Here we have outlined the structure of the following product reviews for each of the consumer programs in this test. For the enterprise products we have used a slightly different review format which includes a brief product summary and sections about the cloud-based management console (e.g., dashboard, host management, detections, policies, investigation) as well as the endpoint protection client (e.g., deployment, general handling, alerts). Summary: We briefly describe the nature of the product and highlight selected key aspects, such as whether it is free or paid, important security features, and our overall experience with it. Please note that all products protect against ransomware in the same way as for other types of malware. Where we have specifically mentioned “ransomware protection”, it means that specific user folders are monitored to prevent unauthorised changes. Installation, Setup & Uninstallation: We describe how to get the product up and running on your Mac, starting with downloading the installer and finishing with any post-setup tasks needed, such as installing and enabling browser extensions. We record any options available, and whether you have to make any decisions during installation. There is also a note on how to uninstall the product, should you need to. Please be aware that when installing any antivirus product on macOS Sequoia (which was used for the tests and reviews), it is necessary to go into the macOS system settings and enable the program’s system extensions as well as grant the program specific permissions, such as Notifications or Full Disk Access. Since this process is essentially identical for all products, we have not mentioned it in the individual reviews. General Handling & Essential Features: We consider how easy it is to find the most important functionality: protection status, different scan options, protection features, quarantine, subscription information (not applicable to free programs), update, settings, and help. Protection: We describe the available scan options, including smart/full/custom scan, external storage scan, and scheduled scans, how and where to trigger them, and briefly mention any special detection settings that are enabled by default, e.g., detection of potentially unwanted applications (PUA) or stalkerware. We might also give additional information about third-party detection engines and other relevant malware protection features, such as browser/email/ransomware protection. Alerts: We look at how the current protection status is displayed, what sort of warning is shown if real-time protection or any other protection feature is disabled, and how to correct this. We also note what type of alert is shown when malware is discovered, and whether the user needs to take any action in this case. Quarantine & Logs: We check the functionality that shows you which malicious items have been found, what information is provided about them, and what the actions are for dealing with them. If available from the program window, we will also note the types of data and events being logged by the program. Advanced Options: We check whether only users with a macOS Administrator account can disable the protection features, uninstall the program, or restore/delete items from quarantine. We regard it as ideal if only administrators (not standard macOS users) can perform at least the first two tasks.

Mac Security Test & Review 2026
| Release date | 2026-06-17 |
| Revision date | 2026-06-05 |
| Test Period | April - May 2026 |
| Online with cloud connectivity | ![]() |
| Update allowed | ![]() |
| False Alarm Test included | ![]() |
| Platform/OS | MacOS |
Introduction
macOS has long enjoyed a reputation for robust security and is often seen as a “hardened” alternative to Windows. Although malware targeting macOS remains far less common than on Windows and Android, there have still been numerous real-world instances (https://www.macworld.com/article/672879/list-of-mac-viruses-malware-and-security-flaws.html). In fact, attackers no longer regard Macs as secondary targets (https://www.macworld.com/article/670537/do-macs-need-antivirus.html, https://objective-see.org/blog/blog_0x84.html). In 2023 and 2024, a surge of sophisticated information-stealers, most notably Atomic Stealer (AMOS) and its forks such as Odyssey (formerly Poseidon), CloudChat, and Shamos, dominated new macOS threats. These cloud-controlled services harvest browser cookies, saved passwords, Keychain data, cryptocurrency wallet credentials, and even extract logins from popular password managers, VPN configurations, and FTP clients. By late 2025, additional stealer families had emerged, including Phexia, DigitStealer, and MacSync Stealer. The latter is notable for being distributed via signed and notarised executables to bypass Gatekeeper scrutiny. Malware in this category is also becoming increasingly modular, with stealers and backdoor components bundled together to enable persistent access rather than one-off data theft.
Distribution tactics have evolved accordingly, with threat actors now relying more on targeted malvertising campaigns and social-engineering schemes rather than user-installed adware bundles. Examples include cloned download sites offering “popular” Mac apps that instead serve up malicious disk images, deceptive Google ads, fake utilities (e.g., video-chat tools, VPN clients), trojanised installers, phishing emails embedding PDF-masquerading apps, and ClickFix-style attacks, which convince users into copy-pasting malicious commands directly into Terminal (https://www.microsoft.com/en-us/security/blog/2026/05/06/clickfix-campaign-uses-fake-macos-utilities-lures-deliver-infostealers/), bypassing Gatekeeper entirely. Consequently, both everyday users and enterprises must supplement basic vigilance with multi-layered defences: modern endpoint protection with real-time malware scanning, DNS and web filtering to block malicious ads, and EDR solutions to detect abnormal system behaviours before data is lost.
macOS Built-In Protections
Out of the box, macOS delivers basic anti-malware capabilities. XProtect is Apple’s signature-based scanner that automatically checks new and modified apps against a database of known malware signatures and remediates infections. Gatekeeper ensures that only apps signed by verified developers and notarised by Apple can run on a Mac. Both features operate mostly in the background, with occasional configuration options and alerts. Complementing these measures, System Integrity Protection (SIP) locks down system-critical files and folders so that even system processes with root privileges cannot alter them. macOS isolates running processes through sandboxing and requires explicit permission for apps to access user files and other sensitive information, such as the camera, microphone, or location. By separating system files onto a read-only volume apart from user data, macOS further reduces the attack surface for malware. System and security updates are automatically installed through the standard macOS software-update process. macOS Tahoe introduced two further protections: Background Security Fixes, which allow Apple to deploy lightweight patches between regular point releases, reducing the window of exposure to newly discovered vulnerabilities, and a Terminal paste warning, which alerts users before pasted content is executed in Terminal, providing a direct countermeasure against ClickFix-style attacks.
The Case for Third-Party Protection
Apple’s built-in approach handles well-established malware effectively but may not respond quickly enough to emerging threats. Any app that bypasses notarisation will appear “safe” to macOS’s built-in protections, and signature-based scanning alone cannot catch zero-day or fileless attacks. Third-party antivirus solutions with heuristic and behavioural engines address both gaps, while web- and phishing-protection browser extensions block malicious URLs before they load. Some Mac antivirus programs can also detect malware targeting other operating systems, such as Windows and Android, when inadvertently transferred via a USB drive. Non-expert users, children, and those who frequently try new software stand to benefit most from this additional layer of protection.
Because macOS faces a smaller threat landscape than Windows, its market for anti-malware products is naturally more limited. Nevertheless, our annual Mac security tests consistently show that participating vendors are committed to threat research and continuous product improvement. We strongly encourage all security vendors to submit their solutions to independent, third-party evaluations, ensuring they meet current industry standards and user expectations. For anyone concerned that third-party antivirus might affect system performance, our tests found no meaningful impact with any of the reviewed products.
Best Practices for Enhancing Mac Security
As with Windows computers, Macs can be made safer by employing good security practices. We recommend the following:
- Do not use an administrator account for day-to-day computing.
- Use secure passwords (iCloud Keychain) or passkeys (biometric identification such as Touch/Face ID) and enforce multi-factor authentication wherever possible.
- Enable FileVault to ensure the contents of your Mac are encrypted and protected if the device is lost or stolen.
- Deactivate any services such as Wi-Fi, Bluetooth, or IPv6 that you do not use.
- Be careful about which programs you install and where you download them from.
- Only install browser extensions from trusted sources and review the permissions they request.
- Pay attention when granting programs permissions to sensitive system areas or information.
- Do not run Terminal commands copied from websites or messages unless you are certain of their origin.
- Be wary of opening any links that you receive via e.g., email or Messages.
- Keep your macOS and third-party software up to date with the latest patches, and ensure automatic updates are enabled.
- Regularly back up your data using Time Machine or another backup solution.
- Use a certified antivirus program for Mac to provide an additional layer of protection. A list of antivirus programs for Mac can be seen here: https://www.av-comparatives.org/list-of-av-vendors-mac/
Tested Products
For this test, macOS Tahoe with the latest security patches was used, as it was the most recent macOS version available at time of testing. The following products were reviewed and tested for this report, using the latest available versions as of April/May 2026:
Additional information about the products and third-party engines/signatures used inside the products: Avast, AVG, and Norton are products of Gen Digital and use the Avast engine. Intego uses the Avira engine for detecting Windows malware. Trellix uses the Bitdefender engine. Avast/AVG specifically asked us to test their free version.
We congratulate the manufacturers who elected to have their products reviewed and tested. Their commitment is a valuable contribution to improving security for Mac systems.
Test Procedure
This test checks how effectively the security products protect a macOS system against malicious apps. The test took place in May 2026 and used macOS malware collected in the preceding months. We used a total of 1500 recent and representative malicious Mac samples, which we believe accurately represent the current threat landscape although this sample size is very small compared to Windows.
While a slightly larger number of samples was initially evaluated, samples detected by all participating products were excluded after the validation phase, beginning with the oldest samples, until a final test-set size of 1500 samples was reached. This helps ensure that the final test set remains relevant and sufficiently challenging for comparative evaluation.
For the test, the macOS system was updated to its latest version and imaged. Each security product was installed on a fresh machine image, and its definitions were updated at the beginning of May 2026. The Mac systems remained connected to the Internet throughout the test to utilize cloud services. A USB flash drive containing the malware samples was inserted into the test machines, and some antivirus programs detected samples at this stage. We then scanned the flash drive, removing any detected samples. Undetected samples were copied to the Mac’s system disk and executed, giving the security products a final chance to detect them.
Additionally, we tested for false positives using a set of clean Mac programs. None of the security products produced any false alarms. To address the rising number of potentially unwanted applications (PUAs) on Mac systems, we conducted an additional test to evaluate the detection capabilities of the products. Specifically, we assessed the detection of 1500 prevalent Mac PUAs using the same methodology as for malware detection.
Many Mac security products assert that they can identify both Mac and Windows malware to prevent the user’s computer from transmitting harmful programs to Windows PCs. To test this claim, we evaluated whether the Mac antivirus products can detect prevalent and current Windows malware. We used 100 Windows samples and followed the same procedure used for Mac malware detection, excluding any undetected samples since Windows programs cannot be executed under macOS.
Settings
All Mac consumer products were tested with default settings.
Enterprise environments typically involve product configuration by a system administrator, following vendor’s guidelines. Therefore, we invited all vendors to configure their respective enterprise products accordingly. The scores achieved reflect performance under the specific settings detailed below:
- CrowdStrike: All settings enabled except “Enhanced network visibility”. All detection and prevention options of “Next-gen antivirus” were set to “Extra Aggressive”.
- Trellix: In “Exploit Guard Protection, “Exploit Guard” with all prevention actions was In “Malware Protection”, “Signature and Heuristic Detection” and “Cloud Lookup” were enabled.
Test Results
The table below shows the protection results of the tested products. We would like to point out that while some products may sometimes be able to reach 100% detection rates in a test, it does not mean that these products will always protect against all threats. It just means that they were able to detect 100% of the widespread samples used in this test. We do not round up scores to 100% if there are misses. Programs with a score of 100% thus had zero misses. For PUA, the highest score possible is capped at 99% due to the nature of the files.
| Product | Mac Malware Protection 1500 samples |
Mac PUA Protection 1500 samples |
Windows Malware Detection* 100 samples |
|---|---|---|---|
| Avast One Free | 99.9% | 95% | 100% |
| AVG AntiVirus Free | 99.9% | 95% | 100% |
| Bitdefender Antivirus | 99.0% | 94% | 100% |
| CrowdStrike Falcon Enterprise | 100% | 99% | 0% |
| ESET HOME Security Essential | 99.9% | 94% | 100% |
| Intego ONE Complete | 96.7% | 94% | 100% |
| Kaspersky Premium | 100% | 99% | 100% |
| Norton AntiVirus Plus | 99.9% | 95% | 100% |
| Trellix Endpoint Security (HX) | 99.0% | 94% | 100% |
| * Detection of Windows threats on Macs can be seen as discretionary. Some products do not include detection for non-Mac threats or have limited detection capabilities due to technical constraints |
|||
Product Reviews
Summary
Avast One Free for Mac is a free antivirus product aimed primarily at non-expert users. It provides essential security features, including a basic email guard and an AI assistant for scam checking. Some of its key aspects are:
- Simple installation and setup of core features.
- Clearly structured interface for easy navigation.
- Multiple scan options and settings, including scheduled and external storage scans.
- Clear and persistent alerts that keep users informed of detected issues.
- Administrative safeguards to prevent unauthorised changes.
Please note that Avast, like AVG and Norton, is a product of Gen Digital. These products share identical core functionality, though there are some differences in their user interfaces.
Installation, Setup & Uninstallation
The program is installed by downloading and running the installer file from the vendor’s website. The setup process walks the user through each step with brief on-screen explanations. The program can be uninstalled via the macOS menu bar or by running the Avast One Uninstaller directly from the macOS Applications folder.
General Handling & Essential Features
The main program window displays the current protection status, alongside access to smart scan, core protection features (Free Antivirus), and additional tools for quick system check-ups. The quarantine and other security-related components (e.g., Mail Shield, Traffic Monitor, Network Inspector) can be found under Free Antivirus. Settings (Preferences) are accessible via the program menu or the macOS menu bar. Subscription information is not applicable, as the program is free. Manual updates can be initiated by clicking Check for Updates under the system tray icon or program name in the macOS menu bar. Online help is available via the Help menu, which directs users to the vendor’s support resources.
Protection
From Scan Center on the Free Antivirus page, users can perform smart scans, deep scans covering all drives and system memory, external storage scans for connected devices, or targeted scans of specific files and folders, and set up scheduled scans. Targeted scans can also be initiated from the Finder context menu. Detection behaviours and scan exceptions are configurable under Preferences; detection of PUA is enabled by default. Web protection is provided by the integrated Web Guard, which scans web traffic in real time to block malicious websites, downloads, and scripts. The Mail Shield scans emails of specified mail accounts for suspicious content; in the free version, this is limited to mail applications installed locally on the Mac, such as Apple Mail, Microsoft Outlook, and Mozilla Thunderbird. The Traffic Monitor provides an overview of data transmission across applications, including the geographic locations of connected servers displayed on an interactive map. Users can submit content, including text messages, links, or images, to the AI-powered Avast Assistant directly from within the program to check for potential scams.
Alerts
If real-time protection (File Shield) or other core shields (Mail Shield, Web Guard) under Free Antivirus are disabled, Avast displays a persistent alert in the main program window. Protection can be re-enabled by clicking the Turn On button.
When malware was detected during the protection test, an alert window appeared as shown below. No user action was required, and the alert persisted until manually closed. Multiple detections are consolidated into a single alert window, navigable via on-screen arrows. Expanding the details section at the bottom of the alert displays further information, including the threat name, severity, file name/path, and associated process.
Quarantine & Logs
The quarantine is accessible from the Free Antivirus page and lists all isolated threats, along with details such as the threat name, file name/path, and detection date. Users can delete items or restore them with administrative privileges.
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Free Antivirus).
- Uninstalling the program.
- Deleting and restoring items from quarantine.
Advertising
The program promotes additional paid applications (e.g., Cleanup, VPN, Breach Guard) and displays in-app messages notifying users of flagged issues, such as ransomware vulnerability, network threats, and fake websites. When users attempt to address these issues, Avast presents an offer to upgrade to Avast Premium Security. If the initial offer is declined, a follow-up prompt appears offering a 60-day free trial of the paid product. Upgrade options may also appear within detection alerts.
Summary
AVG AntiVirus Free for Mac is a free antivirus solution aimed primarily at non-expert users. It provides a straightforward setup process, a clearly structured interface, and malware protection. Some of its key aspects are:
- Simple installation and setup of core features.
- Tile-based interface for easy navigation.
- Multiple scan options and settings, including scheduled and external storage scans.
- Clear and persistent alerts that keep users informed of detected issues.
- Administrative safeguards to prevent unauthorised changes.
Please note that AVG, like Avast and Norton, is a product of Gen Digital. These products share identical core functionality, though there are some differences in their user interfaces.
Installation, Setup & Uninstallation
The program is installed by downloading and running the installer file from the vendor’s website. The setup process walks the user through each step with brief on-screen explanations. The program can be uninstalled via the macOS menu bar or by running the AVG AntiVirus Uninstaller directly from the macOS Applications folder.
General Handling & Essential Features
The main program window displays the current protection status prominently, alongside quick access to smart scan, further scan options (Run Other Scans), and protection feature tiles (Computer, Web & Email). The quarantine is accessible under Computer, and settings (Preferences) are available via the program menu or the macOS menu bar. Subscription information is not applicable, as the program is free. Virus definition updates can be initiated manually by clicking Virus Definitions on the home page, or via Check for Updates under the system tray icon or the program name in the macOS menu bar. Online help is accessible through the Help menu, which directs users to the vendor’s support resources.
Protection
From Run Other Scans on the home page, users can initiate smart scans, deep scans covering all drives and system memory, external storage scans for connected devices, or targeted scans of specific files and folders. The latter can also be launched from the Finder context menu. Scheduled scans and detection behaviours are configurable under Preferences; detection of PUA is enabled by default. Web protection is provided by the integrated Web Shield, which scans web traffic in real time to block malicious websites, downloads, and scripts.
Alerts
If real-time protection (File Shield) under Computer, web protection (Web Shield), or email protection under Web & Email is disabled, AVG displays a persistent alert in the main program window. To re-enable a protection feature, users must navigate to the respective menu tile and turn it back on manually.
When malware was detected during the protection test, an alert window appeared as shown below. No user action was required, and the alert remained visible until manually closed. Multiple detections are consolidated into a single alert window, navigable via on-screen arrows. Expanding the details section at the bottom of the alert displays further information, including the threat name, severity, file name/path, and associated process.
Quarantine & Logs
The quarantine is accessible from Computer on the home page and lists all isolated threats, along with details such as the threat name, file name/path, and detection date. Users can delete items or restore them; the latter requires administrative privileges.
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Computer and Web & Email).
- Uninstalling the program.
- Restoring items from quarantine.
Advertising
The application displays in-app messages notifying users of flagged issues, such as ransomware vulnerability, network threats, and fake websites. When users attempt to address these issues, AVG presents an offer to upgrade to AVG Internet Security. If the initial offer is declined, a follow-up prompt appears offering a 60-day free trial of the paid product. Upgrade options may also appear within detection alerts.
Summary
Bitdefender Antivirus for Mac is a paid antivirus product that includes malware protection, a custom VPN, browser security extensions, and chat protection for popular messaging applications. It is suited to both novice and advanced users. Some of its key aspects are:
- Straightforward installation and setup of core features.
- Well-structured interface providing access to all features.
- Multiple scan options, including automatic external storage scans, ransomware protection, a data-limited VPN, browser protection addons, and chat protection for popular messaging apps (e.g., macOS Messages, WhatsApp, Telegram).
- Clear alerts that keep users informed of detected issues.
- Administrative safeguards to prevent unauthorised changes.
Installation, Setup & Uninstallation
To install the program, the user must log into their Bitdefender account at central.bitdefender.com and download the installer file. Once the installer is launched, the setup wizard guides the user through each step. After installation, users are prompted to create or sign in to a Bitdefender account. An optional tour introduces the key features, and the program recommends enabling app notifications in the macOS system settings, installing the browser extension (Traffic Light), configuring ransomware protection (Safe Files), setting up Time Machine Protection, and initiating a system scan. The interface supports macOS dark and light modes. The program can be uninstalled via the Bitdefender Uninstaller found in the macOS Applications folder.
General Handling & Essential Features
The Dashboard displays the current protection status and provides access to scan options (Quick Scan and System Scan), protection features, settings, subscription information (My Account), and help resources. The quarantine and scan exceptions are located under Protection. Manual updates can be triggered from the Actions menu in the macOS menu bar. The Privacy section includes the data-limited Bitdefender VPN and the Anti-Tracker browser extension. A PDF user manual and online support are accessible via Help. The user manual is dated November 2022 and may not reflect features introduced in subsequent updates, such as Chat Protection. Bitdefender should consider revising this document accordingly.
Protection
From the Protection menu, users can perform a quick scan of critical system areas, a system scan covering all files and folders, or a custom scan targeting specific files or folders. The latter can also be initiated from the Finder context menu. External storages are automatically scanned when connected to the Mac. Web protection is provided through the Traffic Light browser extension, which is compatible with Safari, Chrome, and Firefox, and adds safety ratings to search engine results. The ransomware protection feature monitors user-specified folders and Time Machine backups for unauthorised changes. The Chat Protection feature monitors conversations in macOS Messages, WhatsApp, Facebook Messenger, Telegram, Discord, and LinkedIn for malicious links and scam content. Depending on the application, protection is available either in the native app, in the browser, or both. Detection behaviours and protection settings are configurable under Settings.
Alerts
If real-time protection is disabled via Settings or the system tray icon in the macOS menu bar, Bitdefender displays a persistent alert on the main program window. Protection can be re-enabled by clicking the Enable button.
When malware was detected during the protection test, an alert window appeared as shown below. No user action was required, and the alert remained visible until manually closed. Multiple detections are consolidated into a single alert window, navigable via on-screen arrows. Expanding the details section at the bottom of the alert displays further information, including the threat name, severity, file name/path, and associated process.
Quarantine & Logs
The Quarantine lists all isolated threats with details including the threat name, file name, and detection date. Deleting and restoring quarantined items requires administrative privileges. The Notifications page logs events such as signature updates, component activations, and malware detections; entries can be filtered by severity level (Critical, Warning, Information).
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Settings).
- Uninstalling the program.
- Deleting and restoring items from the quarantine.
Summary
CrowdStrike Falcon Enterprise is an enterprise-grade endpoint security solution for medium to large organisations. It provides centralised, cloud-based management, advanced detection and response capabilities, and real-time protection through a lightweight endpoint protection client. Some of its key aspects are:
- Well-structured cloud console with access to granular details.
- Investigative functions for attack analysis and incident response.
- Advanced search capabilities for threat hunting and correlation.
- Containment feature to isolate compromised endpoints.
- User-level alerts on endpoints and prioritised threat notifications for administrators.
Management Console
The cloud console is navigable via the menu in the top-left corner, providing access to all EDR/XDR functions ranging from incident response, threat detection and remediation, and forensic analysis to endpoint administration, policy management, and reporting. Pages can be bookmarked for quick navigation via the Bookmarks section using the icon beside each page title. The most relevant sections and pages are described below.
Endpoint Security > Activity Dashboard page
The landing page displays key threat metrics in large panels, including a list of recent detections categorised by severity and detection method (Tactic & Technique), SHA-based detections, prevented malware by host, a monthly bar chart of detections by tactics, and several OverWatch statistics reflecting managed threat hunting activity by OverWatch analysts within the organisation’s environment and across all CrowdStrike customers. All dashboard items are clickable and redirect to the relevant detail pages with the respective filters applied.
Counter Adversary Operations > OverWatch
Falcon OverWatch is a managed threat hunting service operated by a dedicated team of CrowdStrike analysts, which proactively and continuously searches for sophisticated adversary activity. When potential threats are identified, designated administrators receive email notifications with remediation guidance. The OverWatch Home and OverWatch Hunting Leads pages provide visibility into OverWatch activity and investigated detections within the organisation’s environment over the preceding 30 days, as well as global trends in intrusions by adversary category, industry, and MITRE ATT&CK tactics, techniques, and procedures (TTPs).
Endpoint Security > Endpoint Detections page
This page provides granular control for analysing detections. Administrators can filter detection entries using a wide range of parameters, including severity, tactic, technique, date and time, host, and more. Selecting an entry opens a comprehensive timeline alongside a details panel, from which key actions can be taken, such as editing the detection status, assigning a user for remediation, immediately containing the affected host, initiating investigation tasks, and accessing the full detection details page. The detection details page presents information across five views. The Details view includes general detection and host information, prevention actions taken, quarantined files, network indicators, associated file hashes, commands and executables involved, a status log, and additional context such as host vulnerabilities or misconfigurations, and indicators of compromise (IOCs). The Process Table, Process Tree, and Process Graph present associated processes in tabular form or as an interactive tree or graph, where entries and nodes can be inspected for details on network, files, disk operations, and command-line history. The Events Timeline lists all relevant events in chronological order.
Endpoint Security > Quarantined Files page
Quarantined items are listed with metadata including timestamp, file name, hostname, logged-on user, and status. Administrators can release, delete, or download files in password-protected archives. Clicking on an entry opens a panel with additional information such as file path, file hash, detection method, and severity. Filters are available to narrow results for faster triage.
Endpoint Security > Prevention Policies page
This page allows administrators to create and configure prevention policies across supported platforms, defining how endpoint protection clients detect and respond to threats. For macOS, configurable components include Sensor Capabilities, Sensor Visibility, Next-Gen Antivirus (On Write, Quarantine, Cloud Machine Learning, Sensor Machine Learning), Malware Protection (Execution Blocking), and Behaviour-Based Prevention (Unauthorised Remote Access IOAs, Credential Dumping IOAs). Machine learning components have adjustable sensitivity levels, ranging from Disabled to Extra Aggressive. Custom host groups and indicators of attack (IOA) rule groups can be assigned per policy; a policy hierarchy determines which one takes precedence.
Host Setup and Management > Host Management page
All registered endpoints are listed here, with customisable columns displaying attributes such as hostname, status, OS version, IP addresses, sensor version, and assigned policies. Clicking on an entry opens the details panel, and advanced filtering allows administrators to search for specific systems.
Investigate section
This area provides forensic investigation and threat hunting capabilities. Administrators can search for hosts, events, users, file hashes, IP addresses, and activities related to detections or files. Additional tools include host and process timelines, as well as reports on remote access and geolocation activity.
Endpoint Protection Client
Deployment
The recommended method is to deploy the Falcon Sensor via an MDM server using a configuration profile supplied by CrowdStrike, which streamlines deployment and avoids manual authorisation steps on endpoints. Alternatively, standalone installers can be used for manual setup. Sensor packages are downloadable under Host Setup and Management > Sensor Downloads, with multiple older versions available for compatibility. The installation process includes step-by-step guidance for local setup.
General Handling
The Falcon Sensor runs with a minimal interface, displaying only status information. Administrative interaction is conducted via the falconctl command-line utility. Example commands include falconctl stats for sensor information and statistics, and falconctl uninstall for removal. With the settings used for the protection test, detected threats are quarantined in situ rather than deleted.
Alerts
When malware was detected during the protection test, an alert appeared as shown below, providing minimal information about the detection and action taken. No user action was required, and the alert closed automatically after a few seconds.
Summary
ESET Home Security Essential is a paid, cross-platform security subscription that delivers malware protection on macOS through ESET Cyber Security. The product is managed and deployed via the ESET HOME web portal. Some of its key aspects are:
- Straightforward installation and setup of core features.
- Clearly structured interface providing access to all core features.
- Multiple scan options, including scheduled and external storage scans.
- Clear alerts that keep users informed of detected issues.
- Administrative safeguards to prevent unauthorised changes.
Installation, Setup & Uninstallation
To install the program, users must log into their ESET HOME account at home.eset.com and download the installer. The setup wizard guides the user through each step with on-screen instructions. The program can be uninstalled by re-running the installer and clicking Uninstall, or via the Uninstaller found under ESET Cyber Security > Contents > Helpers in the macOS Applications folder.
General Handling & Essential Features
The main program window is divided into several sections providing quick access to the protection status (Overview), scan options (Scan), protection features (Protections), and subscription information (Help & Support). The quarantine is accessible under Tools, and manual updates can be initiated via Update. Online help is available via Help & Support or the Help menu. Settings can be accessed via the macOS menu bar.
Protection
From Scan, users can perform a system scan of all local drives or a custom scan targeting specific files and folders. Scheduled scans (Scheduler) and scan exceptions (Detection Exclusions) are configurable under Settings. Further options allow for extensive configuration of alert, update, logging, and detection behaviours, including external storage scans and device control, both disabled by default. PUA detection can be enabled during program setup, which is the recommended option. Under Protections, the program also provides web and email protection (Web and Email) and a firewall (Network Access), with customizable URL lists and app rules. The Applications page under Tools gives information on installed applications and system processes, including whether inbound/outbound network traffic is permitted, the current status, a reputation score, and current/total internet usage.
Alerts
If real-time or web protection is disabled via Protections or Settings, ESET displays a persistent alert in the main program window. Protection can be re-enabled by clicking the Enable link.
When malware was detected during the protection test, an alert appeared as shown below, displaying the threat name, file name, and action taken. No user action was required, and the alert closed automatically after a few seconds.
Quarantine & Logs
The Quarantine lists all isolated threats with details such as the threat name, file name, detection date/type, reason, and file size. Users can delete and restore items with administrative privileges. The Logs Files page under Tools records security events with detailed metadata; entries can be filtered by category such as Detections, Computer Scan, Filtered Websites, and Firewall.
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Protections or Settings).
- Uninstalling the program.
- Accessing, deleting, and restoring items from quarantine.
- Accessing log files.
- Changing program settings.
Summary
Intego ONE Complete is a paid Mac security application that consolidates malware protection, a firewall, system optimisation (SmartClean), and a VPN into a single interface. Features available depend on the plan purchased. Some of its key aspects are:
- Simple installation and setup of core features.
- Unified interface providing access to all components in one place.
- Multiple scan options, including scheduled and external storage scans.
- Clear and persistent alerts that keep users informed of detected issues.
- Administrative safeguards to prevent unauthorised changes.
Installation, Setup & Uninstallation
To install the program, the user must log into their Intego account at account-v2.intego.com, download the installer file, and run it on their Mac. The setup wizard guides the user through each step with brief explanations. The interface supports macOS dark and light modes. The program can be uninstalled by selecting Uninstall from the Help menu.
General Handling & Essential Features
The main program window displays the current protection status and provides access to all core components (Antivirus, Firewall, VPN, and SmartClean) and settings. A ONE Scan can be started from the home page, which performs a combined protection and system performance check. Quarantine (Quarantined Files) and scan exceptions (Safe List) are accessible within the Antivirus section. Updates can be initiated via Check for Updates in the macOS menu bar or from Settings. Subscription information is accessible via the profile icon in the top-right corner of the program window and online help resources are available via the Help menu.
Protection
From the Antivirus menu, users can perform quick scans of key system areas, full scans of the entire disk, and custom scans of specific files or folders, and configure scheduled scans. Custom scans can also be initiated from the Finder context menu. Detection behaviours, including the option to scan volumes on mount, can be changed under Settings > Antivirus. The program employs Intego’s proprietary detection engine for macOS malware and Avira’s engine to identify Windows malware. Note that protection against malicious or fraudulent websites during browsing is not supported. The Firewall allows users to monitor and control the network activity of installed applications. Custom rules can be created for individual or all applications, and the Security Switch can be enabled to immediately block all network traffic. The integrated VPN is only included in the Complete plan and offers 50+ server locations worldwide as well as a kill switch.
Alerts
If real-time protection or the firewall is disabled, Intego displays a persistent alert in the main program window. Protection can be re-enabled by clicking the respective power button.
When malware was detected during the protection test, an alert appeared as shown below, displaying the file name and action taken. No user action was required, and the alert closed automatically after a few seconds. Clicking Review opens the program window, where users can handle the detected threat.
Quarantine & Logs
The Quarantine lists all detected threats with details including the threat name, file name/path, and detection date. Users can delete (Repair), ignore, or restore (Trust) items. The Antivirus History page provides a chronological record of system events, including scans, detections, protection status changes, and quarantine actions.
Advanced Options
By default, password protection for modifying program settings is disabled but can be enabled under Settings. Once activated, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Antivirus and Firewall).
- Manually adding items to scan exceptions (Safe List).
Deleting and restoring items from quarantine do not require administrator credentials, while uninstalling the program always does.
Summary
Kaspersky Premium for Mac is a paid security solution that provides several security and privacy
features in a structured interface, including protection against phishing via browser extensions,
leakage of financial and personal data, and behaviour-based monitoring and blocking of suspicious
application activity. Some of its key aspects are:
- Straightforward installation and setup of core features.
- Well-organised interface providing access to all features.
- Multiple scan options and configurable settings, including scheduled and external storage
scans, as well as browsing-protection addons. - Clear alerts that keep users informed of detected issues.
- Administrative safeguards to prevent unauthorised changes.
Installation, Setup & Uninstallation
Setup begins by logging into the Kaspersky account at my.kaspersky.com, followed by downloading
and running the installer. The process provides step-by-step guidance with brief explanations
throughout. Additional protection features, such as Wi-Fi network protection and browser extensions
for Safari, Chrome, and Firefox, can optionally be enabled during setup. Once installed, the main
program window displays several recommendations, such as enabling automatic macOS updates,
activating location services, and installing missing browser extensions as well as supplemental apps
such as Kaspersky VPN and Password Manager (both included in the Premium plan). The program can
be uninstalled by navigating to Help > Support > Uninstall in the macOS menu bar, or by deleting it
from the macOS Applications folder.
General Handling & Essential Features
The main program window provides an overview of the protection status, scan options (Scan),
subscription information, system insights, and quick actions for privacy and system monitoring tools.
Settings, which includes protection features and scan exceptions (Trusted Zone), quarantine
(Detected Objects), and online help are accessible via the macOS menu bar. Manual updates can be
triggered from the main program window via Database Update or from the macOS menu bar.
Protection
From Scan, users can perform quick scans, full scans, or custom scans of specific files and folders.
The latter can also be initiated from the Finder context menu. Scans can be scheduled from Scan or
from Settings. Detection behaviour and further scan options, including external storage scans, are
also configurable under Settings; detection of stalkerware is enabled by default. The System Watcher
provides behaviour-based protection against emerging threats by monitoring applications for
suspicious activity in real time.
The Kaspersky Protection browser extension provides additional protection against malicious and
phishing websites. The Privacy and Identity sections provide additional features, including a data leak
checker and an identity theft checker, which scan for personal data associated with the user’s email
address or phone number in known data breaches. Further options include blocking applications from
accessing the device’s webcam and preventing websites from tracking browsing activity.
Alerts
If any protection feature is disabled via Settings > Protection, Kaspersky displays a persistent alert on
the main program window. Real-time protection can also be disabled from the system tray icon in the
macOS menu bar. Protection can be re-enabled by clicking the Enable button.
When malware was detected during the protection test, an alert appeared as shown below, displaying
the threat file path and action taken. No user action was required, and the alert closed automatically
after a few seconds. A shortcut to the quarantine is also displayed on the home page of the main
program window.
Quarantine & Logs
The Detected Objects page lists all isolated threats with their threat names and file paths. Clicking the
“…” menu next to an item allows the user to delete or restore it. A Delete All option is available for
bulk removal. Detailed logs of processed objects (detections), updates, scans, and protection feature
activity are accessible under Protection > Reports in the macOS menu bar.
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Settings or the system tray icon).
- Uninstalling the program.
Deleting and restoring items from quarantine do not require administrator credentials, while uninstalling the program always does.
Summary
Norton AntiVirus Plus for Mac is a paid antivirus product that provides essential security features, including AI-powered scam protection. Additional safeguards, such as browser extensions, are available separately. Some of its key aspects are:
- Straightforward installation and setup of core features.
- Clearly structured interface for easy navigation.
- Multiple scan options and configurable settings, including scheduled and external storage scans.
- Clear and persistent alerts that keep users informed of detected issues.
- Administrative safeguards to prevent unauthorised changes.
Please note that Norton, like Avast and AVG, is a product of Gen Digital. These products share identical core functionality, though there are some differences in their user interfaces.
Installation, Setup & Uninstallation
To install the program, the user must log into their Norton account at my.norton.com, download the installer file, and run it on their Mac. Users are guided through a step-by-step wizard with brief explanations. The program can be uninstalled via the macOS menu bar or by running the Norton Uninstaller directly from the macOS Applications folder.
General Handling & Essential Features
The main program window displays the current protection status, alongside quick access to smart scan, further scan options (Scans), protection features (Security), settings, and subscription information. The quarantine is accessible under Security > Quarantine and scan exceptions can be found under Security > Antivirus. Manual updates can be triggered via the LiveUpdate component or by selecting Check for Updates from the macOS menu bar. Online help is available via the Help menu, which directs users to the vendor’s support resources.
Protection
Under Scans on the Home, Security, or Settings page, users can perform smart scans, quick scans, full scans, or targeted scans of specific files and folders. The latter can also be initiated from the Finder context menu. Scheduled scans are configurable under the Custom Scans tab. External Drive Protection can be toggled under Antivirus > Real-Time Protection to automatically check for malware on mounted devices. Web protection is provided by the integrated Safe Web component, while the Intrusion Prevention module protects against network-based attacks, such as those exploiting vulnerable programs or originating from compromised network devices. The Smart Firewall allows users to monitor and control the network activity of installed applications, including the geographic locations of connected servers displayed on an interactive map. The Scam Protection feature uses AI to help identify and block scams across web browsing, emails, text messages, and calls. On macOS, scam protection within the product itself is limited to Safe Web, which detects phishing sites and fraudulent online stores. Additionally, users can submit content, including text messages, images, URLs, or YouTube video links, to Norton Genie, the vendor’s AI assistant, directly from within the program to check for potential scams.
Alerts
If real-time protection (Auto-Protect) under Security > Antivirus or other core shields (Smart Firewall, Safe Web) under Security are disabled, Norton displays a persistent alert in the main program window. Protection can be re-enabled by clicking the Enable button.
When malware was detected during the protection test, an alert window appeared as shown below. No user action was required, and the alert persisted until manually closed. Multiple detections are consolidated into a single alert window, navigable via on-screen arrows. Expanding the details section at the bottom of the alert displays further information, including the threat name, severity, file name/path, and associated process.
Quarantine & Logs
The quarantine is accessible from Security > Quarantine and lists all isolated threats, along with details such as the threat name, file name/path, and detection date. Users can delete items or, with administrative privileges, restore them.
Advanced Options
To enhance security, certain actions are limited to users with macOS Administrator accounts:
- Disabling protection features (under Security > Antivirus).
- Uninstalling the program.
- Restoring items from quarantine.
Summary
Trellix Endpoint Security (HX) is an enterprise-grade endpoint protection solution designed for large-scale deployments, supporting up to 100,000 endpoints per appliance. It provides a centralised management console available in multiple deployment formats (cloud-hosted, appliance-based, or Amazon-hosted) and includes advanced investigative and containment capabilities. Some of its key aspects are:
- Well-organised cloud console with drill-down views.
- Investigation and remediation tools for detailed threat analysis.
- Flexible search facility across endpoints and event data.
- Containment feature to isolate compromised endpoints.
- Prioritised threat notifications for administrators.
Management Console
The console is navigated via a top-page menu, providing access to key components such as threat monitoring, host management, search tools, and administrative controls. The most relevant sections and pages are described below.
Dashboard
Upon login, administrators are presented with an overview of system health and threat activity. This includes metrics such as the total number of hosts with alerts, split into four categories, along with summaries of recent file acquisitions and the status of contained, active, and inactive hosts.
Hosts > Hosts with Alerts page
This page lists all protected hosts with unresolved security alerts. Expanding an entry reveals a chronological breakdown of alerts, including detection type (e.g., signature-based), timestamps, scan type (on-access, on-demand), malware type and name, file status (e.g., quarantined), file attributes (path, hashes, size, modification and access times), and process information (e.g., PID, process path, associated user). Administrators can perform actions such as marking alerts as acknowledged or false positives, adding investigation comments, or managing quarantined items via the Quarantines tab.
Alerts page
This page provides a threat-centric view, displaying all detected threats across the organisation’s network. Threats can be sorted or filtered by attributes such as name, file path, file hash, hostname, host IP address, or event timestamps. Available actions include Acknowledge, Mark as False Positive, Delete, and Add Comment. Clicking on an entry’s name redirects to its full detail view under the Hosts with Alerts page.
Acquisitions page
This page lists all files acquired from endpoints, typically for forensic purposes. Acquisitions are generally initiated from the Hosts with Alerts page and can be downloaded securely for offline analysis.
Rules page
This page contains preconfigured and custom detection logic for identifying specific threats or suspicious behaviours. Rules include indicators of compromise (IOCs), exploit patterns, and known false positives, managed largely by Trellix’s Dynamic Threat Intelligence (DTI) cloud. Administrators can also create custom rules with specific detection conditions for their organisation’s environment.
Enterprise Search page
This search feature enables forensic investigation and threat hunting across all connected endpoints using predefined criteria. Supported search terms include application names, file and executable attributes (e.g., name, path, type, hash), network and web-related details (e.g., IP address, port, URL, DNS, browser, cookie, page), usernames, registry keys, process and service information, timestamps, system events, and more.
Admin section
This section provides controls for managing hosts, policies, and agents, as well as configuring data acquisition, appliance settings, and other system options. On the Policies page, administrators can define and configure endpoint protection policies, covering Exploit Guard Protection (Windows only), Malware Scans (e.g., scan on install, scheduled scan), polling intervals, Malware Protection (e.g., detection options, definition updates, exclusions, quarantine actions), Removal Protection, Tamper Protection, logging behaviours, and further agent settings. On the Host Sets page, hosts can be grouped dynamically based on defined criteria or manually via drag-and-drop. Policies can then be assigned to each host set.
Endpoint Protection Client
Deployment
The latest agent versions for macOS, Windows, and Linux are available under Admin > Agent Versions. Deployment can be performed manually or automated using system management tools such as Jamf. Manual installation requires Full Disk Access permission to be granted in the macOS system settings to ensure full functionality. After installation, the agent takes several minutes to initialise and download the necessary protection components.
General Handling & Alerts
The macOS agent operates silently in the background, with no local user interface or command-line access. During the protection test, no on-screen alerts were displayed on the host upon malware detection. All detection events are visible and manageable solely through the management console.
Award levels reached in this Mac Security Review
No Mac security product is ideal for every user. As with Windows products, we recommend drawing up a shortlist of suitable candidates after reading the reviews and noting the advantages and disadvantages of each. Free trial versions of the shortlisted products can then be installed and tested one at a time over a few days to help inform the final decision. Price, additional features, and support should also be taken into account before choosing a product.
All products tested this year qualify for the AV-Comparatives “Approved Mac Security” award. To be certified, each product had to meet our stringent Mac certification requirements, which are detailed on the following page.
Avast One Free for Mac combines malware protection with a clearly structured interface at no cost. It displays clear, persistent alerts upon threat detection, and includes a basic email guard and an AI assistant for scam checking.
AVG AntiVirus Free for Mac offers malware protection at no cost. Its tile-based interface is easy to navigate, malware detection alerts are clear and persistent, and web and email protection are included.
Bitdefender Antivirus for Mac is a paid antivirus product that includes malware and ransomware protection, a data-limited VPN, browser security extensions, and chat protection for popular messaging applications in a well-structured interface.
CrowdStrike Falcon Enterprise for Mac is an enterprise-grade endpoint security platform for medium to large organisations, offering centralised cloud-based management with advanced detection, response, and threat hunting capabilities.
ESET HOME Security Essential for macOS is a paid security product that delivers malware protection on macOS. It also includes web and email protection and a firewall within its clearly structured interface.
Intego ONE Complete is a paid Mac security application that consolidates malware protection, a firewall, system optimisation, and a VPN in a unified interface. Alerts are clearly displayed upon threat detection.
Kaspersky Premium for Mac is a paid security solution that includes malware protection, behaviour-based monitoring and blocking of suspicious application activity, and privacy features such as data leak checking and webcam access control.
Norton AntiVirus Plus for Mac is a paid antivirus product that provides malware protection, network threat prevention, and AI-powered scam protection. It displays clear, persistent alerts upon threat detection.
Trellix Endpoint Security (HX) for Mac is an enterprise endpoint protection solution for large-scale deployments, managed entirely through a web-based console with advanced investigative, search, and containment capabilities.

| AVG | APPROVED |
| Avast | APPROVED |
| Bitdefender | APPROVED |
| CrowdStrike | APPROVED |
| ESET | APPROVED |
| Intego | APPROVED |
| Kaspersky | APPROVED |
| Norton | APPROVED |
| Trellix | APPROVED |
Copyright and Disclaimer
This publication is Copyright © 2026 by AV-Comparatives ®. Any use of the results, etc. in whole or in part, is ONLY permitted after the explicit written agreement of the management board of AV-Comparatives prior to any publication. AV-Comparatives and its testers cannot be held liable for any damage or loss, which might occur as result of, or in connection with, the use of the information provided in this paper. We take every possible care to ensure the correctness of the basic data, but a liability for the correctness of the test results cannot be taken by any representative of AV-Comparatives. We do not give any guarantee of the correctness, completeness, or suitability for a specific purpose of any of the information/content provided at any given time. No one else involved in creating, producing or delivering test results shall be liable for any indirect, special or consequential damage, or loss of profits, arising out of, or related to, the use or inability to use, the services provided by the website, test documents or any related data.
For more information about AV-Comparatives and the testing methodologies, please visit our website.
AV-Comparatives
(June 2026)





















































