Detection Layers
Last updated
The freeMalwareDetection SDK utilizes a Defense-in-Depth architecture. Because no single scanning methodology can identify every type of threat without generating excessive false positives, the device environment is evaluated across multiple distinct analytical layers. This section documents the specific mechanisms the engine uses to evaluate installed applications.
The detection pipeline operates through two consecutive stages, scaling from fast, deterministic checks to complex, behavioral intelligence:
Looking for an additional layer? Premium Malware Detection extends this pipeline with real-time cloud verification against a continuously updated global threat database.
The following sections detail the exact evaluation logic, the required configuration, and the resulting incident flags. Review each layer to understand how to construct a comprehensive threat model for your application:
Last updated

