Latest News
September 29, 2026 | Text: Markus Selinger | Antivirus for Windows
ATP endurance test in 2026: 24 security products for Windows
Cybercriminals are launching constant attacks on the computers of individuals and companies under Windows around the world. They use infostealers to plunder data from the systems or ransomware to encrypt them. Then they demand a ransom payment, after which – with any luck – they send a decryption tool. A security solution worth its salt needs to provide adequate protection for consumer and corporate users running Windows computers. But how do these solutions hold up in real-world testing? The Advanced Threat Protection test, or ATP test for short, uses real attacks to put the solutions through their paces and see if their protective barrier works under Windows. The endurance test shows how well security solutions available on the market now performed over six months when subjected to attacks using the latest technologies.
ATP endurance test with 24 security solutions for Windows:
Many of the products in the endurance test performed very well in the advanced ATP test
In particular, infostealer and ransomware attacks have always ranked quite high in the list of the dangers lurking on the internet. Their behavior differs from a trojan, which just tries to gain a foothold on a Windows computer. Infostealers and ransomware try to steal or encrypt the data or entire system of consumer or corporate users. Then the data is often published on the darknet where it can be sold. It’s a horrific situation that no one wants to go through. That’s why the most effective way to prevent this is to select a reliable security tool.
The experts at AV-TEST examine the various solutions on the market in the Advanced Threat Protection test so consumer and corporate users know which security solution can best defend them against cyberattackers. The packages need to prove themselves in real attack scenarios that employ the latest attack technologies. The ATP endurance test examined 24 products in the lab from January to June 2026. A large number of products took part in all 3 tests, others only in 2 or one. Nevertheless, it enabled a good side-by-side comparison of the products.
The ATP test with the latest attack scenarios
The test experts bombarded the Windows systems using up to 30 different attack scenarios, for which they employed different tactics that cyberattackers use on a daily basis. They attempted to manipulate Windows tools so they could infiltrate the systems by deploying harmful scripts or exploiting vulnerabilities in the running processes. Here is a list of all the attack techniques used in testing. For some tests, the attacks used a combination of these methods.
PyInstaller executable bundling: Attackers use PyInstaller as a means to bundle dangerous Python scripts together with a small Python runtime environment. The EXE file can be executed directly under Windows. Which means that the user does not need to have Python or any libraries installed, nor is it necessary to install anything for the launch. In our examples, we use PyInstaller to bundle the Python applications into packages, which then load the dangerous shellcode or a manipulated DLL file later on. It enables the dangerous applications to pass unnoticed, because users and security tools will categorize them as something harmless.
Autolt: is a popular BASIC-like scripting language tool for Windows used in automating tasks such as clicks, keystrokes, window manipulation and simple installation/administrative tasks. It can also be used to compile scripts in EXE files enabling them to run without an additional Autolt installation.
Attackers use Autolt to create and distribute malicious scripts. The tool is well-known and legal to use so it doesn’t immediately trigger any alarms when it is deployed. Our attacks use Autolt scripts that implement shellcode loaders, which are designed to decode and execute malicious code directly in a computer’s RAM.
DLL sideloading: Using this attack technique, a legitimate executable file loads a file with a DLL extension, in the guise of a trusted process, from another directory. The attackers had previously replaced the DLL file with a malicious version. In Windows, many applications first search for specific DDL files in their working directory before reverting to system paths. In our examples we used “vulkaninfo.exe”, a legitimate, digitally signed executable file, and injected a manipulated DLL file into the directory. When the program searches for the corresponding library at launch, it loads the infected DLL file.
Scheduled tasks: Attackers can exploit the Windows Task Scheduler to trigger a task to run malicious code one time or routinely. The experts scheduled a task to launch PowerShell and then load a harmful DLL file.
The first part of the ATP test is always the detection of malware, its arrival on the system or its subsequent execution. If the attacker is not detected and is able to launch its attack, then the downstream defense modules of the respective security solution need to be triggered so that the attack is halted in its tracks. Each of these steps are documented in the lab and analyzed by the experts.
ATP endurance test: 24 security products defend against ransomware and infostealers
The security solutions for consumer and corporate users have all completed 1, 2 or even 3 tests over the course of 6 months. The table clearly shows the number of ATP tests in which each product took part. The majority of them completed 3 tests. A product can earn up to 35 points in each round of testing with 10 attack scenarios. If the solution completed 3 tests, then it could earn a maximum of 105 points; for 2 tests 70 points; and for one test 35 points.
For example, several products may have detected 30 different attacks, as shown in the table; however, some packages earned fewer points than the others. This is because the test experts scored 4 points for a successfully defeated infostealer attack and 3 points for a successfully defeated ransomware attack. If the solution was too slow in detecting the attack, or only partly prevented it from executing, then there would have been a half-point or even a full-point deduction.
The results are clearly documented by the testers in a matrix according to the MITRE ATT&CK standard. This is used internationally in professional assessments. It ensures that the tests are precisely reproducible in all steps.
ATP endurance test: 12 products for consumer users
The table on this page shows the outcome of the tests for the 12 solutions for consumer users in the ATP endurance test. We have bundled the products into groups that indicate which completed 3 tests, 2 tests or just 1 test to make the comparison clearer.
The first group with 3 tests consisted of 8 products coming from the following vendors: Avast, AVG, Bitdefender, ESET, K7 Computing, Kaspersky, McAfee and Norton. In this group, there were 6 packages that achieved the full set of 105 points in all 3 tests, correctly identifying 30 attackers in the scenarios. They were the products from Avast, AVG, K7 Computing, Kaspersky, McAfee and Norton.
The package from Bitdefender also managed to detect the attackers in the 30 scenarios; however, it was not able to stop them all. Nevertheless, the results were quite good: 100 out of 105 points.
The ESET security solution rounds off the list with 29 out of 30 attackers detected, earning 93.5 (out of 105) points in the protection score.
The second group with 2 tests consisted of only one product, Avira Security for Windows. The product detected and fended off 18 of the 20 attackers in the test scenarios. However, several points were deducted due to the malware that it did not detect in two cases, so it only attained a protection score of 63 out of 70 points.
The packages from Microsoft, Surfshark and Trend Micro made up the third group involving one test. The first two solutions detected all attackers in the 10 test scenarios without a flaw, earning the full 35 points. Trend Micro was only able to detect 8 out of 10 attackers, which cost it 7 points. This left the product with only 28 out of 35 possible points when it came to the protection score.
ATP endurance test: 12 products for corporate users
The latest endurance test put 12 endpoint solutions for corporate users under Windows through their paces. 8 out of 12 tested products completed 3 tests. The maximum protection scores here were also 105, 70 or 35 points, depending on the number of tests.
In the first group with 3 tests were the 8 endpoint products from Acronis, Avast, Kaspersky with two versions, Microworld, Norton, Qualys and Trellix.
The 5 solutions from Acronis, Avast, Microworld as well as both Kaspersky versions completed the endurance test with excellent results. They were able to detect all 30 attackers in the 30 scenarios without fail. For this feat, they were awarded the maximum total of 105 points as their protection score.
The endpoint products from Norton and Qualys did detect all 30 attackers, yet they each made one minor mistake, which led to a mere 1-point deduction. In the end, they earned 104 out of 105 points in the protection score.
The solution from Trellix only detected 28 out of 30 attackers, as well as experienced a number of minor issues, which also led to a deduction in points. This left the solution with only 97 out of 105 points in terms of the protection score.
The second group with 2 tests consisted of the endpoint solution from Net Protector only. It detected all attackers in the 20 attack scenarios; however, it wasn’t able to properly fend them off and stop them all. These minor issues caused the solution to lose valuable points, earning only 65.5 out of 70 points possible.
The three products from Sophos, Symantec and WithSecure made up the third group involving one test. They all detected the entire set of attackers in the 10 test scenarios. For this feat, the products from Symantec and WithSecure received the full 35 points in terms of the protection score. The endpoint solution from Sophos encountered a minor issue, which led to a one-point deduction: 34 out of 35 points.
Conclusion for the ATP endurance test: good means of defense against ransomware and infostealers
The Advanced Threat Protection endurance test reveals how reliably the security solutions can protect the Windows computers of consumer and corporate users over an extended period of time. The attack scenarios used in testing mimic real-world conditions, further underscoring the reliability of the products. After all, attackers will capitalize on any vulnerabilities they can find in the detection systems, even if only briefly.
Naturally, the most compelling results are those from the group that completed three tests. These tests showed that several products for consumer users are active in the background, reliably protecting the systems. Avast, AVG, K7 Computing, Kaspersky, McAfee and Norton are the 6 security solutions that demonstrated that they can provide the best defense under Windows. They all scored the maximum amount of 105 points in the protection score. The package from Bitdefender also scored a respectable 100 points.
The outcome for the endpoint versions for corporate users was similar, with 5 products earning the maximum amount of points. The solutions from Acronis, Avast, Microworld and both product versions from Kaspersky achieved the maximum score of 105 points in the endurance test.
Norton and Qualys fell short of this feat, but only just barely. They completed the endurance test with 3 tests and a score of 104 out of 105 points.
The other test results of the products performing in just one or two ATP tests can be easily compared with those obtained by the first test group.
The ATP evaluations forming the basis of the endurance test include the following:


