Updated: October 2026
Every Windows endpoint ships with antivirus, and businesses still buy more of it. Brand matters far less than two other things: what the scanner covers, and what walks straight past it. This guide breaks down how antivirus software finds malware, what separates a business product from the consumer one, and where detection and response has to take over.
TL;DR
- Antivirus software. Software that finds and blocks known malicious files on an endpoint, using signatures, code analysis, behavior rules and cloud lookups.
- Business vs consumer. Same engine, different plumbing: central policy, reporting and per-seat licensing.
- The limit. CrowdStrike counted 82% of 2025 detections as malware-free, so there's often no file to scan.
- The call. Keep antivirus as the file-blocking floor. Add detection and response for anything that logs in rather than infects.
What Antivirus Software Does
Antivirus software watches the files arriving on a machine and stops the ones it recognizes as malicious. It's a filter with a memory. Something lands on disk, gets written, gets opened or gets executed, and the scanner checks it before the operating system hands over control.
Three jobs sit inside that one description. Real-time protection inspects files as they appear, which is the part doing most of the work. Scheduled scanning sweeps the disk for anything that slipped in while the agent was off or out of date. Remediation quarantines or deletes what it finds and tries to undo the changes.
The name has drifted from the job. "Antivirus" dates from when viruses were the threat and antimalware became the more accurate label, covering trojans, worms, ransomware droppers, cryptominers, adware and info-stealers. Vendors now use the terms interchangeably. Treat antivirus and antimalware as the same category and read the feature list instead of the label.
What antivirus is good at is volume. Commodity malware still arrives constantly through email attachments, fake installers and USB keys, and a scanner kills it silently thousands of times before anyone files a ticket. That's unglamorous and worth paying for. The trouble starts when the attack doesn't involve a file at all.
The Four Ways Antivirus Finds Malware
Detection isn't one technique. Modern engines stack four, and knowing which one caught something tells you how much confidence to put in the alert.
Signature matching compares a file's hash or byte patterns against a database of known-bad samples. It's fast, cheap and close to zero false positives, because a match means this exact thing has been seen and classified before. It also means the sample had to be caught somewhere first. Change one byte and the hash changes, which is why polymorphic malware rewrites itself on every delivery.
Static heuristics read the file without running it. The engine looks at structure instead of identity: packed or obfuscated code, imports that a normal document has no business calling, a macro that reaches for PowerShell. No prior sample needed, so it catches new variants of old families. The cost is false positives, which is why a badly tuned engine quarantines a legitimate installer.
Behavioral monitoring watches what a process does once it's running. Mass file encryption, shadow copy deletion, credential store access, a Word process spawning a shell. This is the layer that stops something the first two missed, and it's the layer that overlaps with EDR. Detection here happens after execution starts, so the question becomes how fast the response fires.
Cloud lookups and sandboxing send a hash or the file itself to the vendor's backend. A reputation query returns a rating in milliseconds based on what the vendor has seen across its whole install base. Full sandbox detonation runs the sample in an isolated VM and reports what it did. Both move the heavy analysis off the endpoint, and both need connectivity, so a laptop offline on a plane falls back to local signatures.
Vendors call the combination next-generation antivirus. The label mostly signals that machine learning classifiers and behavioral rules carry more weight than the signature file. Useful, and still scoped to things that run on the endpoint.
Worth knowing which layer fired when an alert lands. A signature hit is a settled fact and you can close it. A heuristic or machine learning hit is a probability, so it deserves a look before someone adds a permanent exclusion to make the noise stop. A behavioral hit means the thing was already running, which changes the question from whether to block it to what it touched first.
Business Antivirus vs Consumer Antivirus
The detection engine is usually identical. A vendor doesn't maintain two malware databases. What you pay extra for is everything around the engine.
Central management is the real dividing line. A business product reports every endpoint into one console, pushes policy from that console, and tells you which machines are unprotected, out of date or excluded from scanning. Consumer antivirus reports to the person sitting at the keyboard. At ten endpoints that difference is an inconvenience. At two hundred it's the whole product, because nobody can confirm coverage by walking the floor.
Microsoft makes the split unusually clear. Defender Antivirus ships in Windows and does the scanning. Without Intune or Business Premium behind it there's no central management, no fleet reporting and no policy enforcement, which is exactly the thing that turns a scanner into something an IT team can run. Defender for Business adds the console and the response tooling for organizations with up to 300 users.
A new business owner on r/sysadmin asked the same question in October 2025: Windows already ships Defender, so why pay for Defender for Business? The replies land on the console and reporting.
| Consumer antivirus | Business antivirus | |
|---|---|---|
| Management | Local, per device | Central console, policy push |
| Reporting | On-screen alerts | Fleet-wide, exportable, auditable |
| Licensing | Per household, 1-5 devices | Per seat or per endpoint, contract term |
| Server support | None | Windows Server, often Linux and hypervisors |
| Exclusions | User-set | Policy-controlled, logged |
| Support | Forum and chat | Named contacts, response targets |
| EULA | Personal use only | Commercial use permitted |
That last row catches people. Free consumer antivirus licenses usually prohibit business use, so a fleet running them is out of compliance regardless of how well the scanning works. Auditors ask.
Server coverage is the other line that gets crossed by accident. A file server, a domain controller and a hypervisor host each need different exclusion sets, and a workstation product pointed at them either refuses to install or scans database files it should leave alone. That's where the performance complaints come from, and it's why server licensing is priced separately rather than as an upsell.
What Antivirus Misses in 2026
The numbers have moved decisively, and they all point the same direction. Attackers stopped shipping files.
CrowdStrike's 2026 Global Threat Report counted 82% of 2025 detections as malware-free. The intruder signs in with credentials bought or phished, then works with tools already on the box: PowerShell, WMI, certutil, the RMM agent, the remote desktop client. There's no malicious binary for a scanner to match, because nothing malicious was installed.
Speed compounds it. CrowdStrike measured average breakout time, the gap between landing on one machine and moving to a second, at about 29 minutes in 2025, with the fastest at 27 seconds. Mandiant's M-Trends 2026 found that initial access brokers now hand a fresh foothold to the next group in 22 seconds. In 2022 that hand-off took more than eight hours.
Then the dwell time. Mandiant's global median rose to 14 days from 11, and some intruders now persist in edge devices that carry no standard endpoint telemetry. A firewall or VPN appliance doesn't run an antivirus agent. Nothing is scanning it.
Coverage gaps inside the fleet work the same way. Antivirus protects what the agent is installed on, which in practice means the Windows laptops and desktops somebody remembered to enroll. Network appliances, printers, hypervisors, IoT and the unmanaged contractor machine on the guest network are all outside that boundary. So is a virtual machine spun up last Thursday and never added to the console. The report says 100% compliant because it only counts what it knows about.
Put those together and the shape of the problem is clear. The file-blocking layer is doing fine at what it does. The activity that follows a stolen password generates no file events at all, and the window to notice is measured in minutes.
Detection rates aren't where the difference lies either. AV-Comparatives tested 16 enterprise and SMB products on Windows 11 in its H1 2026 Business Security Test, covering Bitdefender, Cisco, CrowdStrike, Elastic, ESET, Kaspersky, ManageEngine, Microsoft, Sophos, Trellix and others. In the malware protection part of the test, one product, Elastic Security, blocked 100% of samples with zero false alarms on common business software. The rest clustered close behind. When the field is that tight on file detection, the thing worth comparing is what happens after something gets through.
Antivirus vs EDR vs MDR
Three tiers, and the boundaries blur because vendors sell across all of them. What separates them is telemetry, retention and who's watching. For the tier above EDR, see our EDR vs XDR guide.
| Antivirus / NGAV | EDR | MDR | |
|---|---|---|---|
| Question answered | Is this file bad? | What happened on this endpoint? | Someone tell me what happened |
| Trigger | File written or executed | Process, network, registry, identity events | Same as EDR |
| Retention | Alerts and quarantine log | Weeks to months of raw telemetry | Same, held by provider |
| Response | Quarantine, delete, block | Isolate host, kill process, roll back, hunt | Provider acts on your behalf |
| Catches malware-free intrusion | Rarely | Yes, if tuned and watched | Yes |
| Needs an analyst | No | Yes | Provided |
| Runs itself overnight | Yes | Only the automated rules | Yes, staffed |
The practical relationship: EDR products include a next-generation antivirus engine, so deploying EDR generally replaces the standalone scanner rather than sitting beside it. Running two file-scanning engines on one endpoint causes conflicts and performance complaints, and one of them usually ends up disabled.
Pro Tech Show walks through where EDR, MDR and XDR differ, and why the tooling alone isn't the whole answer.
MDR exists because EDR generates alerts that need a human at 3am. An unwatched EDR console is an expensive log file. If nobody is rostered overnight, buy the watching with the tooling. Our breakdown of a working MSP security stack covers how those layers fit together with identity, email and backup.
Check the cyber insurance renewal too. If the questionnaire asks whether EDR runs on every endpoint and server, a partial deployment won't pass, and that settles the question.
The r/msp thread below asks whether Windows Defender is "good now". The top replies draw the line this section draws: the built-in antivirus and Microsoft's EDR are different products, and either one only works as well as it's configured.
When Antivirus Alone Is Enough
There are real cases, and pretending otherwise just sells things nobody needs.
Antivirus on its own holds up when the blast radius is small and the basics are done. That means multi-factor authentication on every account including remote access, no standing local administrator rights, patching that completes rather than merely runs, tested offline backups, and no regulated data on the endpoints. A small architecture practice with eight laptops, everything in a managed cloud tenant, no client financial or health records, and a day of downtime that costs a day of work: strong antivirus plus tight identity hygiene is a defensible position.
The calculation flips on any of these. Regulated or sensitive data, anything covered by HIPAA, PCI DSS or a client contract with security schedules. Downtime that costs real money per hour. Inconsistent patching or MFA, because those are what make a stolen credential useful. A cyber insurance policy, since the questionnaire decides for you. Servers, domain controllers or hypervisors, which is where an intruder goes second. And an environment nobody watches after 6pm.
There's a middle position that gets skipped. Antivirus plus centrally managed identity, conditional access and application control covers a surprising amount of the malware-free case, because it attacks the login rather than the payload. That stack won't tell you what a process did after it started, so it isn't detection and response, but it's a real step up from a scanner alone and it's usually already paid for inside an existing Microsoft 365 tenant. Turning on what you own beats buying a tier nobody will watch.
Notice that none of those triggers are about headcount. A 12-person medical billing operation needs detection and response more than a 200-person warehouse running kiosks. Size is a poor proxy for exposure, which is why "you're too small for EDR" is bad advice in either direction.
What to Check Before You Buy
Detection rate is table stakes now. These are the things that separate products once the independent lab scores come back near-identical.
Read the console first, not the feature list. Ask whether it shows you unprotected endpoints without building a report, because that single view is what stops a machine sitting agentless for four months. Check what happens to a laptop that's offline for two weeks and whether it reports on reconnection or silently drops out of inventory. Confirm server and hypervisor licensing separately, since workstation pricing rarely covers them and the surprise arrives at renewal.
Then the operational details. Find out how exclusions are set and whether they're logged, because exclusions are how antivirus gets quietly neutered and they're the first thing an auditor pulls. Ask about false positive handling and how fast a mistaken quarantine gets reversed across a fleet, not on one machine. Get the actual contract term and the mid-term seat reduction policy in writing, since per-seat licensing that only ratchets upward is how a shrinking client becomes an unprofitable one.
Finally, the integration question. Whatever runs your fleet needs to deploy the agent, verify it and alert on its absence. If the antivirus console and the RMM don't talk to each other, somebody reconciles two lists by hand every month and eventually stops. OpenFrame, the open, AI-native infrastructure layer for IT and security we build at Flamingo, can run a Defender status check as a script across a client's devices and collect the output. Which detection engine you run stays a separate decision.
Where Antivirus Fits Now
Antivirus earned its place and keeps it. It's the cheapest control in the stack per threat blocked, it works without supervision, and it handles the commodity flood that would otherwise fill the queue. Keep it, license it commercially, manage it centrally, and confirm coverage from a console rather than from memory.
Just size it correctly. It answers one question, about files, and 82% of detections last year involved no malware at all. Everything an attacker does with a working password happens somewhere antivirus isn't looking, and the gap between landing and spreading is now under half an hour. Decide deliberately whether you're covering that, and if the answer is a renewal questionnaire you haven't filled in yet, start there. For the layer above this one, read our guide to endpoint security.

Head Of Marketing
Hi all! My name is Vlad and I’ve been brought on to head the marketing team at Flamingo. Thankfully, this isn’t the first time I will be building a marketing department from scratch, so the experience should come in handy. Now it’s time to dive into the world of MSPs and find myself in this new world.
