SES Complete Is a Certified Leader in the AV-Comparatives EPR Test

When put to the test, SES Complete proved robust prevention and response block 100% of threats

  • AV-Comparitives’ evaluation put Symantec® Endpoint Security Complete through complex, multi-stage attacks mirroring real threats organizations face every day. 
  • SES Complete earned Certified Leader Status after successfully containing every attack scenario before it could reach the final asset breach phase.
  • In a competitive field, SES Complete demonstrated strong protection against a wide range of sophisticated threats, adding yet another victory in a long track of wins.

In the cybersecurity industry, there’s no shortage of bold claims. But when an attacker is moving through your environment, those words don’t mean much unless the technology behind them can actually stop an attack before it becomes a breach. 

That’s why we scour the industry for realistic tests that make security prove itself. Every rightful win we earn gives security leaders and defenders more confidence that their defenses can hold up when it matters most.

That makes what we’re about to say next even better. 

Symantec Endpoint Security (SES) Complete was named a Certified Leader in AV-Comparatives’ 2026 Endpoint Prevention and Response (EPR) Test.

AV-Comparatives, a recognized authority on security solutions worldwide, ran top enterprise solutions through complex, multi-stage attack scenarios designed to emulate the very real attacks organizations are up against every day. Rigorously assessing each product’s ability to prevent, detect, respond to, and help remediate threats, the EPR test evaluates how many threats break through. Testing takes place across three phases: compromise and foothold, internal propagation, and asset breach. 

And SES Complete stopped 100% of attacks from reaching the final phase. That includes blocking attempts across privilege escalation, defense evasion, credential access, discovery, and lateral movement—the very techniques attackers use all too often to deepen their foothold and work their way towards your precious assets. When SES Complete faced off against their worst, every attack was blocked prior to the final asset breach phase. 

That’s more than some bold claim. It’s security that’s hard-earned its accolades. 

One agent, one console—the whole attack surface

Traditional endpoint protection approaches have historically focused on detecting and responding to malicious activity, but SES Complete takes a more proactive approach. Beyond the protection demonstrated in the EPR test, SES Complete includes predictive and adaptive capabilities to interrupt living-off-the-land (LOTL) activity, protect identities, and stop attacks before they advance.

What SES Complete accomplished under AV-Comparatives EPR was no easy feat. Even when faced with a wide array of attack vectors—from executables, scripts, installers, add-ins, and USB-propagated payloads—SES Complete stood its ground. 

“This is the kind of dependable, full-chain protection enterprises rely on.”  —Andreas Clementi, Founder & CEO of AV-Comparatives 

The EPR results are a valuable example of SES Complete’s ability to prevent attacks from advancing through the attack chain. But that’s merely one part of its broader proactive defense strategy. AI-driven capabilities like Adaptive Protection and Incident Protection can take this defense even further, helping security teams adapt protection to their environments and anticipate where an attack might go next.   

Defense that knows the difference 

LOTL techniques are a pain to stop for a reason. Attackers can easily hide behind the legitimate tools your employees use every day. Lock them down and you risk disrupting operations. Leave it open and attackers move right in.  

Adaptive Protection, part of SES Complete, finds the middle ground. It learns your organization’s version of normal and automatically tunes policy to block malicious uses of legitimate tools while allowing business as usual. That results in more precise prevention without relying on static, one-size-fits-all hardening rules. 

And when something does happen, Incident Summaries can help analysts get up to speed faster with an AI-generated narrative of the incident and the full attack chain. Instead of piecing together a trail of alerts, analysts get a clearer picture in seconds of what happened and where to focus next.

The next move doesn’t have to be a surprise 

Incident Prediction builds on Adaptive Protection with AI that forecasts an attacker’s next four or five moves with up to 100% confidence. Trained on more than 500,000 real-world attack chains curated by Symantec’s Threat Hunter Team, it can detect when legitimate tools such as PowerShell, WMI, and PsExec are being turned against your organization and help disrupt the attack before it moves further. 

By connecting those behaviors into a larger attack sequence, Incident Prediction gives analysts a clear view of what could happen next, along with the context necessary to decide where their intervention will have the biggest impact. And that completely changes the response. When every second counts, the ability to act earlier can be the difference between a breach and a contained incident. 

Being a leader isn’t easy, and that’s the point 

As proud as we are of this acknowledgement, we know that being a leader means continuing to prove yourself. It’s decades of continuous refinement, rigorous testing, and countless hours finding ways to make our solutions simpler for your defenders, without sacrificing the depth of protection they’ve come to rely on. 

Threats keep moving, so security has to keep proving itself. SES Complete’s Certified Leader recognition from AV-Comparatives validates the years we’ve spent making sure every SOC has access to enterprise-grade endpoint security. 

See how SES Complete can simplify and strengthen your endpoint security. Connect with your in-region experts to learn more. 

You might also enjoy

Upcoming Events

See what's next

Threat Updates

Get the latest