惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
WordPress大学
WordPress大学
Google DeepMind News
Google DeepMind News
T
The Exploit Database - CXSecurity.com
阮一峰的网络日志
阮一峰的网络日志
F
Fox-IT International blog
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
I
Intezer
P
Privacy & Cybersecurity Law Blog
B
Blog RSS Feed
Latest news
Latest news
小众软件
小众软件
A
Arctic Wolf
Attack and Defense Labs
Attack and Defense Labs
L
LINUX DO - 热门话题
博客园 - 聂微东
B
Blog
T
Troy Hunt's Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
Malwarebytes
Malwarebytes
爱范儿
爱范儿
Recorded Future
Recorded Future
Apple Machine Learning Research
Apple Machine Learning Research
人人都是产品经理
人人都是产品经理
D
Docker
T
Threat Research - Cisco Blogs
MyScale Blog
MyScale Blog
Martin Fowler
Martin Fowler
E
Exploit-DB.com RSS Feed
F
Fortinet All Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
PCI Perspectives
PCI Perspectives
Scott Helme
Scott Helme
N
Netflix TechBlog - Medium
博客园 - 三生石上(FineUI控件)
T
True Tiger Recordings
C
Check Point Blog
Microsoft Azure Blog
Microsoft Azure Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
K
Kaspersky official blog
Security Latest
Security Latest
The Hacker News
The Hacker News
Microsoft Security Blog
Microsoft Security Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
Stack Overflow Blog
Stack Overflow Blog
S
Security @ Cisco Blogs
C
CXSECURITY Database RSS Feed - CXSecurity.com
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
M
Microsoft Research Blog - Microsoft Research

Business Insights Cybersecurity Blog by Bitdefender

Bitdefender Supports Ferrari Through Cybersecurity Built on Trust Endpoint Detection & Response is Table Stakes Security MSP Strategic Defense: Why Dual-Layer Email Security (SEG + API) Is Now Essential Bitdefender Threat Debrief | May 2026 Bitdefender Named an Omdia Champion: What It Means for MSPs Ready to Lead Technical Advisory: ShinyHunters Breach of Instructure Canvas LMS What’s New in GravityZone May 2026 (v 6.73) Endpoint Protection in Practice: How Customers Use Bitdefender to Reduce Risk Introducing Proactive Hardening and Attack Surface Reduction (PHASR) for Linux and macOS A Cybersecurity Lifeline for Lean IT Teams: Introducing C.R.E.W. Bitdefender at Black Hat Asia 2026: Disrupt Attacker Playbooks Introducing Extended Email Security What’s New in GravityZone April 2026 (v 6.72) What Mythos Reveals About Zero Trust’s Scope Problem Bitdefender Threat Debrief | April 2026 Shut the Front Door on Email Attacks: How to Scale Security Services Without Increasing Workload Technical Advisory: Axios npm Supply Chain Attack - Cross-Platform RAT Deployed via Compromised Maintainer Account Your Biggest Cyber Risk Could Be What You Already Trust Ransomware Attacks Against the US: 2026 Insights RSAC 2026: What to Expect from Bitdefender Bitdefender Threat Debrief | March 2026 A Cyber Resilience Agenda: Inside the European Central Bank’s 2026–2028 Priorities AI in Cybersecurity: Is It Worth the Effort for Lean Security Teams? MSP Strategic Defense: Building Compliance on Dynamic Attack Surface Reduction Master XDR Investigations: A Deep Dive into the GravityZone XDR Demo Incident IDC Market Note: Surging Demand for EU Data Sovereignty Drives New Cybersecurity-Cloud Partnership Bitdefender Threat Debrief | February 2026
Bitdefender GravityZone: 100% Telemetry in AV-Comparatives 2026 EDR Test
Richard De L · 2026-05-15 · via Business Insights Cybersecurity Blog by Bitdefender

Bitdefender GravityZone Business Security Enterprise recorded 100% relevant telemetry across all 14 attack steps during our inaugural participation in AV-Comparatives’ EDR Detection Validation Certification Test, published May 2026. Bitdefender was the only certified product to achieve complete chain-of-attack visibility.

edr-detection-test-1

The results reflect Bitdefender’s research-led prevention architecture which is also applied to detection: when defensive layers are built to understand the attack surface before exploitation, the same behavioral models that prevent attacks also surface them when operating in detection-only mode.

What Are Key results of the 2026 AV-Comparatives EDR Detection Validation Certification Test?

  • Bitdefender recorded relevant telemetry across all 14 attack steps in the test scenario, the only product to achieve 100% visibility among the 9 certified products.
  • Bitdefender alerted on 11 of 14 attack steps (Active Response), tied for highest in the cohort with Palo Alto and ESET.
  • Combined detection coverage (alert or telemetry): 14 of 14 attack steps – full visibility across the intrusion chain.
  • Signal-to-Noise: 1 false alert across 5 benign-activity scenarios, well under the certification threshold of 3.
  • Alert correlation: 245 alerts consolidated into 3 incidents, reducing analyst workload through automated cross-stage correlation.

Source:

Bitdefender report, AV-Comparatives EDR Detection Validation Certification Test 2026

.

How Was the 2026 AV-C EDR Certification Test Conducted?

The evaluation used a 14-step attack scenario inspired by APT29 (Cozy Bear), APT41 (Winnti), APT27 (Emissary Panda), APT10 (Stone Panda), and FIN7 (Carbanak) tactics. AV-Comparatives’ EDR Detection Validation Certification Test measures how completely endpoint detection and response (EDR) platforms surface attack activity across a multi-stage intrusion. Bitdefender GravityZone Business Security Enterprise finished first among the nine certified products evaluated.

The scenario covered initial access via a spearphishing link, persistence through scheduled-task masquerading, credential access (Kerberoasting, an attack targeting service account credentials by requesting Kerberos tickets, and DCSync, a technique that mimics domain-controller replication to extract password hashes), lateral movement across three systems (WS01 → FS01 → DC01), privilege escalation, and command-and-control through a live C2 framework with redirector infrastructure on Azure (a proxy infrastructure masking the attacker’s actual server to evade detection).

All products were configured in detection-only mode, meaning no blocking or prevention capabilities were active.

The test isolates detection visibility – what the product sees and reports to analysts – from prevention quality. AV-Comparatives’ separate EPR Test covers prevention effectiveness. It’s no accident that Bitdefender GravityZone was the only vendor platform to achieve 100% prevention in the initial attack phase during the EPR Test for 2025. This year’s certification test focuses exclusively on whether the product gives analysts enough visibility to reconstruct what happened.

edr-detection-test-2

Two metrics determine the result:

  • Active Response (alerting): Does the product generate an alert for this attack step?
  • Telemetry (threat-hunting visibility): Does the product record enough event data and forensic logs that an analyst could reconstruct this attack step during investigation, even without an alert?

A separate Signal-to-Noise assessment tests whether the product generates false alerts on benign administrative activity. For full methodology detail, see the published test report.

Full Results Table

The following table consolidates Active Response, Telemetry, and Signal-to-Noise results across all 9 certified products in AV-Comparatives’ the 2026 EDR Detection Validation Certification Test. AV-Comparatives publishes per-vendor reports for this certification test; this view merges them for cross-vendor comparison.

Source: AV-Comparatives EDR Detection Validation Certification Test 2026 individual vendor reports. Table compiled by Bitdefender. Cohort median computed from published scores.

Results in Context

In the 2026 AV-Comparatives’ EDR Detection Validation Certification Test, Bitdefender was the only certified product to record relevant telemetry across every step of a 14-stage attack chain.

The result reflects Bitdefender’s prevention-first posture applied to detection.

Prevention-first architecture means understanding the attack surface and emerging-attack patterns through sustained research, then building defensive layers for those attacks before they appear in the wild.

AV-Comparatives noted Bitdefender’s visibility across the intrusion chain explicitly. The lateral-movement stage (Step 11, compromising DC01 via WinRM) was cited as “one of the strongest parts of the evaluation,” with detections tying remote execution to privileged account context through WinRM, PowerShell, AMSI (Antimalware Scan Interface, a Windows telemetry hook that intercepts script content before execution), and wsmprovhost.exe (the Windows Remote Management process host) activity.

The DCSync credential-theft technique (Step 14) demonstrates the telemetry-depth advantage. DCSync mimics domain-controller replication to extract password hashes – a technique that leaves minimal forensic traces because it uses legitimate domain-controller protocols. Bitdefender did not generate an alert on Step 14 but surfaced the activity through telemetry: domain-controller replication detections mapped directly to the DCSync attempt, giving analysts enough context to reconstruct what happened. When replication traffic originates from a non-domain-controller system in an unusual user context, that’s detectable – if the product is recording the right data.

edr-detection-test-3

Bitdefender consolidated 245 alerts into 3 incidents through automated correlation. Alert volume alone is not a quality signal; what matters is whether an analyst can reconstruct the attack without manually stitching together hundreds of disconnected events. Three incidents for a 14-step intrusion spanning three systems demonstrates analyst-workload efficiency.

Resources

For the full Bitdefender report, including stage-by-stage detection breakdowns and alert-correlation details, see the published certification document.

You can also learn more about the Bitdefender GravityZone platform.