for the first time, i have a machine with this installed and holy damn... it's so bad. it uses 30~50% cpu all the time + tons of IO. how can people just accept software that just degrades your machine for small gains on security?
when i try to use docker, tmux within a terminal, it gets even worse -- i've seen it using 60% cpu + io.
Since then I just find the least obtrusive AV and just try to avoid clicking on anything suspicious, because I'm convinced they all offer "meh" protection at best.
These have absolutely massive issues with false positives that take ages to resolve even if reported.
My requirements were simple: it had to run in our cloud (AWS, eu-west-2) because of PII concerns, preferably "serverless"/ephemeral and we needed to scan assets our data analysts would use in their day to day operations (tiny files, massive files - a bit of everything).
After a several time consuming days I had to give up because I found nothing. The Internet has become a mirage of av/malware scanning solutions that no longer exist (one of our guys reported that Sophos had a CLI tool - savscan - but when I looked it appeared to be discontinued). Almost every major vendor I came across offered an end-point product that ran on their cloud or had moved out of the malware/virus scanning market in favour of a DPI firewall. I was hampered by a lack of product documentation/feature comparison tables on the "enterprise" vendor marketing websites and sad "cloudification" of stacks that really ought to have a CLI binary.
Microsoft is also the biggest vendor of enterprise endpoint security solutions - that is Microsoft Defender and products like "Palo Alto Cortex" compete. However, the home offering of Defender _is_ quite different in terms of usage from the enterprise version and so is the amount of instrumentation.
EDIT:
In many cases, these security changes meant deep architectural changes were required to third party solutions. And most ecosystem vendors were not incented to invest heavily in their legacy apps. Some of these solutions took the unorthodox approach of modifying data structures and even instructions in the kernel in order to implement their functionality, bypassing APIs and multiprocessor locks, often causing havoc. At one point, something like 70% of all Windows “blue screens” were caused by these third party drivers and their unwillingness to use supported APIs to implement their functionality. Antivirus vendors were notorious for using this approach.
In my role as head of Microsoft security, I personally spent years explaining to antivirus vendors why we would no longer allow them to “patch” kernel instructions and data structures in memory, why this was a security risk, and why they needed to use approved APIs going forward, that we would no longer support their legacy apps with deep hooks in the Windows kernel — the same approach that hackers were using to attack consumer systems. Our “friends”, the antivirus vendors, threatened to sue us in return, claiming we were blocking their livelihood and abusing our monopoly power! With friends like that, who needs enemies? They just wanted their old solutions to keep working even if that meant reducing the security of our mutual customers — the very thing they were supposed to be improving.
https://blog.usejournal.com/what-really-happened-with-vista-...I think they definitely had a purpose a long time ago but probably not for the past 15 years.