All reports

07/2026 - 06/2027

Security Certification Test Report: Palo Alto Networks Cortex XDR

Endpoint Security Certification Test (Anti-Tamper)

Details

Vendor: Palo Alto Networks
Product: Cortex XDR
Version: 9.2.0.120
CERT ID: 2026-0712
Test period: July 2026
Certificate expiry date: June 2027
Result: PASS

All reports

02/2026 - 03/2026

Advanced Security Test Report: Fortinet FortiEndpoint – EDR (Protection)

Testing Protection Against Fully Featured Attacks

These attacks are designed to compromise systems and penetrate target networks in the same way as the advanced persistent hacking groups known as Gamaredon Group, Ember Bear, Evasive Panda, and DPRK operate to breach systems and networks.

SE Labs used full chains of attack, meaning that testers behaved as real attackers, probing targets using a variety of tools, techniques and vectors before attempting to gain lower-level and more powerful access. Finally, the testers/attackers attempted to complete their missions, which might include stealing information, damaging systems and connecting to other systems on the network.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download

There are many opportunities to spot and stop attackers. Products can detect them when attackers send phishing emails to targets. Or later, when other emails contain links to malicious code. Some kick into action when malware enters the system. Others sit up and notice when the attackers exhibit bad behaviour on the network.

Regardless of which stages your security takes effect, you probably want it to detect and prevent before the breach runs to its conclusion in the press.

Our Enterprise Advanced Security test is unique, in that we test products by running a full attack. We follow every step of a breach attempt to ensure that the test is as realistic as possible.

This is important because different products can detect and prevent threats differently.

Ultimately you want your chosen security product to prevent a breach one way or another, but it’s more ideal to stop a threat early, rather than watch as it wreaks havoc before stopping it and trying to clean up.

Fortinet FortiEDR Protection test results

Some products are designed solely to watch and inform, while others can also remove threats either as soon as they appear or after they start causing damage.

For the ‘watchers’ we run the Advanced Security test in Detection mode. For ‘stoppers’ like Fortinet FortiEndpoint we can demonstrate effectiveness by testing in Protection Mode.

In this report we look at how Fortinet FortiEndpoint handled full breach attempts. At which stages did it detect and protect? And did it allow business as usual, or mis-handle legitimate applications?

All reports

03/2026 - 04/2026

Advanced Security Test Report: Cisco Secure Email Threat Defense – Email (Protection)

Test Email Security Against Business-focussed Attackers

Good security testing is realistic, using the kinds of threats customers see in real life. This is why we put a lot of focus on Business Email Compromise (BEC) scenarios, rather than just more conventional threat types (like generic phishing and malware). Read this Cisco Secure Email Threat Defense Test for more information.

Many organisations focus on blocking spam and detecting malware, but BEC attacks present a different kind of threat. BEC targets the human element of email communication.

Attackers craft convincing, fraudulent emails that appear to come from legitimate sources, tricking recipients into transferring money, sharing sensitive information or performing other actions that compromise the organisation.

BEC cases are not about malware detection or basic spam filtering. Instead, they exploit trust and authority. These attacks may bypass traditional security mechanisms because they often don’t contain malicious links or attachments. Instead, they rely on social engineering, making them incredibly dangerous and quite hard to spot by either people or technology.

Testing email security without BEC scenarios is to ignore a highly effective and popular method that attackers use every day to infiltrate businesses. It’s essential to ensure that email security solutions are able to recognise these nuanced threats and react accordingly.

Cisco Secure Email Threat Defense Test

Furthermore, adding security to a standard email platform shouldn’t be an afterthought. Many businesses assume that the platforms they use, such as Microsoft 365 or Google Workspace, have robust, built-in defences. While these platforms offer a solid baseline, they are not infallible. Attackers continuously evolve their tactics, exploiting gaps in standard security settings.

Comprehensive email security requires layered defences that integrate seamlessly with these platforms, providing advanced detection capabilities, including AI-driven anomaly detection, BEC filtering, and more.

By enhancing the built-in security of these platforms, with products such as Cisco‘s, organisations can mitigate risks more effectively. Security should be adaptive and proactive, not reactive, ensuring that your organisation stays protected even as threats evolve. Including BEC scenarios in testing is an essential part of validating these systems’ robustness. Read this free Cisco Secure Email Threat Defense Test report.

All reports

01/2026 - 03/2026

Security Evaluation Test Report: Enterprise Endpoint Security (Protection)

Protection Under Realistic Attack

Security products are often judged by what they claim to do. This report examines how they actually
behave when subjected to realistic attack conditions. SE Labs’ approach is to replicate credible adversary
behaviour and observe how products respond to it, across the full attack chain.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download

Measured Protection Against Realistic Cyber Attacks

That attack process includes the initial compromise and could potentially involve lateral movement, persistence, and data exfiltration or ransomware. Our objective is to measure protection as it is experienced in practice, not as it is defined by feature lists or controlled demonstrations.

Each product is exposed to the same threats, under the same conditions, with outcomes recorded and verified. This allows for direct comparison, and we can share the technical details to help improve the products afterwards.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

03/2026 - 02/2027

Security Certification Test Report: CrowdStrike Falcon

Endpoint Security Certification Test (Anti-Tamper)

Details

Vendor: CrowdStrike
Product: Falcon
Version: 7.34.20608.0
CERT ID: 2026 -0340
Test period: March 2026
Certificate expiry date: February 2027
Result: PASS

All reports

09/2025 - 10/2025

Advanced Security Test Report: CrowdStrike Falcon – EDR (Protection)

Ransomware resilience under attack

Ransomware remains one of the most commercially effective forms of cyber attack, not because it is technically sophisticated, but because it consistently encounters environments where basic cyber hygiene has degraded.

This report is therefore not about ransomware as a payload alone. It is about whether security products meaningfully support good cyber hygiene when it matters most, and whether that support holds up across both immediate and deeply embedded attack scenarios.

The answers are found in the detail that follows.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download

Ransomware remains one of the most commercially effective forms of cyber attack, not because it is technically sophisticated, but because it consistently encounters environments where basic cyber hygiene has degraded.

Attackers do not need zero-day exploits if patching is inconsistent, privileges are excessive, or protective controls are misconfigured or poorly maintained. In those conditions, ransomware is not an intrusion problem. It is an inevitability.

Ransomware resilience is critical

This report examines ransomware resilience through two complementary attack paths. In the first, ransomware is executed directly, reflecting scenarios where initial access has already been achieved through common vectors such as phishing, exposed services, or credential reuse. In the second, attackers establish a foothold, move laterally, escalate privileges, and only then deploy ransomware, mirroring the more deliberate campaigns now seen in real-world incidents. Both paths are rooted in the same question: what happens when cyber hygiene is stressed rather than assumed?

Security products under pressure

Rather than treating ransomware as a single event, the testing focuses on how effectively security products support day-to-day hygiene under pressure. This includes preventing execution where possible, containing activity when prevention fails, and limiting impact when attackers operate with time and intent. The distinction matters.

Ransomware outcomes are shaped long before encryption begins, often by decisions made months or years earlier about patching discipline, privilege control, and defensive coverage.

The results illustrate why product capability must be evaluated in realistic conditions. A security control that performs well in isolation may behave very differently when faced with chained actions, degraded signals, or attacker persistence. Equally, small implementation weaknesses can compound quickly once an attacker moves beyond the initial breach.

How well does your endpoint security support the organisation?

This report is therefore not about ransomware as a payload alone. It is about whether CrowdStrike Falcon meaningfully support good cyber hygiene when it matters most, and whether that support holds up across both immediate and deeply embedded attack scenarios.

The answers are found in the detail that follows.

All reports

09/2025 - 11/2025

Security Evaluation Test Report: Enterprise Endpoint Security (Protection)

What’s the difference and why should you care?

This cyber security test includes a mixture of threats. Most are the sort of attack that individuals and businesses face daily. Others are much more targeted and focused on taking control of victims with
greater precision. A targeted attack is rarely created for a single individual. Instead, it is designed
for a defined group of potential victims.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download

A targeted attack is designed for a defined group of potential victims

In practice, attackers rarely focus on one individual. Instead, they target defined groups such as employees of a particular organisation or users of a specific service. From there, they personalised to appear more relevant, timely, or trustworthy.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

09/2025 - 10/2025

Advanced Security Test Report: AhnLab EPP/EDR – EDR (Detection)

Endpoint Detection and Response is more than anti-virus

AhnLab EPP/EDR test results by SE Labs.

SE LABS tested AhnLab EPP/EDR against a range of hacking attacks designed to compromise systems and penetrate target networks in the same way as criminals and other attackers breach systems and networks.

Full chains of attack were used, meaning that testers behaved as real attackers, probing targets using a variety of tools, techniques and vectors before attempting to gain lower-level and more powerful access. Finally, the testers/attackers attempted to complete their missions, which might include stealing information, damaging systems and connecting to other systems on the network.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download

An Endpoint Detection and Response (EDR) product like AhnLab EPP/EDR goes beyond traditional antivirus software, which is why it requires more sophisticated testing. This involves testers mimicking real attackers and following every step of an attack.

While shortcuts might seem tempting, fully executing each phase of an attack is crucial to truly evaluate the effectiveness of EDR products.

Moreover, each step must reflect real-world scenarios; you can’t just guess what cybercriminals might do and hope it’s accurate. That’s why SE Labs tracks the actual behaviour of cyber criminals and designs tests based on how attackers attempt to compromise their targets.

The cyber security industry refers to this sequence of steps as the ‘attack chain.’ The MITRE organization has documented these stages in its ATT&CK framework.

Structured guide to testing

While this framework doesn’t provide an exact blueprint for real-world attacks, it offers a structured guide that testers, security vendors, and customers (like you!) can use to conduct tests and interpret the results.

SE Labs’ Advanced Security tests are based on real attacker behaviour, and we present our findings using a MITRE ATT&CK-style format.

You can see how the ATT&CK framework outlines each step of an attack and how we apply it to our testing in section 4. Threat Intelligence, starting on page 12. This approach offers two key benefits: confidence that our tests are both realistic and relevant, and familiarity with the way cyber attacks are illustrated.

All reports

11/2025 - 10/2026

Security Certification Test Report: Agger Labs

Endpoint Security Certification Test (Ransomware)

Details

Vendor: Agger Labs
Product: Agger
Version: 1.6.0.1
CERT ID: 2025 -1165
Test period: November 2025
Certificate expiry date: October 2026
Result: PASS

All reports

06/2025 - 08/2025

Security Evaluation Test Report: Enterprise Endpoint Security (Protection)

Is This Enterprise Report Too Complicated?

Security testing can be easy to explain but hard to execute. Testing can simplify life for organisations needing to buy cyber security products. It helps to create shortlists of competent products worth considering. It can also help explain why security is needed. A good test can demonstrate the sorts of threats real targets face and then show a solution.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download

Security testing can be easy to explain but hard to execute

But apparent simplicity is often the product of massive complexity. Security products and attacks are very complicated.

This report simplifies an extremely thorough test to make life easier for businesses and individuals
that need to buy cyber security protection but without the need to fully understand the nuts and bolts of it.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product was exposed to the same threats, which were a mixture of targeted attacks using well-established techniques and public email and web-based threats that were found to be live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

Contact us

Give us a few details about yourself and describe your inquiry. We will get back to you as soon as possible.

Get in touch

Feel free to reach out to us with any questions or inquiries

info@selabs.uk Connect with us Find us