Published: October 14, 2025
8
5
80

"Security Researcher" claims they evade all AVs easily. But the sample they used for testing is not malicious, it is just calc.exe. I know the industry is not perfect, but testing malware detection with non-malicious payload is ridiculous. https://www.reddit.com/r/antiv...

@struppigel Going to gently push back on you there. Yes, payloads and calling apps can/should be scanned... but why are odd/suspicious invocations even allowed? I don't think calc.exe is enough, but it's a DAMN good start and shows issues.

@bettersafetynet @struppigel Because in OP's testing sample was only consumer grade tools that can't afford a high or even medium false positive rate since nobody else is gonna classify these alerts

@colere_0 @struppigel well tbf, the alert logic in EVERY security tool can be better... but The Fear of False Positives causes more attack surface than just about any other issue. We need a serious re-think on what security tooling should be

@bettersafetynet @struppigel Oh no for sure there can be improvements, but I think this distinction between personal and professional environnements is important in this context especially, since in personnal use too much user friction might mean them uninstalling the solution, good balance is hard to find

Share this thread

Read on Twitter

View original thread

Navigate thread

1/5