All reports

04/2026 - 06/2026

Security Evaluation Test Report: Enterprise Endpoint Security (Protection)

Effective protection depends on recognising more than malware

Recent targeted campaigns show that attackers still don’t need novel malware or an undisclosed vulnerability to infiltrate an organisation. Increasingly, they combine familiar tools, credible social engineering and legitimate system functions into an attack chain where each action may appear relatively harmless. The sophistication lies not in the malware used, but in the sequence of events.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [1.31 MB]

A targeted attack is rarely created for a single individual

An attack might begin with a convincing email or phone call, followed by a request to join a screen-sharing session. The victim may then be persuaded to install a legitimate remote-management tool, open a trusted application or run commands supplied by someone claiming to provide technical support. Each step can appear perfectly reasonable in isolation. Only when viewed together does the malicious objective become clear.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

01/2026 - 03/2026

Security Evaluation Test Report: Enterprise Endpoint Security (Protection)

Protection Under Realistic Attack

Security products are often judged by what they claim to do. This report examines how they actually
behave when subjected to realistic attack conditions. SE Labs’ approach is to replicate credible adversary
behaviour and observe how products respond to it, across the full attack chain.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [825.24 KB]

Measured Protection Against Realistic Cyber Attacks

That attack process includes the initial compromise and could potentially involve lateral movement, persistence, and data exfiltration or ransomware. Our objective is to measure protection as it is experienced in practice, not as it is defined by feature lists or controlled demonstrations.

Each product is exposed to the same threats, under the same conditions, with outcomes recorded and verified. This allows for direct comparison, and we can share the technical details to help improve the products afterwards.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

03/2026 - 02/2027

Security Certification Test Report: CrowdStrike Falcon

Endpoint Security Certification Test (Anti-Tamper)

Details

Vendor: CrowdStrike
Product: Falcon
Version: 7.34.20608.0
CERT ID: 2026 -0340
Test period: March 2026
Certificate expiry date: February 2027
Result: PASS

All reports

09/2025 - 10/2025

Advanced Security Test Report: CrowdStrike Falcon – EDR (Protection)

Ransomware resilience under attack

Ransomware remains one of the most commercially effective forms of cyber attack, not because it is technically sophisticated, but because it consistently encounters environments where basic cyber hygiene has degraded.

This report is therefore not about ransomware as a payload alone. It is about whether security products meaningfully support good cyber hygiene when it matters most, and whether that support holds up across both immediate and deeply embedded attack scenarios.

The answers are found in the detail that follows.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [1.60 MB]

Ransomware remains one of the most commercially effective forms of cyber attack, not because it is technically sophisticated, but because it consistently encounters environments where basic cyber hygiene has degraded.

Attackers do not need zero-day exploits if patching is inconsistent, privileges are excessive, or protective controls are misconfigured or poorly maintained. In those conditions, ransomware is not an intrusion problem. It is an inevitability.

Ransomware resilience is critical

This report examines ransomware resilience through two complementary attack paths. In the first, ransomware is executed directly, reflecting scenarios where initial access has already been achieved through common vectors such as phishing, exposed services, or credential reuse. In the second, attackers establish a foothold, move laterally, escalate privileges, and only then deploy ransomware, mirroring the more deliberate campaigns now seen in real-world incidents. Both paths are rooted in the same question: what happens when cyber hygiene is stressed rather than assumed?

Security products under pressure

Rather than treating ransomware as a single event, the testing focuses on how effectively security products support day-to-day hygiene under pressure. This includes preventing execution where possible, containing activity when prevention fails, and limiting impact when attackers operate with time and intent. The distinction matters.

Ransomware outcomes are shaped long before encryption begins, often by decisions made months or years earlier about patching discipline, privilege control, and defensive coverage.

The results illustrate why product capability must be evaluated in realistic conditions. A security control that performs well in isolation may behave very differently when faced with chained actions, degraded signals, or attacker persistence. Equally, small implementation weaknesses can compound quickly once an attacker moves beyond the initial breach.

How well does your endpoint security support the organisation?

This report is therefore not about ransomware as a payload alone. It is about whether CrowdStrike Falcon meaningfully support good cyber hygiene when it matters most, and whether that support holds up across both immediate and deeply embedded attack scenarios.

The answers are found in the detail that follows.

All reports

09/2025 - 11/2025

Security Evaluation Test Report: Enterprise Endpoint Security (Protection)

What’s the difference and why should you care?

This cyber security test includes a mixture of threats. Most are the sort of attack that individuals and businesses face daily. Others are much more targeted and focused on taking control of victims with
greater precision. A targeted attack is rarely created for a single individual. Instead, it is designed
for a defined group of potential victims.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [731.04 KB]

A targeted attack is designed for a defined group of potential victims

In practice, attackers rarely focus on one individual. Instead, they target defined groups such as employees of a particular organisation or users of a specific service. From there, they personalised to appear more relevant, timely, or trustworthy.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

06/2025 - 08/2025

Security Evaluation Test Report: Enterprise Endpoint Security (Protection)

Is This Enterprise Report Too Complicated?

Security testing can be easy to explain but hard to execute. Testing can simplify life for organisations needing to buy cyber security products. It helps to create shortlists of competent products worth considering. It can also help explain why security is needed. A good test can demonstrate the sorts of threats real targets face and then show a solution.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [721.45 KB]

Security testing can be easy to explain but hard to execute

But apparent simplicity is often the product of massive complexity. Security products and attacks are very complicated.

This report simplifies an extremely thorough test to make life easier for businesses and individuals
that need to buy cyber security protection but without the need to fully understand the nuts and bolts of it.

Proving the Work

We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.

The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product was exposed to the same threats, which were a mixture of targeted attacks using well-established techniques and public email and web-based threats that were found to be live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

04/2025 - 06/2025

Security Evaluation Test Report: Enterprise Endpoint Security (Protection)

The Cost of Enterprise Endpoint Protection Failure

It will always be more than the cost of good protection. Whether you provide security for a global enterprise or run a small business with just a few employees, a single compromised endpoint brings serious consequences. In many cases, attackers don’t breach the most valuable system, but the most vulnerable. Once breached, attackers can move on to steal data, disrupt operations or deploy ransomware that stops business in its tracks.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [715.85 KB]

It will always be more than the cost of good protection

For large organisations, the impact might include fines, reputational damage and widespread operational
downtime.

For smaller companies, the effect can be far worse. A single ransomware incident or business
email compromise could lead to a level of financial loss that the business cannot absorb. In some cases,
it means closure.

The Cost of Enterprise Endpoint Protection Failure

Why do we go to all this trouble? Because businesses need answers grounded in reality, not synthetic benchmarks or scripted demos. We copy the bad guys to discover the truth.

These include common malware found in the wild and more advanced attacks modelled on real adversaries. Some threats were captured directly from the internet and tested immediately. Others were designed to reflect how a capable attacker behaves, using techniques such as spear phishing and running post-exploitation tools within a network.

Which solutions to trust?

Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product was exposed to the same threats, which were a mixture of targeted attacks using well-established techniques and public email and web-based threats that were found to be live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

01/2025 - 03/2025

Security Evaluation Test Report: Enterprise Endpoint Security (Protection)

Can Your Endpoint Protection Stop a Real Hacker?

In the enterprise security space, bold claims are everywhere. Most vendors say their endpoint protection stops ransomware, blocks phishing, and detects advanced threats. But when the stakes are high, how many tools can actually deliver? Will your endpoint protection stop a real hacker?

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [726.18 KB]

To find out, we test like hackers

At SE Labs, we don’t rely on vendor claims. We Test Like Hackers.

That means replicating real-world attacks using threat intelligence and offensive tools. We create phishing emails, customise exploits, build backdoors and more. We don’t cut corners. We mimic genuine adversaries to see how well products perform under realistic, high-pressure conditions.

Endpoint Protection Stop a Real Hacker?

Why do we go to all this trouble? Because businesses need answers grounded in reality, not synthetic benchmarks or scripted demos. We copy the bad guys to discover the truth.

In this comparative report, we put leading endpoint products through rigorous testing. Each product faced the same attack scenarios, allowing us to observe how early they detected threats, whether they blocked them effectively, and how well they protected the system overall.

Which solutions to trust?

If your organisation depends on endpoint security to protect sensitive data, this report will show you which solutions are worth your trust, and which ones may leave you exposed.

We should be able to rely confidently on the security products that everyone tells us we need. The endpoint protection products in this report have undergone the most strenuous testing available, and they’ve come out well. They’ll provide you with strong protection while you use your computer to do something useful, fun or both.

How we test

We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product was exposed to the same threats, which were a mixture of targeted attacks using well-established techniques and public email and web-based threats that were found to be live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

12/2024 - 12/2024

Advanced Security Test Report: CrowdStrike Falcon 2025

Ransomware vs. Endpoint Security

Ransomware is the most visible, most easily understood cyber threat affecting businesses today. Paralysed computer systems mean stalled business and loss of earnings. On top of that, a ransom demand provides a clear, countable value to a threat. A demand for “one million dollars!” is easier to quantify than the possible leak of intellectual property to a competitor.

One reason why ransomware is so ‘popular’ is that the attackers don’t have to produce their own. They outsource the production of ransomware to others, who provide Ransomware as a Service (RAAS).

Attackers then usually trick targets into running it, or at least into providing a route for the attackers to run it for them. Artificial intelligence systems make the creation of such social engineering attacks easier,
cheaper and more effective than ever before.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [1.65 MB]

Product factsheet:

Ransomware Deep Attacks

We tested CrowdStrike Falcon against a range of attacks designed to extort victims. These attacks were realistic, using the same tactics and techniques as those used against victims in recent months.

For the first part of this test, we analysed the common tactics of ransomware gangs and created two custom gangs that use a wider variety of methods. In all cases we run the attack from the very start, including attempting to access targets with stolen credentials or other means. We then move through the system and sometimes the network, before deploying the ransomware as the final payload.


Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. Our results help vendors improve their products and buyers choose the best for their own needs.

All reports

07/2024 - 09/2024

Enterprise Advanced Security (EDR): Enterprise 2024 Q3 – DETECTION

Endpoint security products

Endpoint Detection Compared

We compare endpoint security products directly using real, major threats

Welcome to the third edition of the Enterprise Advanced Security test, where we directly compare various endpoint security products. This report examines how these products tackle major threats faced by businesses of all sizes from the Global 100 down to medium enterprises, and likely small businesses too. While we provide an overall score, we also delve into the specific details that matter most to your security team, outlining the different levels of protection these products offer.


Endpoint Detection and Response (EDR) solutions go beyond traditional antivirus software, requiring more advanced testing methods. To truly evaluate EDR capabilities, testers need to act like real attackers, meticulously replicating each step of an attack.

It might be tempting to take shortcuts during testing, but to genuinely assess an EDR product’s effectiveness, it’s crucial to execute every stage of an attack. And each of these stages needs to be realistic; you can’t just guess what cybercriminals might do. That’s why SE Labs carefully tracks real-world cybercriminal behaviour and designs tests based on their tactics.

Thankfully, the MITRE organization has outlined these steps through its ATT&CK framework. While this framework doesn’t provide a precise guide for every attack scenario, it offers a valuable structure that testers, security vendors, and customers (like you!) can use to conduct tests and interpret results.

Loader Loading…
EAD Logo Taking too long?

Reload Reload document
| Open Open in new tab

Download [2.44 MB]

How we test endpoint security products

We tested a variety of Endpoint Detection and Response products against a range of hacking attacks
designed to compromise systems and penetrate target networks in the same way criminals and other attackers breach systems and networks.


Full chains of attack were used, meaning that testers behaved as real attackers, probing targets using a variety of tools, techniques and vectors before attempting to gain lower-level and more powerful access. Finally, the testers/attackers attempted to complete their missions, which might include stealing information, damaging systems and connecting to other systems on the network.

Choose your reports and reviews carefully

We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. Our results help vendors improve their products and buyers choose the best for their own needs.

Contact us

Give us a few details about yourself and describe your inquiry. We will get back to you as soon as possible.

Get in touch

Feel free to reach out to us with any questions or inquiries

info@selabs.uk Connect with us Find us