Test: Can endpoint solutions be manipulated?

Test: Can endpoint solutions be manipulated?
Advertising

Share post

AV-Comparatives has published the results of its anti-tampering certification test, which shows whether endpoint solutions defend themselves against tampering: CrowdStrike, ESET, Kaspersky and Palo Alto Networks are among those taking part.

The test attempts to disable or modify user and kernel space components of endpoint solutions to assess their anti-tampering properties. The test evaluates whether it is possible to disable or change AV/EPP/EDR components or functions through manipulation, with all tampering activities (manipulation) performed in the Windows user area. The following products are included in the test.

Advertising
  • Crowd Strike Falcon Enterprise
  • ESET PROTECT Entry
  • Kaspersky Endpoint Security for Business
  • Palo Alto Networks Cortex XDR Prevent

Manipulation: what needs to be defended against?

To be approved by AV-Comparatives as an anti-tampering protection, all tampering attempts made during the test must be prevented. With various tests, tools and procedures, the testers try to penetrate the endpoint solutions or test the tamper resistance of each product. Attempts are made to disable the most important functions as part of prevention by affecting various diverse components of the respective product.

  • Test 1: Successfully protected against manipulation attacks that could lead to a temporary or permanent and partial or complete deactivation of the EDR functionality was not possible.

The following components or categories have been tested against tampering attacks that could result in permanent, temporary, partial, or total loss of product functionality:

Advertising

Subscribe to our newsletter now

Read the best news from B2B CYBER SECURITY once a month



By clicking on "Register" I agree to the processing and use of my data in accordance with the declaration of consent (please open for details). I can find more information in our Privacy Policy. After registering, you will first receive a confirmation email so that no other person can order something you don't want.
Expand for details on your consent
It goes without saying that we handle your personal data responsibly. If we collect personal data from you, we process it in compliance with the applicable data protection regulations. Detailed information can be found in our Privacy Policy. You can unsubscribe from the newsletter at any time. You will find a corresponding link in the newsletter. After you have unsubscribed, your data will be deleted as soon as possible. Recovery is not possible. If you would like to receive the newsletter again, simply order it again. Do the same if you want to use a different email address for your newsletter. If you would like to receive the newsletter offered on the website, we need an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. Further data is not collected or only collected on a voluntary basis. We use newsletter service providers, which are described below, to process the newsletter.

CleverReach

This website uses CleverReach to send newsletters. The provider is CleverReach GmbH & Co. KG, Schafjückenweg 2, 26180 Rastede, Germany (hereinafter “CleverReach”). CleverReach is a service that can be used to organize and analyze the sending of newsletters. The data you enter for the purpose of subscribing to the newsletter (e.g. email address) will be stored on the CleverReach servers in Germany or Ireland. Our newsletters sent with CleverReach enable us to analyze the behavior of the newsletter recipients. This can include It is analyzed how many recipients have opened the newsletter message and how often which link in the newsletter was clicked. With the help of so-called conversion tracking, it can also be analyzed whether a previously defined action (e.g. purchase of a product on this website) took place after clicking on the link in the newsletter. Further information on data analysis by CleverReach newsletter is available at: https://www.cleverreach.com/de/funktionen/reporting-und-tracking/. The data processing takes place on the basis of your consent (Art. 6 Para. 1 lit. a DSGVO). You can revoke this consent at any time by unsubscribing from the newsletter. The legality of the data processing operations that have already taken place remains unaffected by the revocation. If you do not want an analysis by CleverReach, you must unsubscribe from the newsletter. For this purpose, we provide a corresponding link in every newsletter message. The data you have stored with us for the purpose of subscribing to the newsletter will be stored by us or the newsletter service provider until you unsubscribe from the newsletter and deleted from the newsletter distribution list after you have canceled the newsletter. Data stored by us for other purposes remain unaffected. After you have been removed from the newsletter distribution list, your e-mail address may be stored by us or the newsletter service provider in a blacklist if this is necessary to prevent future mailings. The data from the blacklist is only used for this purpose and is not merged with other data. This serves both your interest and our interest in complying with the legal requirements when sending newsletters (legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR). Storage in the blacklist is not limited in time. You may object to the storage if your interests outweigh our legitimate interest. For more information, see the privacy policy of CleverReach at: https://www.cleverreach.com/de/datenschutz/.

Data processing

We have concluded a data processing agreement (DPA) for the use of the above-mentioned service. This is a contract mandated by data privacy laws that guarantees that they process personal data of our website visitors only based on our instructions and in compliance with the GDPR.
  • User-space processes, including threads and handles (terminate, suspend, etc.)
  • Services in user space (pause, stop, disable, uninstall, etc.)
  • Registry keys (delete, remove, rename, add, etc.)
  • DLLs (manipulation, modification, hijacking, etc.)
  • Agent integrity (disable, change, uninstall, etc.)
  • File system (manipulation, modification, etc.)
  • Kernel drivers (ELAM drivers, filter drivers, minifilter drivers, etc.)
  • Other components and functions (e.g. connection to update services, etc.)

All 4 products CrowdStrike Falcon Enterprise, ESET PROTECT Entry, Kaspersky Endpoint Security for Business and Palo Alto Networks Cortex XDR Prevent successfully passed the test and received the “Approved Anti Tempering 2023” certificate from AV-Comparatives.

More at AV-Comparatives.org

 


About AV-Comparatives

AV-Comparatives is an independent AV test laboratory based in Innsbruck, Austria, and has been publicly testing computer security software since 2004. It is certified according to ISO 9001: 2015 for the area of ​​"Independent tests of anti-virus software". It also has EICAR certification as a "Trusted IT Security Testing Lab".


 

Matching articles on the topic

Agent-based cybersecurity with an open source model

Trend Micro’s AI agent Trend Cybertron is released as an open source model. The AI ​​model and agent framework1 is intended to facilitate the development of autonomous ➡ Read more

OpenCloud: Alternative file management solution

File management, file sharing and content collaboration - but in new ways and away from solutions of the large digital corporations Microsoft SharePoint ➡ Read more

Protect IoT and OT environments with MXDR

With the increasing number of IoT and OT devices, companies are increasing their attack surfaces for cybercriminals. Last year, almost every ➡ Read more

Hybrid SASE solution FireCloud Internet Access

With FireCloud Internet Access, WatchGuard Technologies presents the first product in a new family of hybrid Secure Access Service Edge (SASE) solutions. ➡ Read more

Proactive cybersecurity AI fends off attacks

Trend Micro's first proactive cybersecurity AI sets new standards with new capabilities for proactive risk management, threat modeling, attack path ➡ Read more

Chinese cyber espionage is increasing dramatically

The Global Threat Report 2025 published shows an increasing aggressiveness of Chinese cyber espionage, a rise in GenAI-based social engineering and vulnerability research ➡ Read more

Cybersecurity: Improved Enterprise Browser 

With the Enterprise Browser as part of the fully integrated SSE, companies can enable access from unmanaged devices, BYOD and ➡ Read more

Against cyber risks: Platform for risk management

Quickly identify security gaps and thus mitigate cyber risks: The new application extends Zscaler’s Exposure Management solution and offers a single ➡ Read more