The bit about the anti-malware is sad. Does anyone remember a true positive from their AV? I can recall countless incidents caused by false positives, but can’t remember a single true positive. The latest was Crowdstrike Falcon (AI POWERED!!1) flagging signtool.exe as malware. The one from the Windows SDK. By Microsoft. Signed with Microsoft keys.
Yes. I don't remember the details but there was one time where it prevented me from executing some download that was malicious. This was more than a decade ago.
On another occasion (around the same time) it failed to prevent malware from executing. I never found out what the method of infection was, but after changing back the wallpaper and removing it from startup programs, I suffered no further ill effects... fifteen year old me was not very thorough but seems to have worked anyway.
And then there are the numerous annoyance occasions where it false-positived on legitimate software like Nirsoft, Cain&Abel, Netcat, Nmap, etc. Not to mention corporate proxies blocking my personal link shortener but being fine with bitly. Security theatre, those are.
To be fair, AV also prevents executing standard metasploit things and attackers have to be a bit more creative which gets tedious and so it can be an indicator of compromise to have this pop an alert even if the attacker succeeds a few minutes later.