Most engines ask whether anyone has reported a file yet. Atomdrift reads it and decides at scan
time, and nothing leaves your machine. Measured every day against live malware under 48 hours old.
curl -fsSL https://install.atomdrift.org/scan.sh | sh
Apache-2.0 · Linux, macOS, Windows, BSD, illumos · no telemetry
Last 7 days · 13 runs
· 2026-10-08
80.3%
Zero-day malware detected
0.5%
false positives
Hostile
58.6%
0.2% false positives
Suspicious
21.7%
0.3% false positives
L0L2000–L2500
at L25— the shipped default
Hostile is a confident detection, suspicious one to review. LN expects
N hostile false positives per 100 million benign files; raising it moves detections from suspicious to
hostile · 568 zero-day samples, median
4 h old · 612 known-good
Detected per engine identical cohort
Atomdrift
80.3% (≥ suspicious)
VirusTotal
69.2% (n≥1)
malcontent
58.1% (≥ high)
ClamAV
29.8%
Socket
10.9%
GuardDog
6.3% (risk≥5)
Aikido Malware
4.9%
SafeDep
4.4%
VirusTotal
98.3% (n≥1)
Atomdrift
97.8% (≥ suspicious)
malcontent
78.7% (≥ high)
ClamAV
55.1%
Aikido Malware
0.0%
GuardDog
0.0% (risk≥5)
SafeDep
0.0%
Socket
0.0%
VirusTotal
96.4% (n≥1)
malcontent
94.6% (≥ high)
Atomdrift
94.6% (≥ suspicious)
ClamAV
61.3%
Aikido Malware
0.0%
GuardDog
0.0% (risk≥5)
SafeDep
0.0%
Socket
0.0%
VirusTotal
82.9% (n≥1)
Atomdrift
80.0% (≥ suspicious)
malcontent
32.9% (≥ high)
ClamAV
1.4%
Aikido Malware
0.0%
GuardDog
0.0% (risk≥5)
SafeDep
0.0%
Socket
0.0%
Atomdrift
64.3% (≥ suspicious)
VirusTotal
3.6% (n≥1)
Aikido Malware
0.0%
ClamAV
0.0%
GuardDog
0.0% (risk≥5)
malcontent
0.0% (≥ high)
SafeDep
0.0%
Socket
0.0%
GuardDog
57.5% (risk≥5)
Atomdrift
50.0% (≥ suspicious)
Socket
37.5%
malcontent
27.5% (≥ high)
Aikido Malware
25.0%
SafeDep
17.5%
VirusTotal
12.5% (n≥1)
ClamAV
0.0%
Socket
84.4%
Atomdrift
75.0% (≥ suspicious)
malcontent
71.9% (≥ high)
Aikido Malware
40.6%
GuardDog
34.4% (risk≥5)
VirusTotal
28.1% (n≥1)
ClamAV
0.0%
SafeDep
0.0%
VirusTotal
95.5% (n≥1)
Atomdrift
22.7% (≥ suspicious)
ClamAV
9.1%
Aikido Malware
0.0%
GuardDog
0.0% (risk≥5)
malcontent
0.0% (≥ high)
SafeDep
0.0%
Socket
0.0%
SafeDep
100.0%
Socket
100.0%
Atomdrift
94.4% (≥ suspicious)
malcontent
77.8% (≥ high)
Aikido Malware
11.1%
ClamAV
0.0%
GuardDog
0.0% (risk≥5)
VirusTotal
0.0% (n≥1)
VirusTotal
56.3% (n≥1)
malcontent
56.3% (≥ high)
Atomdrift
50.0% (≥ suspicious)
Aikido Malware
0.0%
ClamAV
0.0%
GuardDog
0.0% (risk≥5)
SafeDep
0.0%
Socket
0.0%
VirusTotal
28.6% (n≥1)
Atomdrift
28.6% (≥ suspicious)
Aikido Malware
0.0%
ClamAV
0.0%
GuardDog
0.0% (risk≥5)
malcontent
0.0% (≥ high)
SafeDep
0.0%
Socket
0.0%
malcontent
80.0% (≥ high)
VirusTotal
40.0% (n≥1)
Atomdrift
20.0% (≥ suspicious)
Aikido Malware
0.0%
ClamAV
0.0%
GuardDog
0.0% (risk≥5)
SafeDep
0.0%
Socket
0.0%
Atomdrift
75.0% (≥ suspicious)
VirusTotal
50.0% (n≥1)
Aikido Malware
0.0%
ClamAV
0.0%
GuardDog
0.0% (risk≥5)
malcontent
0.0% (≥ high)
SafeDep
0.0%
Socket
0.0%
Atomdrift
66.7% (≥ suspicious)
GuardDog
66.7% (risk≥5)
Aikido Malware
33.3%
malcontent
33.3% (≥ high)
Socket
33.3%
VirusTotal
33.3% (n≥1)
ClamAV
0.0%
SafeDep
0.0%
Atomdrift
50.0% (≥ suspicious)
Aikido Malware
0.0%
ClamAV
0.0%
GuardDog
0.0% (risk≥5)
malcontent
0.0% (≥ high)
SafeDep
0.0%
Socket
0.0%
VirusTotal
0.0% (n≥1)
Atomdrift
100.0% (≥ suspicious)
Aikido Malware
0.0%
ClamAV
0.0%
GuardDog
0.0% (risk≥5)
malcontent
0.0% (≥ high)
SafeDep
0.0%
Socket
0.0%
VirusTotal
0.0% (n≥1)
Aikido Malware
100.0%
Socket
50.0%
Atomdrift
0.0% (≥ suspicious)
ClamAV
0.0%
GuardDog
0.0% (risk≥5)
malcontent
0.0% (≥ high)
SafeDep
0.0%
VirusTotal
0.0% (n≥1)
detected as hostiledetected as suspiciousnot detected, or no record · a missout of scope · a misserrored · a miss
Reputation lookups (Socket, Aikido, SafeDep) answer whether a package has been reported.
413 of 568 samples weren't registry packages at all; of the
155 Socket could look up, it had a record for 62.
VirusTotal is 62 engines
voting, one upload at a time: its public API allows four lookups a minute and five hundred a day. We upload the malware it
has never seen; known-good files are only looked up. How Atomdrift decides →
Runs on your cores. Local, CPU-only, air-gapped if you like. No per-query bill, no rate limit, no
upload.
Reads 100+ formats. Source in every major language, ELF, PE, Mach-O, firmware, containers, archives,
documents; packages from 47 registries.
Built to be embedded. Exit codes, JSON, an HTTP service, Rust libraries. Apache-2.0: ship it inside
what you sell.
Detected as hostile: malware vs. known-good sliders try each engine's other settings
Detection and false-positive chart data
VirusTotal n≥6: 59.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥5: 61.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥4: 62.1% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
VirusTotal n≥3: 63.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥2: 66.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥1: 69.2% of malware detected as hostile, 0.7% of known-good detected as hostile.
Atomdrift L0: 38.9% of malware detected as hostile, 0.2% of known-good detected as hostile.
Atomdrift L1–L10: 39.1% of malware detected as hostile, 0.2% of known-good detected as hostile.
Atomdrift L25: 58.6% of malware detected as hostile, 0.2% of known-good detected as hostile (default).
Atomdrift L50: 60.9% of malware detected as hostile, 0.3% of known-good detected as hostile.
Atomdrift L100–L250: 62.7% of malware detected as hostile, 0.3% of known-good detected as hostile.
Atomdrift L500: 79.6% of malware detected as hostile, 0.3% of known-good detected as hostile.
Atomdrift L1000: 79.8% of malware detected as hostile, 0.3% of known-good detected as hostile.
Atomdrift L2000–L2500: 80.3% of malware detected as hostile, 0.3% of known-good detected as hostile.
malcontent critical: 36.1% of malware detected as hostile, 0.5% of known-good detected as hostile (default).
malcontent critical+high: 58.1% of malware detected as hostile, 7.0% of known-good detected as hostile.
ClamAV hostile: 29.8% of malware detected as hostile, 0.0% of known-good detected as hostile.
Socket hostile: 10.9% of malware detected as hostile, 0.0% of known-good detected as hostile.
Aikido Malware hostile: 4.9% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥10: 0.9% of malware detected as hostile, 0.2% of known-good detected as hostile.
GuardDog risk≥9: 1.1% of malware detected as hostile, 0.2% of known-good detected as hostile.
GuardDog risk≥8: 2.6% of malware detected as hostile, 0.2% of known-good detected as hostile.
GuardDog risk≥7: 4.2% of malware detected as hostile, 0.5% of known-good detected as hostile (default).
GuardDog risk≥6: 5.3% of malware detected as hostile, 0.7% of known-good detected as hostile.
GuardDog risk≥5: 6.3% of malware detected as hostile, 0.8% of known-good detected as hostile.
SafeDep hostile: 4.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Detection and false-positive chart data
VirusTotal n≥6: 95.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥5: 95.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥4: 96.1% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
VirusTotal n≥3: 96.6% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥2: 97.2% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥1: 98.3% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L0: 51.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1–L10: 51.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L25: 87.1% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
Atomdrift L50: 87.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L100–L250: 87.6% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L500: 97.2% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1000: 97.8% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L2000–L2500: 97.8% of malware detected as hostile, 0.0% of known-good detected as hostile.
ClamAV hostile: 55.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
malcontent critical: 43.8% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
malcontent critical+high: 78.7% of malware detected as hostile, 0.0% of known-good detected as hostile.
Aikido Malware hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥10: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥9: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥8: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥7: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
GuardDog risk≥6: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥5: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
SafeDep hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Socket hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Detection and false-positive chart data
VirusTotal n≥6: 85.6% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥5: 87.4% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥4: 89.2% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
VirusTotal n≥3: 89.2% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥2: 91.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥1: 96.4% of malware detected as hostile, 0.0% of known-good detected as hostile.
malcontent critical: 85.6% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
malcontent critical+high: 94.6% of malware detected as hostile, 18.3% of known-good detected as hostile.
Atomdrift L0: 72.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1–L10: 72.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L25: 79.3% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
Atomdrift L50: 79.3% of malware detected as hostile, 1.7% of known-good detected as hostile.
Atomdrift L100–L250: 82.9% of malware detected as hostile, 1.7% of known-good detected as hostile.
Atomdrift L500: 94.6% of malware detected as hostile, 1.7% of known-good detected as hostile.
Atomdrift L1000: 94.6% of malware detected as hostile, 1.7% of known-good detected as hostile.
Atomdrift L2000–L2500: 94.6% of malware detected as hostile, 1.7% of known-good detected as hostile.
ClamAV hostile: 61.3% of malware detected as hostile, 0.0% of known-good detected as hostile.
Aikido Malware hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥10: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥9: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥8: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥7: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
GuardDog risk≥6: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥5: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
SafeDep hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Socket hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Detection and false-positive chart data
VirusTotal n≥6: 58.6% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥5: 64.3% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥4: 68.6% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
VirusTotal n≥3: 72.9% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥2: 81.4% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥1: 82.9% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L0: 37.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1–L10: 37.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L25: 47.1% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
Atomdrift L50: 47.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L100–L250: 48.6% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L500: 75.7% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1000: 75.7% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L2000–L2500: 80.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
malcontent critical: 17.1% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
malcontent critical+high: 32.9% of malware detected as hostile, 0.0% of known-good detected as hostile.
ClamAV hostile: 1.4% of malware detected as hostile, 0.0% of known-good detected as hostile.
Aikido Malware hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥10: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥9: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥8: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥7: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
GuardDog risk≥6: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥5: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
SafeDep hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Socket hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Browser Extensions: 3 known-good samples of this kind in the last 7 days is too few for a false-positive rate. The bars above still show it.
Detection and false-positive chart data
Socket hostile: 37.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥10: 2.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥9: 5.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥8: 15.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥7: 32.5% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
GuardDog risk≥6: 45.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥5: 57.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
Aikido Malware hostile: 25.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L0: 2.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1–L10: 2.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L25: 20.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
Atomdrift L50: 25.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L100–L250: 25.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L500: 50.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1000: 50.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L2000–L2500: 50.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
SafeDep hostile: 12.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
malcontent critical: 5.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
malcontent critical+high: 27.5% of malware detected as hostile, 3.8% of known-good detected as hostile.
VirusTotal n≥6: 2.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥5: 2.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥4: 2.5% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
VirusTotal n≥3: 2.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥2: 5.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥1: 12.5% of malware detected as hostile, 1.3% of known-good detected as hostile.
ClamAV hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Detection and false-positive chart data
Socket hostile: 84.4% of malware detected as hostile, 0.0% of known-good detected as hostile.
malcontent critical: 43.8% of malware detected as hostile, 1.6% of known-good detected as hostile (default).
malcontent critical+high: 71.9% of malware detected as hostile, 19.4% of known-good detected as hostile.
Aikido Malware hostile: 40.6% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L0: 9.4% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1–L10: 9.4% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L25: 40.6% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
Atomdrift L50: 40.6% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L100–L250: 46.9% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L500: 75.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1000: 75.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L2000–L2500: 75.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥10: 12.5% of malware detected as hostile, 1.6% of known-good detected as hostile.
GuardDog risk≥9: 12.5% of malware detected as hostile, 1.6% of known-good detected as hostile.
GuardDog risk≥8: 25.0% of malware detected as hostile, 1.6% of known-good detected as hostile.
GuardDog risk≥7: 28.1% of malware detected as hostile, 3.2% of known-good detected as hostile (default).
GuardDog risk≥6: 31.3% of malware detected as hostile, 4.8% of known-good detected as hostile.
GuardDog risk≥5: 34.4% of malware detected as hostile, 4.8% of known-good detected as hostile.
VirusTotal n≥6: 25.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥5: 25.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥4: 25.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
VirusTotal n≥3: 25.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥2: 25.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥1: 28.1% of malware detected as hostile, 1.6% of known-good detected as hostile.
ClamAV hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
SafeDep hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Detection and false-positive chart data
VirusTotal n≥6: 59.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥5: 63.6% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥4: 63.6% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
VirusTotal n≥3: 68.2% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥2: 90.9% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥1: 95.5% of malware detected as hostile, 0.7% of known-good detected as hostile.
Atomdrift L0: 4.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1–L10: 4.5% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L25: 13.6% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
Atomdrift L50: 13.6% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L100–L250: 13.6% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L500: 22.7% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1000: 22.7% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L2000–L2500: 22.7% of malware detected as hostile, 0.0% of known-good detected as hostile.
ClamAV hostile: 9.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
Aikido Malware hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥10: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥9: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥8: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥7: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
GuardDog risk≥6: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥5: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
malcontent critical: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
malcontent critical+high: 0.0% of malware detected as hostile, 0.7% of known-good detected as hostile.
SafeDep hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Socket hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Detection and false-positive chart data
SafeDep hostile: 100.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Socket hostile: 100.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Aikido Malware hostile: 11.1% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L0: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1–L10: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L25: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
Atomdrift L50: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L100–L250: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L500: 94.4% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L1000: 94.4% of malware detected as hostile, 0.0% of known-good detected as hostile.
Atomdrift L2000–L2500: 94.4% of malware detected as hostile, 0.0% of known-good detected as hostile.
ClamAV hostile: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥10: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥9: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥8: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥7: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
GuardDog risk≥6: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
GuardDog risk≥5: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
malcontent critical: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
malcontent critical+high: 77.8% of malware detected as hostile, 7.9% of known-good detected as hostile.
VirusTotal n≥6: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥5: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥4: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile (default).
VirusTotal n≥3: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥2: 0.0% of malware detected as hostile, 0.0% of known-good detected as hostile.
VirusTotal n≥1: 0.0% of malware detected as hostile, 1.6% of known-good detected as hostile.
Java: 1 known-good sample of this kind in the last 7 days is too few for a false-positive rate. The bars above still show it.
Android: 7 malware samples in the last 7 days is too few to chart. The bars above still show it.
macOS: 5 malware samples in the last 7 days is too few to chart. The bars above still show it.
Archives: 4 malware samples in the last 7 days is too few to chart. The bars above still show it.
Go: 3 malware samples in the last 7 days is too few to chart. The bars above still show it.
Editor Extensions: 2 malware samples in the last 7 days is too few to chart. The bars above still show it.
PHP: 2 malware samples in the last 7 days is too few to chart. The bars above still show it.
Rust: 2 malware samples in the last 7 days is too few to chart. The bars above still show it.
Each dot is an engine at one setting, plotting what it detects as hostile there; its
suspicious detections, counted in the bars above, are not plotted. Defaults: Atomdrift L25 (as shipped), VirusTotal n≥4 (engines agreeing), malcontent critical, GuardDog risk≥7 (its “likely malicious”). Socket, Aikido Malware and SafeDep had no record of any known-good file they could look
up, and VirusTotal had a record of 178 of 612. No record counts as not flagged, so those
false-positive rates include files the engine never judged.
Run by run last 30 days · detected, hostile or suspicious, as the bars count it
Each point is the malware one run added, scored like the bars above. A sample drawn again within the
week counts in the run that first scanned it, so the shaded runs pool to exactly the figures at the top. A fresh
cohort every run, so every line swings. Judge us on the worst night, not the best.
False positives
Of 612 known-good samples, Atomdrift detected 3 (0.5%):
1 as hostile (0.2%) and
2 as suspicious (0.3%).
What “zero-day” means here. Every detection sample first appeared in the wild less than 48
hours before the run (median 4 h, youngest
0.7 h): too new for reputation or download
history to form, and usually for a signature of its own — though one from a known family can still match an
older signature, which is why signature engines score at all. Catching malware a feed has already named is a
different, easier problem.
How this is scored. Every engine gets the identical cohort, and a skip counts as a miss for
everyone — a file nobody scanned is a file nobody detected. The bars count everything an engine detects, down to
the setting named beside it; the chart counts what it detects as hostile, one dot per setting. A sample drawn by
more than one run in the window counts once, at its first scan. A listing from a contestant's own feed counts
only once an independent engine corroborates it. The 612 known-good samples are 406 registry packages, 77
project and vendor downloads and 129 files whose source wasn't
recorded, which reached our collection up to 60 days before they were scanned (median
32). Each is re-checked later: one that turns out to be malware is dropped from the
false-positive rates, and any engine that flagged it is credited with an early detection.
We run this benchmark and we're one of the engines in it, so we publish every sample, verdict and rate.
Why the cohort isn't a random sample. A plain random draw from the malware and open-source
firehoses is dominated by whatever published most: three registries took 70% of the known-good seats and Windows
executables 60% of the malware seats, which left most file formats never measured at all. So each cohort is built
from two parts. Most seats track the real population, damped by a square root so the biggest format stays the
biggest without crowding out everything else. The rest go one-per-format on a rotation, and that rotation is the
only reason a Firefox add-on or a Conda package appears here at all.
Over the last 7 days: 376 proportional seats and
192 rotation seats on the malware side, across
24 formats.
So every rate is published twice. The bars show the rate over this cohort. Because the cohort
over-samples rare formats deliberately, that is not what an engine would score on the population — so each rate
is also re-weighted by every format's true share of it.