← MALWARE HISTORY LABINTERACTIVE EXPERIENCE · AVAILABLE

MUSEUM ANTIVIRUS WORKSTATION

Virus Scanner Lab

SIGNATURES · HEURISTICS · BEHAVIOR

Compare three fictional detection methods using synthetic browser-state fixtures. Nothing is uploaded, executed, read from your device, or retained.

Safe educational model

This is a deterministic fictional behavior model, not a scanner or sandbox. No files, filesystem APIs, uploads, external services, malware samples, hashes, rules, or executable content are used. Every result is harmless, local browser state and can be reset.

OFFLINE ANALYSIS CONSOLE

Detection evidence workstation

LOCAL · SYNTHETIC · REVERSIBLE

Clears all scan findings, decisions, and synthetic observations.

Historical context

Early antivirus tools relied heavily on databases of recognizable patterns. Over time, as malware became more varied, heuristic analysis helped estimate suspicious characteristics and behavioral or sandbox approaches added observed context. Modern defensive tools often combine layers rather than treating any one signal as a final answer.

KEY LESSON DETECTION IS EVIDENCE
SIGNATURE: “HAVE I SEEN THIS PATTERN BEFORE?” ↓ HEURISTIC: “DOES THIS LOOK SUSPICIOUS?” ↓ BEHAVIOR: “WHAT DOES THIS APPEAR TO DO?”