Home › Windows, macOS and Linux
What your desktop already protects, before you install anything
Windows, macOS and Linux each arrive with security features switched on by default. Knowing what they are is the only way to judge whether a paid product would add something or repeat it.
Why the platform question comes first
A decade ago, buying security software was close to automatic on one platform and unusual on the others. That gap has narrowed from both directions: the built-in defences on every desktop system have grown substantially, while the attacks that matter most to households have shifted towards methods that no operating system can prevent, because they target the person rather than the machine.
The practical consequence is that a sensible answer to "do I need antivirus?" depends on which desktop you are sitting at, what it already runs, and whether those features are actually enabled. This page sets out the first two. Only you can check the third, and it takes about two minutes.
One scope note: this guide covers desktop and laptop computers. Mobile phones and tablets have quite different security models, and we do not cover them.
Windows
Current versions of Windows include a security stack that runs by default on a machine with no third-party product installed. Microsoft documents these features for consumers in its Windows support material at support.microsoft.com. The components most relevant to a home desktop are these.
- Microsoft Defender Antivirus
- Real-time file protection with the layered approach described in how antivirus software works: signature matching, heuristics, cloud lookups and behaviour monitoring. It updates through Windows Update and switches itself off automatically when a third-party product registers as the active antivirus, which is why running two is not additive.
- SmartScreen
- Reputation checking applied to downloaded files and to addresses visited in Microsoft Edge. An unrecognised executable prompts a warning that many users have learned to click past — worth pausing on rather than dismissing.
- Controlled folder access
- The ransomware-shielding feature: nominated folders can only be written to by applications on an allowed list. It is not enabled by default in all configurations, and turning it on is free.
- Windows Firewall
- Network filtering, on by default, with separate profiles for private and public networks. A security suite's firewall generally replaces this rather than adding to it.
- User Account Control and standard accounts
- The prompt that appears when software asks for administrative rights. Its effectiveness is much higher when day-to-day use happens in a standard account rather than an administrator account — a change that costs nothing and is rarely made.
- BitLocker device encryption
- Protects data if the machine is stolen. Availability depends on the Windows edition and hardware.
Third-party products on Windows therefore compete with a capable default. The reasons people still buy them are mostly the ones in our free versus paid comparison: bundled tools, support, and features aimed at shared or family machines.
macOS
Apple builds several independent layers into macOS, described in its Platform Security guide at support.apple.com. They work differently from a traditional scanner, which is why the "do Macs need antivirus?" question generates such inconsistent answers.
- Gatekeeper checks that applications come from an identified developer and have been notarised by Apple before allowing them to run for the first time.
- XProtect is a signature-based malware check applied when applications launch, updated separately from full system updates.
- System Integrity Protection prevents modification of protected system files, including by a process running with administrative rights.
- Sandboxing and permission prompts restrict what applications can reach — the microphone, the camera, the Documents folder, screen recording — and require explicit consent per application.
- FileVault provides full-disk encryption.
Two honest observations follow. macOS is not immune; malware targeting it exists, and adware and unwanted "cleaner" applications are a genuinely common nuisance on the platform. At the same time, the most frequent problems Mac users encounter are phishing, imitation support pop-ups and subscription scams, which no scanner on the machine addresses. That is a strong argument for reading our page on fake alerts and support scams before deciding anything about software.
Linux desktops
Linux distributions take a different approach again, and the difference is structural rather than a matter of features.
Software normally arrives through a distribution's package repositories, signed and maintained by the distribution, which removes the single largest infection route on other platforms: downloading an executable from an unknown web page. Standard users do not run with administrative rights, and privilege escalation is an explicit, audited step. Many distributions also apply mandatory access control frameworks that confine what a compromised process can reach.
Desktop antivirus scanners on Linux exist, and they have two sensible uses. The first is scanning files that will be passed on to Windows or macOS users — a Linux machine can carry malware harmlessly and still hand it to someone else. The second is compliance, where an organisation requires a scanner regardless of platform. For a personal Linux desktop that installs from repositories and updates promptly, a resident scanner is usually not the highest-value addition; keeping the system updated and backed up is.
The risks that do apply to Linux users are the cross-platform ones: browser-based phishing, malicious extensions, compromised credentials, and software installed from outside the repositories without checking its source.
| Question | Windows | macOS | Linux desktop |
|---|---|---|---|
| Real-time malware scanning built in? | Yes, on by default | Checks at launch rather than a resident scanner | Not by default |
| Main software source | Web downloads and the Microsoft Store | App Store and notarised developer downloads | Distribution repositories |
| Firewall included? | Yes, enabled | Yes, available in settings | Yes, via the distribution's tools |
| Disk encryption available? | BitLocker, edition-dependent | FileVault | Usually offered at installation |
| Most common real-world problem | Downloaded software and phishing | Adware, imitation support pop-ups, phishing | Phishing and credential reuse |
| Typical case for a paid product | Shared or family machines, bundled tools, support | Households wanting adware clean-up and support | Scanning files bound for other platforms |
The practices that apply on all three
Whatever platform you are on, these do more for a household than the choice between two security products, and the Australian Cyber Security Centre's guidance for individuals and families at cyber.gov.au covers them in more detail.
- Apply operating system and browser updates promptly rather than deferring them indefinitely.
- Use a standard, non-administrator account for everyday work.
- Keep at least one backup that is not permanently connected to the computer.
- Turn on multi-factor authentication for email first, then banking, then everything else — email is the account that can reset the others.
- Use distinct passwords, stored in a manager rather than reused across services.
- Install software from the vendor's own site or the platform's store, never from a link in a pop-up.
- Turn on disk encryption if the machine ever leaves the house.
Check before you buy
Open your system's security settings and confirm what is already switched on. People regularly buy a product to obtain a capability their computer had all along but had quietly disabled — often because a previous trial version registered itself as the active antivirus and was never fully removed.
So does your machine need more?
On Windows, a third-party product is a reasonable purchase for a shared household machine, and a genuinely optional one for a careful single user. On macOS, the case rests more on adware clean-up and support than on the scanner itself. On a Linux desktop installing from repositories, it is usually the least necessary of the three.
In every case the decision improves once you have taken the inventory described in choosing antivirus software. Avast, the vendor this site has a commercial relationship with, publishes consumer products for these desktop platforms; what we can and cannot say about them is set out in our vendor profile.