What can antivirus detection prove?¶
An antivirus detection proves that a product matched a file, process or behaviour to its detection logic and recorded a result. What it proves beyond that depends on the underlying event and the action the product took.
The product may have blocked a download before execution, quarantined an inactive file, terminated a running process or raised a behavioural alert for activity that continued. Those outcomes have very different implications for compromise and harm.
Read beneath the alert label¶
Preserve the alert or export together with:
- product and engine version;
- detection name and time;
- affected file path, hash, process or command;
- rule, signature or behavioural basis where available;
- action taken and whether it succeeded;
- linked events, device and account identifiers; and
- later analyst or vendor reclassification.
Detection names are vendor terminology. A name may describe a known family, a generic technique, a potentially unwanted application or a confidence-based assessment. Different products can assign different labels to the same sample, and a generic initial label may change after further analysis.
Consequently, the name alone does not prove authorship, a particular campaign or an offender group. Nor does the absence of a detection prove the absence of malware: coverage depends on the product, configuration, visibility and detection knowledge available at the time.
Connect detection to activity¶
Use the alert to locate more direct evidence. Process records can show whether code ran; file and memory analysis can establish what was present; network and account records can show resulting activity. A product log reporting that prevention succeeded may support the conclusion that a particular attempt was blocked, but it should not be generalised to every route or stage of the incident.
Retention may be short, and console data may change as detections are enriched. Promptly preserving both the original alert and its classification history makes the eventual conclusion reproducible.
Key takeaway
Antivirus detection is a valuable lead and sometimes evidence of a blocked or running event, but execution, effect and attribution must come from the alert details and corroborating records - not the detection name alone.