Tag: enterprise

Process Injection Certification Test

AV-Comparatives Process Injection Certification Test

AV-Comparatives conducts targeted offensive security tests, offering vendors the opportunity to pursue certification in specific areas. In this test, our focus centered on “Shellcode Execution / Process Injection.” Certification reports are exclusively issued for vendors who successfully meet our rigorous criteria. Tested vendors received comprehensive technical data and detailed feedback to enhance their products’ resilience against potential attacks.

https://www.av-comparatives.org/news/process-injection-certification-test/

Continue reading…

LSASS Credential Dumping Certification Test

AV-Comparatives LSASS Credential Dumping Certification Test

AV-Comparatives performs targeted offensive security tests, offering vendors the opportunity to pursue certification in specific areas. In this year’s assessment, one focus was “Credential Dumping” (LSASS Protection). Certification reports are exclusively issued for vendors who successfully meet our stringent criteria. Tested vendors received detailed technical data and feedback to enhance their products’ resilience against potential attacks.

https://www.av-comparatives.org/news/lsass-credential-dumping-certification-test/

Continue reading…

The difference between AV-Comparatives’ EPR Test and MITRE ATT&CK Engenuity

Both the AV-Comparatives EPR Test and MITRE Engenuity have their merits, each providing useful insights into endpoint security solutions. Understanding the differences between these two tests is essential for IT managers, CISOs, and other tech-savvy professionals looking to select endpoint security solutions that will effectively protect their environments.

Continue reading…

NGFW Egress C2 Test: Assessing the Effectiveness of Outgoing Network Traffic Prevention and Detection Capabilities

AV-Comparatives Next-Gen Firewall Egress C2 Test

In June 2023, AV-Comparatives conducted an NGFW Egress C2 Test to evaluate the effectiveness of NGFW products in detecting and preventing malicious traffic. In targeted attacks, one of the goals of APT groups is to establish control over a compromised system by opening a command-and-control channel (C2) to the command-and-control server operated by the attacker. If the attacker has already gained access to the system via a trusted relationship, or has delivered malware using phishing or USB drives, they can use C2 malware to open the C2 channel.

Continue reading…