How Defendrix compares.
A capability-oriented view of what the current client implements and where its authority ends. Vendor-to-vendor rankings wait for reproducible independent testing of exact versions and settings.
Capability
Current status
Evidence boundary
Real-time file observation and scanning
Implemented
User-mode watchers are lossy; overflow and scan failures reduce health instead of producing a clean result.
Behavior and execution evidence
Implemented
Primarily post-launch observation. Weak or incomplete signals cannot independently authorize destructive remediation.
Ransomware honeypot and correlation
Implemented
Independent decoy, entropy, and behavior evidence must converge on one recaptured process identity.
Boot and EFI-relevant state audit
Implemented
User-mode measurement, not ELAM or a signed storage filter. Missing enrollment and mismatches remain visible.
Live patch / inline-hook detection
Implemented
Selected loaded modules are compared with their on-disk images; coverage is not universal kernel attestation.
Authenticated incident observations to LAN peers
Observe-only
Eligible receivers validate and log bounded signals. They do not accept a remote verdict or auto-change policy.
ARP and LAN anomaly evidence
Implemented
Gateway and network inconsistency is evidence, not attribution; local containment requires a verified OS result.
DNS configured-list enforcement
Opt-in
Marker-owned hosts-file entries are verified. DoH, direct IP, alternate resolvers, and administrator override remain outside it.
Remote support
Consent-gated
A 9-digit routing ID is not an authenticator. Sessions require identity, local approval, bounded permissions, and expiry.
Windows Defender coexistence
Implemented
Defendrix does not disable Defender or add an install-folder exclusion; exact compatibility still needs clean-VM matrix testing.
Activated-device seat licensing
Implemented
The dashboard releases only eligible non-admin seats after fresh reauthentication. Permanent in-app self-deletion is separate, hardware-bound, and irreversible.
Hardware-bound Owner administration
Implemented
Exactly one privileged identity is admitted through the full authoritative binding. There is no generic HWID admin bypass.
Offline grace after validated activation
24 hours
Requires protected token state, exact prior identity, sane timestamps, and prior server validation.
Comparative antivirus superiority
Not established
Requires exact signed builds, frozen datasets, current comparators, independent execution, and efficacy, false-positive, recovery, and performance evidence.
The short version
Defendrix combines endpoint scanning, LAN telemetry, fleet correlation, activated-seat licensing, and consent-gated remote support in one Windows client.
See pricing