Antivirus Software

For personal use I just use Defender in windows plus using standard accounts so even if malware infiltrates the system, it cannot make critical changes, install itself system-wide, or access sensitive files without additional authorization otherwise I don't even use one in Linux. At work, I use Kaspersky.
 
This is such a loaded question. Too many anti-virus programs have become adware. The correct answer is "it depends"

For most individuals, anti-virus is no longer needed and will not protect you from what you fall for now. Many OS tools are sufficient.

For most companies, anti-virus is severely lacking, and you need endpoint protection.

FYI - Some infections now sit in EUFI, so reinstallation is insufficient to clear them off. Luckily, this is not the norm yet.

Just my 2 cents.
 
  • Like
Reactions: Trevor Chandler
This is such a loaded question. Too many anti-virus programs have become adware. The correct answer is "it depends"

For most individuals, anti-virus is no longer needed and will not protect you from what you fall for now. Many OS tools are sufficient.

For most companies, anti-virus is severely lacking, and you need endpoint protection.

FYI - Some infections now sit in EUFI, so reinstallation is insufficient to clear them off. Luckily, this is not the norm yet.

Just my 2 cents.
A loaded question? This question doesn't even come close to a toy pistol :)

Endpoint protection is a little vague to me. Expound for me a tad more, please.

Thanks for the FYI! I wasn't aware of this.

Love your commentary!!! I feel you're selling yourself short by referring to your
comments as "2 cents". I had it at no less than a dime :)

Thanks Jeff!!!
 
  • Like
Reactions: precious
This is such a loaded question. Too many anti-virus programs have become adware. The correct answer is "it depends"

For most individuals, anti-virus is no longer needed and will not protect you from what you fall for now. Many OS tools are sufficient.

For most companies, anti-virus is severely lacking, and you need endpoint protection.

FYI - Some infections now sit in EUFI, so reinstallation is insufficient to clear them off. Luckily, this is not the norm yet.

Just my 2 cents.
Looks like even malware is leveling up faster than some antivirus software! Guess we’re all doomed if EUFI infections become the norm!
 
  • Like
Reactions: Trevor Chandler
A loaded question? This question doesn't even come close to a toy pistol :)

Endpoint protection is a little vague to me. Expound for me a tad more, please.

Thanks for the FYI! I wasn't aware of this.

Love your commentary!!! I feel you're selling yourself short by referring to your
comments as "2 cents". I had it at no less than a dime :)

Thanks Jeff!!!

Endpoint protection aims to monitor and protect your systems. One of the most widely known, not just for the airline outage it caused, is Crowdstrike. You can find them at https://www.crowdstrike.com/. One benefit over antivirus is your system logs are sent to a central point where they are being analyzed. If any one of their clients gets a new, unknown virus, they can immediately roll out fixes for that to all of the endpoints.

They can also map, and intervene against something as it tries to move through your environment. They have their own security operations center (SOC) that can liaise with your SOC.

Every once and a while I get in trouble because something I am doing lights up their systems like it is a Christmas tree. They like to know when I am doing certain assignments so they can expect and just alert and not act when I am up to no good with my class.
 
  • Like
Reactions: Trevor Chandler
So, I've gotten rather cozy to Windows Defender for Endpoint. While WDE leverages Defender on the Windows workstation, it also creates that all important Endpoint protection piece, which allows for all the classic AV functions, but also for enterprise management, Identity (for use in older AD environments), XDR (SIEM/SOAR), threat intelligence, hunting, all that good stuff.

But Layer 8 is the best AV protection, by far.

/r
 
  • Like
Reactions: Trevor Chandler
So, I've gotten rather cozy to Windows Defender for Endpoint. While WDE leverages Defender on the Windows workstation, it also creates that all important Endpoint protection piece, which allows for all the classic AV functions, but also for enterprise management, Identity (for use in older AD environments), XDR (SIEM/SOAR), threat intelligence, hunting, all that good stuff.

But Layer 8 is the best AV protection, by far.

/r
Layer 8? Okay, you're over my head now. Expound please!!!!