Endpoint Central EDR Earns AV Comparatives 2026 Certification
A spear-phishing link, Kerberoasting, lateral movement and a DCSync attack against Active Directory: these were among the techniques in the 14-stage attack chain used by AV-Comparatives to evaluate enterprise detection capabilities in 2026. For IT administrators and security analysts, the test offers a practical look at how endpoint security platforms expose an intrusion as it moves from a workstation towards domain-level compromise.
ManageEngine Endpoint Central with EDR was one of nine products to earn certification in that test round, alongside Bitdefender GravityZone Business Security Enterprise, ESET PROTECT Elite, Fortinet FortiEDR, G Data 365 | MXDR, Genian Insights E, Kaspersky EDR Expert (on-premises), Palo Alto Networks Cortex XDR Pro and Sangfor Athena AI-Native EPP. Each was assessed under AV-Comparatives’ detection-validation methodology, giving security teams a shared reference point for examining attack visibility and investigation capabilities.
The 2026 scenario was designed to resemble a realistic red-team engagement and drew on tactics, techniques and procedures associated with advanced threat actors such as APT29, APT41, APT27, APT10 and FIN7. Vendors were not told in advance which techniques would be used, helping the assessment reflect the uncertainty security teams face during real-world attacks.
Endpoint Central delivered telemetry coverage across 13 of the 14 attack stages and successfully validated all five dedicated Signal-to-Noise scenarios. Its detailed report walks through the attack techniques and the evidence available to analysts at each step, making it useful reading for anyone exploring EDR or reviewing an existing endpoint security deployment.
Download the Endpoint Central EDR AV-Comparatives report
Endpoint Central’s Signal-to-Noise result applies to the five dedicated validation scenarios in this assessment.
Inside the 14 Stage Enterprise Attack Chain
The scenario followed an intrusion across Windows 11 endpoints and Windows Server 2022 systems acting as a file server and domain controller. Command-and-control infrastructure was hosted in Microsoft Azure, with a redirector forwarding attacker communications. The attack stages were mapped to the MITRE ATT&CK framework and covered the following sequence:
- Malware delivery
- Spear-phishing link and simulated user interaction
- Browser-parented command-and-control beacon execution
- Scheduled-task creation for persistence
- Local system and domain enumeration
- Kerberoasting a service account
- Lateral movement to the file server using the service account
- Browser-parented command-and-control on the file server
- Creation of a local administrator account
- Domain-user impersonation and privilege assessment
- Lateral movement from the file server to the domain controller
- Parent and child process masquerading on the domain controller
- Creation of a Domain Admin account
- DCSync attack using domain credential replication
How Endpoint Central EDR Achieved Certification
The assessment examined detection and investigative visibility with products configured in detection-only mode. AV-Comparatives distinguished between Active Response, where an alert brings suspicious activity to an analyst’s attention, and Telemetry, where recorded evidence supports threat hunting and further investigation.
Endpoint Central’s 13-stage telemetry coverage gave analysts evidence across much of the attack sequence, including malicious execution, command-and-control communications, lateral movement and account manipulation. This breadth of visibility supports the investigation of activity across endpoints and Active Directory systems.
Test highlights:
- 13 of 14 stages with telemetry coverage
- 5 of 5 Signal-to-Noise scenarios validated
- AV-Comparatives EDR Detection Validation certification achieved
Useful Context for Threat Hunting and Investigation
The report documents how Endpoint Central’s hunting data helped analysts examine process relationships, command lines and network activity. On the file server, recorded administrative commands exposed creation of a local account and its addition to the Administrators group. On the domain controller, telemetry captured creation of a domain account and its addition to the Domain Admins group.
For security teams, this context helps connect individual events into an understandable attack sequence. Analysts can examine which systems were involved, how privileges changed and where further investigation is needed.
Signal to Noise Validation for Everyday Administration
AV-Comparatives separately ran five scenarios involving legitimate administrative activity to assess unnecessary alerting. Endpoint Central successfully validated all five. The result provides a useful indication of its alerting behaviour in those defined scenarios, an important consideration for teams managing analyst workload alongside detection coverage.
AI Assisted Investigation Capabilities
The report also includes ManageEngine’s description of AI-assisted alert summaries, conversational investigation and automated investigation features. These are designed to provide context, support natural-language queries and bring related findings together to help analysts identify likely root causes and consider response actions. This feature overview is vendor-provided information, separate from the certification assessment.
Download the Detailed Endpoint Central EDR Report
Endpoint Central’s certification gives organisations an independent reference for its detection and investigation capabilities. The detailed report adds technical depth through a stage-by-stage account of the simulated intrusion, MITRE ATT&CK mappings and screenshots showing the available alerts and hunting evidence.
Download the report and explore Endpoint Central EDR’s 2026 results
Wi-Fi Key Generator
Follow Firewall.cx
Recommended Downloads
Cisco Password Crack
Decrypt Cisco Type-7 Passwords on the fly!





