agentenversionen für macOS, Windows und Linux finden Sie unter Admin > Agent Versions. Deployment can be performed manually or automated using system management tools such as Jamf. Manual installation requires Full Disk Access permission to be granted in the macOS system settings to ensure full functionality. After installation, the agent takes several minutes to initialise and download the necessary protection components.
Allgemeine Handhabung und Warnungen
The macOS agent operates silently in the background, with no local user interface or command-line access. During the protection test, no on-screen alerts were displayed on the host upon malware detection. All detection events are visible and manageable solely through the management console.






















































































