Compare three fictional detection methods using synthetic browser-state fixtures. Nothing is uploaded, executed, read from your device, or retained.
Safe educational model
This is a deterministic fictional behavior model, not a scanner or sandbox. No files, filesystem APIs, uploads, external services, malware samples, hashes, rules, or executable content are used. Every result is harmless, local browser state and can be reset.
OFFLINE ANALYSIS CONSOLE
Detection evidence workstation
LOCAL · SYNTHETIC · REVERSIBLE
Clears all scan findings, decisions, and synthetic observations.
Historical context
Early antivirus tools relied heavily on databases of recognizable patterns. Over time, as malware became more varied, heuristic analysis helped estimate suspicious characteristics and behavioral or sandbox approaches added observed context. Modern defensive tools often combine layers rather than treating any one signal as a final answer.
KEY LESSON DETECTION IS EVIDENCE
SIGNATURE: “HAVE I SEEN THIS PATTERN BEFORE?” ↓ HEURISTIC: “DOES THIS LOOK SUSPICIOUS?” ↓ BEHAVIOR: “WHAT DOES THIS APPEAR TO DO?”