More likely how our Malwarebytes is configured, I do have it set to use High CPU for example. There's a balance of security vs usability and rarely is 900Mbps being downloaded for continuous periods. There's likely ways to mitigate. The deployment is via profile inc config, and I can't be bothered adjusting it significantly as it would impact the estate. Largely it is configured out of the box, with exception, the scan frequency is reduced as its operating with the agent active, loaded onto a machine that is a fresh image. Hence, the agent is monitoring anything added/removed, which again is bounded by security mechanisms set by privilege. Generally my machine is outside the scope anyway, I have tools deployed *should* I use it for system access, but that would mean loading on more profiles for monitoring of device etc. I leverage Citrix VDI, so this is the middle ground and allows me to see how sw performs on a BYOD device (which is approved), where VDI is unworkable (rarely).
EDIT: Config was ratified by their approved consultancy, leveraging Jamf Pro. I did raise the CPU issue a while back, and was informed it is set to scan each file as it is "saved." What this means in practice is if I download a single large file, it doesn't scan until the end. If I load something such as a one drive and sync locally, with say 10k files, it will spin up the cpu as each file is saved, this is when it can use lots of CPU when lots of files are dropping all at once, at high speed.
One Drive is configured to adapt number of simultaneous connections to balance the end user experience. At faster speeds there's a greater number (provided there is not retransmission / packet loss).
Edited by ukhardy07 (Mon 06-Feb-23 19:18:10)