3 ms·
While I agree in principle, most such platforms can avoid serious performance degradation with correct configuration. There's a lot of incentive for these thing
by cookiecaper 7y ago
While I agree in principle, most such platforms can avoid serious performance degradation with correct configuration. There's a lot of incentive for these things to come very aggressive out of the box -- after all, who wants to spend millions of dollars on software and then never even notice it? It's in the AV vendor's interest to make itself known and initially to overalarm. This also gives them some plausible deniability in the case that something does get through: they can just blame the guy who turned off $PerfObliteratingScan83 in the enterprise's profile. :)
Every enterprise deploying such software is expected to pare back the behavior to accommodate their specific risk profile, and in particular, to ensure that any high-performance tooling or internal software is exempted from most types of real-time protection. This is obviously much easier said than done in the real world, but it doesn't have to be an all-or-nothing proposition.