Am I detected?
Antivirus engines sometimes flag software that is perfectly legitimate. AID shows you which ones flag yours, what triggered them, and what to change so they stop.
For installers, executables and scripts you have built yourself.
From flagged to cleared in three steps
You do not need to read raw scan logs. AID translates each detection into a cause you can act on.
-
1
Submit your file
Upload a build or paste its hash. Nothing is installed on your machine.
-
2
See who flags it, and why
Each detection is listed with the engine that raised it and the behavior or trait that likely triggered it.
-
3
Fix it and re-check
Follow the suggested change, rebuild, and run the check again. Keep the history in your dashboard.
Why legitimate software gets flagged
Detection is often based on how a file looks and behaves, not on proof that it is malicious. These are the most common reasons for a false positive.
Unsigned or newly signed code
Engines trust established publishers. A new certificate or no signature at all starts you with low trust.
Packers and obfuscation
Compressed or scrambled binaries resemble how malware hides itself, even when you only wanted a smaller download.
Behavior that looks suspicious
Adding itself to startup, injecting into other processes, or downloading and running files can all trigger heuristics.
Low reputation
A file few people have downloaded has no track record, so cautious engines treat it as unknown and risky.
Questions
What is a false positive?
It is when an antivirus engine flags a safe file as malicious. It is common with new, unsigned or packed software.
Does AID remove the detection for me?
No. AID explains the cause so you can fix your build. If a detection remains after that, you can report it to the vendor as a false positive.
Do I need an account?
Registering lets you keep a history of checks in your dashboard and compare builds over time.
Is my file shared?
Check the privacy details before you submit a file, especially if your software is unreleased.
Engines and what each contributes
GET /v1/engines lists versions and availability| Engine | Contributes | Returns |
|---|---|---|
| clamav | Full ClamAV database, resident beside the app. | Signature name, database version. |
| yara | Your rulesets, for families, tooling and packer artefacts. | severity=high or a family tag counts malicious; the rest stays suspicious. |
| pe_heuristics | Entropy, imports, imphash, overlay, signing state. | Weighted structural indicators. |
| capa | Capability detection mapped to MITRE ATT&CK techniques. | Only high-signal namespaces grade suspicious. |
| oletools | VBA and XLM macros from Office containers. | Macros analysed, not skipped. |
| fuzzyhash | ssdeep and TLSH against your corpus. | Catches variants that break a hash lookup. |
| detectiteasy | Packer, compiler and protector ID. | UPX, VMProtect, Themida. |
A missing engine reports itself unavailable, and never counts as a vote for “clean”.
What a scan costs
Metered per scan, not per seat- Static analysis
- 1 credit per sample. New accounts start with free credits.
- Dynamic execution
- 2 credits: executed in a disposable guest, with the AV's behavioral verdict.
- API keys
- Own balance, so a build server never sees the account. Only the SHA-256 is stored.
- Credit ledger
- Every balance change writes a row. Any balance can be replayed.
Find out if your software is detected
Run a check, read the reasons, and ship a build that users can install without warnings.