惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
雷峰网
雷峰网
Google DeepMind News
Google DeepMind News
Y
Y Combinator Blog
Microsoft Security Blog
Microsoft Security Blog
M
MIT News - Artificial intelligence
WordPress大学
WordPress大学
MongoDB | Blog
MongoDB | Blog
V
V2EX
博客园 - 【当耐特】
GbyAI
GbyAI
Stack Overflow Blog
Stack Overflow Blog
I
InfoQ
Martin Fowler
Martin Fowler
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Hugging Face - Blog
Hugging Face - Blog
B
Blog
V
Visual Studio Blog
D
DataBreaches.Net
C
Check Point Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
F
Fortinet All Blogs

Business Insights Cybersecurity Blog by Bitdefender

What’s New in GravityZone September 2026 (v 6.77) The New AI Arms Race Starts Before the Attack Why Are So Many Security Professionals Keeping Breaches Quiet? Everyone Says Security Consolidation Saves Money. Four Organizations Did the Math The Next MDR Evolution: Digital Sovereignty, Trusted AI, Continuous Protection Frontier AI and the Changing Dynamics of Cybersecurity Bitdefender Threat Debrief | August 2026 Rapidly Rising Risk: AI in the Shadows GravityZone Achieves Top Results in AV-Comparatives Testing When Visibility Becomes the Target: Bitdefender at Black Hat USA 2026 Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core Bitdefender Recognized as a Major Player in the 2026 IDC MarketScape for Worldwide MDR Service for Midmarket What’s New in GravityZone July 2026 (v 6.75) Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR Bitdefender Threat Debrief | July 2026 Trust Under Attack: How Deepfakes Are Rewriting Cybercrime Your AI SOC Won’t Catch Ransomware by Itself 2026 Cybersecurity Assessment: The Gap Between Knowing and Doing Your Last Red Team Tested the Wrong Attack MSP Strategic Defense: Why MDR Is the New Security Baseline for MSPs Technical Advisory: FortiBleed Credential Exposure Campaign Targeting Internet-Facing Fortinet Devices Bitdefender Recognized in the 2026 Gartner® Europe Context: Magic Quadrant™ for Endpoint Protection CISA Mandates Change for Structured, Prioritized Updates and Vulnerability Management Claimed Twice: Five Reasons the Same Ransomware Victim Shows Up Under Two Flags What’s New in GravityZone June 2026 (v 6.74) Bitdefender Threat Intelligence: Built for How Security Teams Work Bitdefender Threat Debrief | June 2026 Cut Complexity in Half While Reducing Risk Across Your Endpoint Environment Bitdefender Named a Visionary in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection How Leading Organizations Turn EDR Into Operational Resilience
Bitdefender Achieves AV-Comparatives EPR Certified Leader...
Richard De La Torre · 2026-09-15 · via Business Insights Cybersecurity Blog by Bitdefender

AV-Comparatives has published its Endpoint Prevention and Response (EPR) Comparative Report for 2026.

Across 50 targeted attack scenarios, Bitdefender GravityZone Business Security Enterprise shut down every attack automatically in the first phase, before any of them established a foothold. No lateral movement to chase. No asset breach to contain.

The attacks ended where they started, and Bitdefender GravityZone did it without blocking a single legitimate program or leaving an analyst waiting on a sandbox verdict.

That is the result of the 2026 evaluation, and what follows is the context around it.

What Does the EPR Test Measure?

The EPR test is not a malware scan. AV-Comparatives builds complete attack chains and runs them end to end, which is a much harder thing to defend against and a much more useful thing to measure.

Each of the 50 scenarios moves through three phases:

  • Phase 1, Endpoint Compromise and Foothold: Initial access, execution, and persistence. This is the attacker getting in and staying in.

  • Phase 2, Internal Propagation: Privilege escalation, defense evasion, credential access, discovery, and lateral movement. This is the attacker spreading.

  • Phase 3, Asset Breach: collection, command and control, exfiltration, and impact. This is the attacker getting what they came for.

If a product fails to stop an attack in one phase, the scenario continues into the next. Every product is scored on two different abilities. Active response, which means the product stopped the attack by itself, and passive response, which means it did not stop the attack, but it raised an alert an administrator could act on. The scenarios map to the MITRE ATT&CK framework and draw on the tradecraft of real groups, including APT28, APT29, Lazarus, Kimsuky, FIN7, Black Basta, and LockBit.

Stopping Attacks at the Front Door

Phase 1 active response is the cleanest measure of prevention in the report, because it shows how often a product stopped an attack before the attacker had anything to work with.

Image: Bitdefender GravityZone stopped all 50 attack scenarios automatically during Phase 1, one of three products in the test to do so.

Bitdefender GravityZone stopped 100% of the 50 scenarios in Phase 1. Eleven other products let somewhere between 4% and 32% of attacks past the foothold stage, where they then had to be caught later in the chain.

That gap is critical.

An attack stopped in Phase 1 costs you nothing: no investigation, no containment, no cleanup, no incident report. An attack stopped in Phase 2 has already escalated privileges or moved laterally, and now somebody on your team owns a ticket. AV-Comparatives prices this directly into its model, applying 0% of the breach impact when an attack is actively stopped and reported in Phase 1, 25% when it is stopped in Phase 2, and 75% when it is stopped in Phase 3.

In simplest terms: you’re either catching an intruder at the door or catching them in the server room. Both are technically successes, but only one of the scenarios means you sleep that night.

Security That Stays Out of the Way

Prevention is easy to buy if you are willing to block everything that moves. But what if you need prevention and productivity? The EPR test is built to catch that trade-off, and it does so through two cost categories.

Operational Accuracy: This measures whether the product interferes with legitimate work. AV-Comparatives runs a battery of clean scenarios: opening executables, scripts, and macro-enabled documents; browsing clean sites; and running the administrator tools and scripts real IT teams use every day. Over-blocking is expensive because every false positive requires an investigation and a restore. As the report puts it, “The greater the number of false alerts, the more difficult it becomes to recognize a genuine alert.”

Workflow Delay: This measures whether the product stalls people while it thinks, typically by holding an unknown file for sandbox analysis while the user waits.
GravityZone recorded no operational accuracy costs and no workflow delay costs. Zero in both categories. Six of the fourteen tested products incurred operational accuracy costs, and one of those incurred workflow delay costs on top. This is the number to look at if you only have time for one thing besides the Phase 1 result. Full prevention with zero friction says something about how you achieved prevention, not just that it happened.

What the 2026 AV-C EPR Certification Tells You 

To certify, a product needs a 92% or higher average across the combined active and passive response phases, plus a low modeled operational impact. It is a real bar, and several products failed it. Of those that passed, earning the badge shows a product is competent; however, you will find significant performance differences in the underlying numbers. Bitdefender is in the upper-right portion of the quadrant.

Image: The AV-Comparatives Enterprise CyberRisk Quadrant for the 2026 EPR Test. Prevention and response capability runs up the vertical axis; the five-year operational impact score runs right to left, so further right is lower impact.

On combined prevention and response capability, Bitdefender GravityZone scored 99.7%, the second-highest result in the test.

Three products separated themselves at the top of the quadrant, and Bitdefender GravityZone is one of them. Landing a top-tier result on both axes at once is something only three of the fourteen tested products managed, and Bitdefender GravityZone did it while stopping every attack at the point of entry.

Image: The test results illustrate what a miss can mean for the success of a security breach.

One caution on that cost axis, and AV-Comparatives is explicit about it: these are standardized list-price inputs used for comparability, not real contract pricing. Product price is also only one input among several, and the report notes it carries less influence compared with prevention effectiveness, operational accuracy, and workflow efficiency.

Silently Blocked Threats

AV-Comparatives notes that Bitdefender GravityZone, along with ESET, G Data, VIPRE, WithSecure and Vendor C, produced some silent blocks in Phase 1. A silent block means the attack was stopped, but the product did not generate a corresponding report for it. The attack is dead either way, which is why the active response score stayed at 100%, and the Bitdefender GravityZone Phase 1 passive response came in at 98%.

The Methodology Change to Watch

AV-Comparatives says it used AI-assisted development techniques to build its testing tools and generate scenario variations. A lab that can generate many variants of an attack chain, rather than assembling a fixed set of samples by hand, is testing your defenses against something they have not seen before, on every run.

Detection logic tuned to a specific sample’s artifacts, its hashes, its file names, its exact command lines, degrades quickly under that kind of pressure. Prevention anchored to behavior holds up better, because what an attack does at the end of the chain is far more stable than the tooling it uses at the front of it.

That is precisely what we build for at Bitdefender. The clearest illustration remains WannaCry, where a Bitdefender model trained in 2014 blocked the 2017 outbreak on behavioral grounds, with no knowledge of the specific vulnerability being exploited.

Today, fifty scenarios stopped in Phase 1 show what that looks like when a testing lab deliberately varies the attacks.

Key Takeaways from the 2026 Testing

Fifty attacks, and Bitdefender GravityZone stopped every one of them automatically at the point of entry, with nobody left waiting on a sandbox. GravityZone didn't block anything it shouldn't have. The result translates most directly into work your security team doesn't have to do.

The combination of complete Phase 1 prevention and zero operational cost puts Bitdefender in a select group, and Bitdefender GravityZone is in it.