Antivirus-Artifacts catalogs API hooks observed in various commercial antivirus products. This project aims to provide a comprehensive resource for understanding how these AVs monitor and detect malicious activity. By documenting these API hooks, it enables researchers to analyze malware behavior and develop more effective detection strategies. The artifacts are curated from dynamic malware analysis efforts.
This project offers a centralized and organized collection of antivirus API hooks. It provides valuable granular detail on the specific APIs monitored by each vendor. The project's structured format simplifies analysis and comparison across different AV products, which is not commonly available elsewhere.
- Avira: List of APIs monitored by Avira for detecting malicious behavior, crucial for understanding Avira's detection mechanisms.
- BitDefender: Comprehensive list of BitDefender API hooks, facilitating analysis of their behavioral detection techniques.
- F-Secure: Documented F-Secure API hooks, enabling reverse engineering and understanding their malware detection methods.
- Malwarebytes: Detailed Malwarebytes API hooks, supporting analysis of their API-based malware detection.
- Norton: Catalog of Norton API hooks for understanding their real-time protection behavior.
- TrendMicro: List of TrendMicro AI-based API hooks aiding in understanding their behavioral analysis.
- WebRoot: Documentation of WebRoot API hooks, offering insights into their signature-based and heuristic detection approaches.
The project is actively maintained, with recent commits indicating ongoing updates and additions to the artifact list. The data is regularly updated based on current malware analysis. While no formal release cycle exists, the project demonstrates healthy activity and a commitment to accuracy, evidenced by consistent updates and issue addressing.
Security researchers and malware analysts benefit from Antivirus-Artifacts by gaining insights into how major antivirus vendors detect malware. It enables more effective malware analysis and the development of advanced detection solutions. This resource complements static and dynamic analysis techniques, enhancing overall malware understanding.
