Vendor: Deep Instinct
01/2026 - 03/2026
Security Evaluation Test Report: Enterprise Endpoint Security (Protection)
Protection Under Realistic Attack
Security products are often judged by what they claim to do. This report examines how they actually
behave when subjected to realistic attack conditions. SE Labs’ approach is to replicate credible adversary
behaviour and observe how products respond to it, across the full attack chain.
Measured Protection Against Realistic Cyber Attacks
That attack process includes the initial compromise and could potentially involve lateral movement, persistence, and data exfiltration or ransomware. Our objective is to measure protection as it is experienced in practice, not as it is defined by feature lists or controlled demonstrations.
Each product is exposed to the same threats, under the same conditions, with outcomes recorded and verified. This allows for direct comparison, and we can share the technical details to help improve the products afterwards.
Proving the Work
We don’t really think most people care about the deep details, but we include them anyway because we’ve put a lot of effort into doing our due diligence for this test report. We’ve been thorough, ticked all the boxes that the industry requires of us, and ticked some extra ones we think are critical.
The standard of our testing is world-leading and we want to prove to you that you can trust this test report – which is why there are explanations and charts for every part of the test. Even for bits you probably don’t care about.
Which solutions to trust?
Effective endpoint protection must do more than respond to known threats. It must adapt quickly, stop attacks early and resist attempts to bypass defences. While no product is perfect, some provide a much higher level of protection than others. This report makes those differences clear.
How we test
We tested a variety of anti-malware (aka ‘anti-virus’; aka ‘endpoint security’) products from a range of well-known vendors in an effort to judge which were the most effective. Each product faced the same threats. Specifically, these included a mixture of targeted attacks that used well established techniques, as well as public email and web based threats that were live on the internet at the time of the test. The results indicate how effectively the products were at detecting and/or protecting against those threats in real-time.
Choose your reports and reviews carefully
We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.

Choose the best enterprise security product
By understanding the rules of security testing
Our reports help you choose the best enterprise security product that can protect you from ransomware and other types of attack.
Choose the best enterprise anti-malware solution
This report contains security testing results. You can compare the performance of a variety of products that claim to protect you against online threats. This, in theory, will help people and businesses choose the best security product.
Product factsheets:
But this is a free report. How can you trust that the high-scoring vendors didn’t just pay for their ranking? Do you suspect that some low-scoring vendors dropped out of the report? Or asked to be retested until they scored better?
What are the rules behind the scenes in security testing?
With security testing the stakes are high. From a customers’ perspective, the wrong decision could be disastrous to a business. Or a personal life.
So we, as testers, have a massive responsibility to do the right thing, meaning the honest thing. That means trying to involve as many reputable security vendors as possible in our tests and treating them all fairly.
Security vendors want to sell products and will do what they can to achieved strong marketing. That can involve appearing in weak tests or engaging with more ‘flexible’ testers. One strategy could be to test enough privately against competitors and then release the one report that shows your product at the top of the list.
We focus on strong technical testing and avoid purely marketing-led initiatives. We have awards for vendors who do well, but we stand out by assessing technology deeply and helping improve things for everyone.
Five simple rules
In our blog post Public and Private Testing we explain our five simple rules to help maintain the integrity of our reports. If you want to peak behind the curtain, to see how we work with security vendors, the information is all available online.
Testing Standards
For this report we also followed the only available Standard for anti-malware testing, the one run by the Anti-Malware Testing Standards Organization. This ensures that we do what we say we’ll do, and can prove it.
We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This report has gone through the AMTSO certification process to ensure that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best for their own needs.
Endpoint protection needs your attention
How to get out more than you put in
Our reports help you choose the best enterprise endpoint protection for your organisation. Picking a suitable solution isn’t just a matter of scanning through testing awards. You need to look closely at what you need, what you already have and what is available.
Choose the best enterprise endpoint protection
If you were going to buy a new security fence, burglar alarm or CCTV system you would research the various options and consider how to deploy it in your very specific situation. The same should follow for endpoint protection systems. What do you really need? Are the candidates basically capable? And can you get the best out of them in your environment. We hope this report helps you answer some of these important questions.
We pride ourselves on a level of transparency that elevates our work above the less open reports available. But don’t just take our word for it. This enterprise endpoint protection report has gone through the AMTSO certification process. This ensures that we say what we’re going to do; do it; and can prove it. Our results help vendors improve their products and buyers choose the best anti-malware solution for their own needs.