AV - should companies keep buying it?
-
I asked about this before - and felt we didn't really discuss it much.
So again I'm asking.
Also - would it be better money spent on a solution for patch management?
Sure Chocolatey covers a lot of freeware/shareware, but it doesn't handle most paid software.It seems that updating software daily is much more critical to systems being secure instead of trying to rely on AV.
Thoughts?
-
Should companies buy AV?
Generally, I would say "no". Not that they shouldn't have AV, but good AV is free and maintained by the system. Additional AV isn't necessarily bad, but the cost of it is often ridiculously high and very difficult to justify. There are good AV programs out there like Webroot and Bitdefender. But Defender is good, too, and included.
AV is mostly a panacea today. It's a second line of defense, but typically only turning out to be useful at times when blatant disregard for security basics were already the cause of problems. And third party AV in the real world seems to cause more issues than it solves.
-
@Dashrender said in AV - should companies keep buying it?:
It seems that updating software daily is much more critical to systems being secure instead of trying to rely on AV.
This has always been the case, education is just leading more people to realize how many people have not patched in the past and people are more prepared to hold those not patching accountable for the risk that they put people at.
-
AV was super important in the era of "no security" with DOS and Windows 98, for example. AV was "the security mechanism" that you added to your system. Since the Windows NT family has security mechanisms, the role of AV has almost always been just a placebo, or nearly so.
-
Now I want to compare the third party setup to a bare bones windows defender setup. Our webroot protected systems get 10/10 (totally stops all ransomware tests) when testing with ransim. I guess I'll spin up a win 10 VM and see what that scores.
-
@RojoLoco said in AV - should companies keep buying it?:
Now I want to compare the third party setup to a bare bones windows defender setup. Our webroot protected systems get 10/10 (totally stops all ransomware tests) when testing with ransim. I guess I'll spin up a win 10 VM and see what that scores.
Since it's simulated - I'm not sure I think it has any real value. True attacks are using both old and zero day exploits - I'm guessing very little will stop zero day exploits, the number one thing is user education and awareness.
-
@Dashrender said in AV - should companies keep buying it?:
@RojoLoco said in AV - should companies keep buying it?:
Now I want to compare the third party setup to a bare bones windows defender setup. Our webroot protected systems get 10/10 (totally stops all ransomware tests) when testing with ransim. I guess I'll spin up a win 10 VM and see what that scores.
Since it's simulated - I'm not sure I think it has any real value. True attacks are using both old and zero day exploits - I'm guessing very little will stop zero day exploits, the number one thing is user education and awareness.
True, but I have no other way to test short of trying to get infected on purpose. And I know it's not testing the user-clicked-a-dumb-link scenario. I think the real test will be if defender freaks out when I unzip the installer (like webroot did). That shows that it is detecting something at least.
-
@Dashrender said in AV - should companies keep buying it?:
@RojoLoco said in AV - should companies keep buying it?:
Now I want to compare the third party setup to a bare bones windows defender setup. Our webroot protected systems get 10/10 (totally stops all ransomware tests) when testing with ransim. I guess I'll spin up a win 10 VM and see what that scores.
Since it's simulated - I'm not sure I think it has any real value. True attacks are using both old and zero day exploits - I'm guessing very little will stop zero day exploits, the number one thing is user education and awareness.
I'd say it has some value, but not a ton. Middle ground. It's telling, but not definitive.
-
We use it as a last ditch tool to protect end users from themselves. Necessary no, useful yes.
Bonus - sophos also manages our bit defender keys
Bonus x2 - sophos also does phish testing, which is not only useful but also amusing
Bonus x3 - sophos actually works and doesn't do dumb stuff that wastes my time.
-
@MattSpeller said in AV - should companies keep buying it?:
We use it as a last ditch tool to protect end users from themselves. Necessary no, useful yes.
Bonus - sophos also manages our bit defender keys
Bonus x2 - sophos also does phish testing, which is not only useful but also amusing
Bonus x3 - sophos actually works and doesn't do dumb stuff that wastes my time.
#3 is why I like webroot. Easy central control. Can you get any kind of management console for windows defender without giving MS a bunch more money?
-
@scottalanmiller said in AV - should companies keep buying it?:
And third party AV in the real world seems to cause more issues than it solves.
This is really what it boils down to. Adding 3rd party security software to a system has to open more holes in the underlying operating system, for itself at the bare minimum. Instead of providing additional security, they increase the attack surface. Just the opposite of what your trying to do.
That's not to say they are never worth while. A centralized dashboard to manage all the computers can be well worth the cost.
-
@scottalanmiller said in AV - should companies keep buying it?:
@Dashrender said in AV - should companies keep buying it?:
@RojoLoco said in AV - should companies keep buying it?:
Now I want to compare the third party setup to a bare bones windows defender setup. Our webroot protected systems get 10/10 (totally stops all ransomware tests) when testing with ransim. I guess I'll spin up a win 10 VM and see what that scores.
Since it's simulated - I'm not sure I think it has any real value. True attacks are using both old and zero day exploits - I'm guessing very little will stop zero day exploits, the number one thing is user education and awareness.
I'd say it has some value, but not a ton. Middle ground. It's telling, but not definitive.
really? sounds like it's little more than the eicar test. yep.. the AV detected the known pattern - yeah.. lol
-
@RojoLoco said in AV - should companies keep buying it?:
@MattSpeller said in AV - should companies keep buying it?:
We use it as a last ditch tool to protect end users from themselves. Necessary no, useful yes.
Bonus - sophos also manages our bit defender keys
Bonus x2 - sophos also does phish testing, which is not only useful but also amusing
Bonus x3 - sophos actually works and doesn't do dumb stuff that wastes my time.
#3 is why I like webroot. Easy central control. Can you get any kind of management console for windows defender without giving MS a bunch more money?
no of course not - but you didn't get it from Webroot for free either.
As for actually getting reporting - You could get logs from the local machine via powershell and a logging server, then run reports, etc, etc, etc...
but yeah - that is kinda ugly. -
@travisdh1 said in AV - should companies keep buying it?:
@scottalanmiller said in AV - should companies keep buying it?:
And third party AV in the real world seems to cause more issues than it solves.
This is really what it boils down to. Adding 3rd party security software to a system has to open more holes in the underlying operating system, for itself at the bare minimum. Instead of providing additional security, they increase the attack surface. Just the opposite of what your trying to do.
That's not to say they are never worth while. A centralized dashboard to manage all the computers can be well worth the cost.
To what end though? If the centralized console tells you it stopped an infection - now what? do you actually review what the user was doing? I suppose if you want to read daily reports that the AV is updated - you could get that from WSUS for Windows machines, though BYOD makes that kinda hard - though not impossible.
-
@RojoLoco said in AV - should companies keep buying it?:
#3 is why I like webroot. Easy central control. Can you get any kind of management console for windows defender without giving MS a bunch more money?
You can make your own, but that's the same as spending money (basically.) The nice thing about Defender is that you rarely need central control. If that's something you need, then Defender is weak today. But rarely have we found a need for that.
-
@Dashrender said in AV - should companies keep buying it?:
@travisdh1 said in AV - should companies keep buying it?:
@scottalanmiller said in AV - should companies keep buying it?:
And third party AV in the real world seems to cause more issues than it solves.
This is really what it boils down to. Adding 3rd party security software to a system has to open more holes in the underlying operating system, for itself at the bare minimum. Instead of providing additional security, they increase the attack surface. Just the opposite of what your trying to do.
That's not to say they are never worth while. A centralized dashboard to manage all the computers can be well worth the cost.
To what end though? If the centralized console tells you it stopped an infection - now what? do you actually review what the user was doing? I suppose if you want to read daily reports that the AV is updated - you could get that from WSUS for Windows machines, though BYOD makes that kinda hard - though not impossible.
That's my take on it, that's not information that I really want people sifting through under normal circumstances.
-
@Dashrender said in AV - should companies keep buying it?:
As for actually getting reporting - You could get logs from the local machine via powershell and a logging server, then run reports, etc, etc, etc...
but yeah - that is kinda ugly.Kinda ugly, once. But once you have the tools, it is free "forever." I wonder if ELK or something does that well.
-
@scottalanmiller said in AV - should companies keep buying it?:
@Dashrender said in AV - should companies keep buying it?:
As for actually getting reporting - You could get logs from the local machine via powershell and a logging server, then run reports, etc, etc, etc...
but yeah - that is kinda ugly.Kinda ugly, once. But once you have the tools, it is free "forever." I wonder if ELK or something does that well.
That was my wondering as well.
-
@scottalanmiller said in AV - should companies keep buying it?:
@Dashrender said in AV - should companies keep buying it?:
@travisdh1 said in AV - should companies keep buying it?:
@scottalanmiller said in AV - should companies keep buying it?:
And third party AV in the real world seems to cause more issues than it solves.
This is really what it boils down to. Adding 3rd party security software to a system has to open more holes in the underlying operating system, for itself at the bare minimum. Instead of providing additional security, they increase the attack surface. Just the opposite of what your trying to do.
That's not to say they are never worth while. A centralized dashboard to manage all the computers can be well worth the cost.
To what end though? If the centralized console tells you it stopped an infection - now what? do you actually review what the user was doing? I suppose if you want to read daily reports that the AV is updated - you could get that from WSUS for Windows machines, though BYOD makes that kinda hard - though not impossible.
That's my take on it, that's not information that I really want people sifting through under normal circumstances.
Yeah, and when you really need it, it's already failed.
-
@scottalanmiller said in AV - should companies keep buying it?:
@RojoLoco said in AV - should companies keep buying it?:
#3 is why I like webroot. Easy central control. Can you get any kind of management console for windows defender without giving MS a bunch more money?
You can make your own, but that's the same as spending money (basically.) The nice thing about Defender is that you rarely need central control. If that's something you need, then Defender is weak today. But rarely have we found a need for that.
The console is mostly to see who did something stupid so I can say "hey, don't do that shit".