Zero-day malware detection that runs anywhere, reads anything.
VirusTotal and Socket answer one question: has anyone reported this yet? Atomdrift reads the artifact and decides at scan time, on your hardware. No list to be on, no window to sit in, no code leaving your machine. Measured every day against live malware under 48 hours old.
Apache-2.0 · Linux, macOS, Windows, BSD, illumos · no telemetry · what's different ↓
2026-09-05 · 50 live samples, median 14 h old.
Caught, per engine identical cohort · a skip counts as a miss
Every engine is scored at its most sensitive setting, ours included. Grey is scope: the engine only reads registry packages, so the rest of the cohort counts as missed. Red is failure: the engine reads the format but timed out or crashed, which also counts as missed.
Detection vs. false positives every rival ships one setting — -l is a dial you set
Detection and false-positive chart data
- VirusTotal: 74% caught (37 of 50), 0 false positives of 50.
- Atomdrift: 68% caught (34 of 50), 0 false positives of 50.
- malcontent: 58% caught (29 of 50), 5 false positives of 50.
- ClamAV: 32% caught (16 of 50), 0 false positives of 50.
- Aikido Malware: 6% caught (3 of 50), 0 false positives of 50.
- GuardDog: 2% caught (1 of 50), 0 false positives of 50.
- SafeDep: 0% caught (0 of 50), 0 false positives of 50.
- Socket: 0% caught (0 of 50), 0 false positives of 50.
False-positive axis inverted and cropped at 10%. Hover any mark for exact counts.
Every previous run last 30 days · a fresh cohort each time
Most engines swing sixty points as the samples change. Judge us on the worst night, not the best.
False-positive rate by filetype last 7 days · top 10
File types that most often trigger a false alarm on known-good packages. Both sides list the same types in the same order, ranked by how often either engine flagged them.
atomscan
VirusTotal
500 known-good picks across the window (after adjudication). A type can show 0% on one side when only the other engine flagged it.
What's different architecture, not features
-l is benign files flagged per 100 million, calibrated per
file type. Every verdict lists the capabilities that drove it, so a false positive is a bug you can read and
fix.Keep VirusTotal for what it is good at: consensus on malware the world already knows. Atomdrift covers the rest — the package published this morning, the binary no registry indexes, the code you cannot send to anyone.
Where each engine lost this run's samples: files it could not read, and packages it indexes but had no entry for when we asked. 37 of 50 samples weren't registry packages at all — binaries, executables, archives. That is the shape of firmware, images, and your own code.
| Engine | Couldn't read | Could look up | No record yet | Caught |
|---|---|---|---|---|
| SafeDep | 46 | 4 | 4 | 0 |
| Aikido Malware | 46 | 4 | 1 | 3 |
| GuardDog | 46 | 4 | — | 1 |
| Socket | 37 | 13 | 13 | 0 |
“No record yet” is the detection gap, measured: a live malicious package the vendor indexes and had no entry for at the moment we asked. VirusTotal, Atomdrift, malcontent, ClamAV read every sample. How it decides →
Who it's built for tuned for software written by strangers
Open-source marketplaces
Registries, app stores, extension galleries, model hubs: anything that hosts code other people wrote. Scan at publish time, before the first download, on infrastructure you run. One engine across 47 package ecosystems, and a false-positive budget you can defend to maintainers.
Security vendors
Add zero-day coverage to a SAST, SCA, firmware, container or EDR product without building a malware team. Embed the CLI, the HTTP service or the Rust libraries; every verdict comes with the evidence behind it. OEM rights and support from the engineers who build it.
Anyone with a machine
Something on the box looks wrong. Point it at a file, a directory, an archive, a running process or the whole host. More file types, more languages and more operating systems than any other scanner, open or commercial. Nothing leaves the machine.
Prefer a hosted API? Our sponsor, isotope¹³, has you covered.
Appendix — samples and methodology all 50, every one linked
How this is scored. Every engine gets the identical cohort, and a skip counts as a miss for all of them — a file nobody scanned is a file that got through. A listing from a contestant's own feed counts only once an independent engine corroborates it. Known-good packages come from the freshest 48 hours of the open-source firehose and are re-checked later: one that turns out to be malware leaves that run's false-positive rates, and any engine that flagged it is credited with an early detection. We run this benchmark and we're one of the engines in it, so every sample, verdict and rate is published.
Engine versions: Atomdrift 2.8.0 · ClamAV 1.5.2 · GuardDog 3.2.0 · malcontent 1.25.9 (locally-run engines; VirusTotal, Socket, Aikido Malware, SafeDep are hosted services queried live, so they carry no pinned version).
Point it at anything.
Apache-2.0 · runs locally · no account, no index, no gap