All reports

07/2026 - 08/2026

Security Evaluation Test Report: macOS Home Anti-Malware

Is Apple’s macOS hack-proof?

This test aims to assess the security built into macOS, the operating system that runs Apple’s desktop and laptop personal computers. We also wanted to evaluate the usefulness and effectiveness of anti-virus (aka endpoint security) on macOS against targeted attacks.

If macOS’ in-built security is sufficiently strong, it might not be technically necessary to use anti-virus. You might be able to rely on the security features built into the operating system.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [1.37 MB]

If it’s not sufficiently strong then the next question is, “are popular third-party anti-virus solutions good enough to add value.” In other words, do you need anti-virus on a Mac to stop targeted attacks?

We created targeted attacks using common tools available to, and frequently used by attackers in the real world. The testing team then confirmed that these attacks were viable – that they worked against macOS systems with security settings disabled.

Once we had a library of functional attacks we set up two sets of targets. All targets were Mac computers with security settings enabled. We installed anti-virus software on these.

We chose five well-known anti-malware products that frequently appear in reviews and web searches. Most claim to offer protection against threats in real-time (not just as scans after an attack). These were from the following companies: Bitdefender, Canimaan Software (ClamAVX), ESET, Gen Digital (Norton) and Total Security (TotalAV).

macOS Home Anti-Malware

Targeted attacks are used to take control of a computer and achieve some aim, such as stealing or damaging data. It is not always necessary for an attacker to retain control (aka persistence) to achieve this goal. So the earlier the anti-virus detects the attack, the better.

How well did macOS protect against the threats? Did the anti-virus products help at all? Read on to find out how safe your Mac is.

All reports

04/2026 - 06/2026

Security Evaluation Test Report: Enterprise Endpoint Security (Protection)

Effective protection depends on recognising more than malware

Recent targeted campaigns show that attackers still don’t need novel malware or an undisclosed vulnerability to infiltrate an organisation. Increasingly, they combine familiar tools, credible social engineering and legitimate system functions into an attack chain where each action may appear relatively harmless. The sophistication lies not in the malware used, but in the sequence of events.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [1.31 MB]

A targeted attack is rarely created for a single individual

An attack might begin with a convincing email or phone call, followed by a request to join a screen-sharing session. The victim may then be persuaded to install a legitimate remote-management tool, open a trusted application or run commands supplied by someone claiming to provide technical support. Each step can appear perfectly reasonable in isolation. Only when viewed together does the malicious objective become clear.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

04/2026 - 06/2026

Security Evaluation Test Report: Home Anti-Malware (Protection)

Effective protection depends on recognising more than malware

Recent targeted campaigns show that attackers still don’t need novel malware or an undisclosed vulnerability to infiltrate an organisation. Increasingly, they combine familiar tools, credible social engineering and legitimate system functions into an attack chain where each action may appear relatively harmless. The sophistication lies not in the malware used, but in the sequence of events.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [1.39 MB]

A targeted attack is rarely created for a single individual

An attack might begin with a convincing email or phone call, followed by a request to join a screen-sharing session. The victim may then be persuaded to install a legitimate remote-management tool, open a trusted application or run commands supplied by someone claiming to provide technical support. Each step can appear perfectly reasonable in isolation. Only when viewed together does the malicious objective become clear.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. Don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

04/2026 - 06/2026

Security Evaluation Test Report: SMB Endpoint Security (Protection)

Effective protection depends on recognising more than malware

Recent targeted campaigns show that attackers still don’t need novel malware or an undisclosed vulnerability to infiltrate an organisation. Increasingly, they combine familiar tools, credible social engineering and legitimate system functions into an attack chain where each action may appear relatively harmless. The sophistication lies not in the malware used, but in the sequence of events.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [1.38 MB]

A targeted attack is rarely created for a single individual

An attack might begin with a convincing email or phone call, followed by a request to join a screen-sharing session. The victim may then be persuaded to install a legitimate remote-management tool, open a trusted application or run commands supplied by someone claiming to provide technical support. Each step can appear perfectly reasonable in isolation. Only when viewed together does the malicious objective become clear.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

01/2026 - 03/2026

Security Evaluation Test Report: Enterprise Endpoint Security (Protection)

Protection Under Realistic Attack

Security products are often judged by what they claim to do. This report examines how they actually
behave when subjected to realistic attack conditions. SE Labs’ approach is to replicate credible adversary
behaviour and observe how products respond to it, across the full attack chain.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [825.24 KB]

Measured Protection Against Realistic Cyber Attacks

That attack process includes the initial compromise and could potentially involve lateral movement, persistence, and data exfiltration or ransomware. Our objective is to measure protection as it is experienced in practice, not as it is defined by feature lists or controlled demonstrations.

Each product is exposed to the same threats, under the same conditions, with outcomes recorded and verified. This allows for direct comparison, and we can share the technical details to help improve the products afterwards.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

01/2026 - 03/2026

Security Evaluation Test Report: SMB Endpoint Security (Protection)

Protection Under Realistic Attack

Security products are often judged by what they claim to do. This report examines how they actually
behave when subjected to realistic attack conditions. SE Labs’ approach is to replicate credible adversary
behaviour and observe how products respond to it, across the full attack chain.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [768.37 KB]

Measured Protection Against Realistic Cyber Attacks

That attack process includes the initial compromise and could potentially involve lateral movement, persistence, and data exfiltration or ransomware. Our objective is to measure protection as it is experienced in practice, not as it is defined by feature lists or controlled demonstrations.

Each product is exposed to the same threats, under the same conditions, with outcomes recorded and verified. This allows for direct comparison, and we can share the technical details to help improve the products afterwards.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

01/2026 - 03/2026

Security Evaluation Test Report: Home Anti-Malware (Protection)

Protection Under Realistic Attack

Security products are often judged by what they claim to do. This report examines how they actually
behave when subjected to realistic attack conditions. SE Labs’ approach is to replicate credible adversary
behaviour and observe how products respond to it, across the full attack chain.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [778.92 KB]

Measured Protection Against Realistic Cyber Attacks

That attack process includes the initial compromise and could potentially involve lateral movement, persistence, and data exfiltration or ransomware. Our objective is to measure protection as it is experienced in practice, not as it is defined by feature lists or controlled demonstrations.

Each product is exposed to the same threats, under the same conditions, with outcomes recorded and verified. This allows for direct comparison, and we can share the technical details to help improve the products afterwards.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. Don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

-

Security Evaluation Test Report: Norton 360 – macOS (Protection)

Do you need anti-virus for your Mac?

Norton 360 macOS test results by SE Labs.

SE Labs tested Norton 360 against a range of hacking attacks designed to compromise systems and penetrate target networks in the same way as criminals and other attackers breach systems and networks.

We test like hackers, behaving like real attackers and probing targets with a variety of tools, techniques and vectors before attempting to gain access. Once we have access at a basic level we try to boost our power on the system before attempting to complete the mission, which might include stealing information, hiding our tracks and even damaging systems.

Read about the Norton 360 macOS test results in this free report.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [822.75 KB]

All reports

09/2025 - 11/2025

Security Evaluation Test Report: Home Anti-Malware (Protection)

What’s the difference and why should you care?

This cyber security test includes a mixture of threats. Most are the sort of attack that individuals and businesses face daily. Others are much more targeted and focused on taking control of victims with
greater precision. A targeted attack is rarely created for a single individual. Instead, it is designed
for a defined group of potential victims.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [737.34 KB]

A targeted attack is rarely created for a single individual

In practice, attackers rarely focus on one individual. Instead, they target defined groups such as employees of a particular organisation or users of a specific service. From there, they personalised to appear more relevant, timely, or trustworthy. Effective protection against general threats requires strong baseline controls, accurate detection of known malicious behaviour, and the ability to stop threats quickly and consistently

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. Don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

09/2025 - 11/2025

Security Evaluation Test Report: SMB Endpoint Security (Protection)

What’s the difference and why should you care?

This cyber security test includes a mixture of threats. Most are the sort of attack that individuals and businesses face daily. Others are much more targeted and focused on taking control of victims with
greater precision. A targeted attack is rarely created for a single individual. Instead, it is designed
for a defined group of potential victims.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [862.36 KB]

A targeted attack is designed for a defined group of potential victims

In practice, attackers rarely focus on one individual. Instead, they target defined groups such as employees of a particular organisation or users of a specific service. From there, they personalised to appear more relevant, timely, or trustworthy.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

Contact us

Give us a few details about yourself and describe your inquiry. We will get back to you as soon as possible.

Get in touch

Feel free to reach out to us with any questions or inquiries

info@selabs.uk Connect with us Find us