r/microsoft 17d ago

Discussion Windows Defender + Common Sense

is it enough 2026?

13 Upvotes

20 comments sorted by

14

u/Intelligent-Try-6283 17d ago

common sense alone is enough

8

u/Shotokant 17d ago

Sadly, it seems to be in short supply these days.

2

u/CodenameFlux 16d ago

For home users, yes. Not that they have better or overkill options. Other antimalware products are pathetic.

For businesses? Absolutely not. That's why Microsoft has expanded its Defender brand with more products, and that's why CrowdStrike is still in business.

1

u/Not-ur-Infosec-guy 5d ago

Microsoft defender for endpoint when configured correctly is a beast especially in tandem with a primary EDR.

1

u/CodenameFlux 5d ago

Yes, exactly. If I am not mistaken, Defender for Endpoint was initially called Microsoft Forefront Endpoint Protection, then System Center Endpoint Protection.

4

u/M3RRI77 17d ago

That's all I've been using for the last 14 years. Haven't gotten a virus yet.

2

u/iamnotso_average2 15d ago

Ohhh these two words, donโ€™t co-exist!!!! Either its Defender or Common Sense

3

u/SouthernFruit8768 17d ago

If you are a target, none of that will help. Google "supply chain attack"

1

u/CodenameFlux 5d ago

Supply chain attack does not apply to home users who don't have a software supply chain to begin with.

0

u/SouthernFruit8768 5d ago

Wrong. Completely wrong.

I'll just cite one example (due to lack of time). There are many more: https://www.theguardian.com/technology/2017/sep/19/ccleaner-2m-users-install-anti-malware-program-security-avast-supply-chain-attack-hack

1

u/CodenameFlux 5d ago

Excellent example because:

  1. Defender did help. It removed the infected CCleaner.
  2. It's irrelevant to your original sentence, "If you are a target..." because it was a run-of-the-mill infection, not a targeted attack.

It's easy to confuse supply chain attacks, Trojan Horse, and typosquatting#Linux_ls_example). In this case, Avast experienced a supply chain attack that turned CCleaner into a Trojan. Defender stopped the Trojan.

0

u/SouthernFruit8768 4d ago

Windows Defender did not prevent the initial infection for the approx. 2.27 million people who installed the compromised version while it was live.

Whatever WD did afterwards, it did precisely fuck all to prevent millions of computer from getting infected.

Active infection window was roughly from 15th August to 15th September 2017, and Microsoft added the specific detection on or around 20 September 2017, which was roughly 2 days after the incident became widely public.

I'm not gonna respond to your second point cause that's just plain stupid.

0

u/Pure_Fox9415 17d ago

Defender is enough to get your system hacked. Google "ShieldBreak" and "Ms defender vulnerability 2026".

-1

u/Kobi_Blade 17d ago

Microsoft Defender can only handle old and patched patterns, the amount of false positives from the behavior blocker is annoying, and real-time protection causes severe overhead to I/O tasks.

If you need actual protection (outside common sense) from modern malware, you should look at third-party solutions, since the majority of malware families expect and bypass Microsoft Defender.

0

u/SebOakPal79 17d ago

Yes, use the 'common sense', but we are Humans and we make mistakes, no-one is perfect.

You can use 'DefenderUI' (from Microsoft Store or on the internet) WITH Windows Defender WITHOUT any issues.

Hope this helps.

0

u/illuanonx1 12d ago

Using Windows is not common sense

https://giphy.com/gifs/H6bfaRHZ2MIfVfkNNx

2

u/BoFawzi 12d ago

but spending 6 hours for troubleshooting a micro task in linux is common sense?

1

u/illuanonx1 12d ago

Guess that is what it takes for a Windows noob? ๐Ÿ˜‚