SOC 2 Readiness
24/7 Security Monitoring
Canadian-Based SOC
GuardsArm Platform · Detect

Malware Detection

Catch malware three ways.

Signature scanning alone misses most of what matters. GuardsArm detects malware at the command line, at the file, and on the endpoint itself.

  • Process YARA
  • FIM hash reputation
  • Quarantine controls
Three detection paths converging on one finding: process and command-line pattern matching, file hash reputation, and on-agent file scanning

What is at stake

Every detection method has a well-understood blind spot, and a single-method approach is a decision about which attacks you are willing to miss.

Coverage across known files, resident files and fileless execution

Three paths with blind spots of different shapes. The point is not thoroughness for its own sake — it is that the gaps do not line up.

Suspect files never leave the host

On-endpoint analysis keeps a potentially sensitive file where it is. For regulated and air-gapped operators, detection that depends on uploading a file somewhere is simply not adoptable.

A malware finding carries the platform’s full response options

Because it is an ordinary finding, it inherits the same severity model, ATT&CK mapping and containment actions — rather than living in a separate antivirus console with its own workflow.

Who carries this

SOC and incident response, with the data-handling property mattering most to whoever signs off on your privacy and residency position.

The problem

One detection method catches one kind of malware

Signature scanning finds known files. It does not find a payload that was decoded in memory, nor a legitimate system binary doing something it should not, nor a script that never touched disk in recognisable form. Pattern matching on execution finds those, and in turn misses the dormant known-bad file sitting in a share waiting to be opened.

Reputation checking is the cheapest high-confidence verdict available and is useless against anything new. Each method has a well-understood blind spot, and the blind spots are not the same shape, which is the entire argument for running more than one.

GuardsArm runs three paths, all of them on the endpoint. That last detail matters more than it sounds: detection that requires uploading a suspect file somewhere is not available to an air-gapped deployment, and is a data-handling decision everywhere else.

The point of three detection paths is not thoroughness. It is that their blind spots do not overlap.

Capabilities

What malware detection does

Command-line and process YARA

YARA matching against process and command-line activity, which catches execution that never writes a distinctive file.

File reputation through FIM

Hashes of changed files checked against threat intelligence and malware databases as part of file integrity monitoring.

On-agent YARA with a Malware Center

YARA scanning runs on the endpoint and reports into a dedicated Malware Center with quarantine controls.

How it fits the platform

All three paths report into the same detection pipeline, so a malware finding carries the same severity model, ATT&CK mapping and response options as any other alert.

The three paths

What each one catches that the others do not

PathWhat it catchesHow it works
Command-line and process YARAMalicious execution, including fileless activityYARA rules evaluate process and command-line content as it runs, which catches payloads that never settle on disk in a recognisable form.
FIM-hash file reputationKnown-bad files arriving or changingFile integrity monitoring produces a hash on change; the hash is checked against threat-intelligence sources and malware databases for a reputation verdict.
On-agent YARA scanningMalicious files resident on the endpointYARA runs on the agent against files where they sit. Nothing is uploaded anywhere to be examined, and hits feed the Malware Center with quarantine controls.

All three run on the agent. No file is transmitted off the endpoint to be analysed.

How it works

From a match to a contained host

A malware finding is an ordinary finding, which is what gives it the platform's response options rather than an antivirus product's.

  1. Detection on the endpoint

    All three paths run on the agent itself. On-agent evaluation is what makes this usable in an air-gapped deployment and what means suspect files never leave the host they were found on.

  2. A finding enters the normal pipeline

    A malware hit is a finding like any other: same 0–15 severity level, same band, same ATT&CK mapping, same queue. It is not routed to a separate antivirus console.

  3. The Malware Center collects the file-level view

    A dedicated console area holds YARA hits with quarantine controls attached, which is where file-level work happens once an analyst has decided a finding is real.

  4. Response options are the platform ones

    Quarantine the file, kill the process, isolate the host, block the address — the same tiered active-response engine, with the same approval gates and safelists.

  5. Correlation turns a hit into a picture

    A malware finding alongside persistence, credential access or mass file modification assembles into an incident. The file is the artefact; the sequence is the attack.

Terms

Including what the platform does not do

YARA

A rule language for describing and matching patterns in files and process memory. The standard tool for expressing "this family of malware looks like this" in a form a scanner can execute.

Fileless malware

Activity that executes without writing a recognisable payload to disk — frequently through a scripting host or a legitimate system binary. File scanning alone misses it, which is why command-line and process evaluation is a separate path here.

Malware Center

The console area where on-agent YARA hits land, with quarantine controls. It is the file-level working surface, distinct from the alert queue where the finding first appears.

What this is not

There is no detonation sandbox in the platform. Detection is YARA-based matching plus hash reputation, performed on the endpoint. That is a deliberate boundary and worth stating plainly rather than leaving implied.

Background

Understand the concept first

Plain explainers on the underlying ideas, written for someone evaluating rather than buying.

Questions

Common questions

Is this signature scanning?

Not only. There are three paths: YARA matching against process and command-line activity, file reputation on hashes through file integrity monitoring, and on-agent YARA scanning. The first catches execution that never writes a distinctive file.

Can we quarantine a file from the console?

Yes. On-agent YARA scanning reports into a Malware Center with quarantine controls.

Does it detonate suspicious files in a sandbox?

No. Detection is YARA matching, file reputation and on-agent scanning rather than sandbox detonation. Worth saying plainly, since sandboxing is commonly assumed to be part of any malware feature.

See Malware Detection running on your own infrastructure

We will walk through the console, the deployment model and what it takes to stand it up in your environment.