AID multi-engine file analysis

Am I detected?

Antivirus engines sometimes flag software that is perfectly legitimate. AID shows you which ones flag yours, what triggered them, and what to change so they stop.

For installers, executables and scripts you have built yourself.

From flagged to cleared in three steps

You do not need to read raw scan logs. AID translates each detection into a cause you can act on.

  1. 1

    Submit your file

    Upload a build or paste its hash. Nothing is installed on your machine.

  2. 2

    See who flags it, and why

    Each detection is listed with the engine that raised it and the behavior or trait that likely triggered it.

  3. 3

    Fix it and re-check

    Follow the suggested change, rebuild, and run the check again. Keep the history in your dashboard.

Why legitimate software gets flagged

Detection is often based on how a file looks and behaves, not on proof that it is malicious. These are the most common reasons for a false positive.

Unsigned or newly signed code

Engines trust established publishers. A new certificate or no signature at all starts you with low trust.

Packers and obfuscation

Compressed or scrambled binaries resemble how malware hides itself, even when you only wanted a smaller download.

Behavior that looks suspicious

Adding itself to startup, injecting into other processes, or downloading and running files can all trigger heuristics.

Low reputation

A file few people have downloaded has no track record, so cautious engines treat it as unknown and risky.

Questions

What is a false positive?

It is when an antivirus engine flags a safe file as malicious. It is common with new, unsigned or packed software.

Does AID remove the detection for me?

No. AID explains the cause so you can fix your build. If a detection remains after that, you can report it to the vendor as a false positive.

Do I need an account?

Registering lets you keep a history of checks in your dashboard and compare builds over time.

Is my file shared?

Check the privacy details before you submit a file, especially if your software is unreleased.

Engines and what each contributes

GET /v1/engines lists versions and availability
EngineContributesReturns
clamav Full ClamAV database, resident beside the app. Signature name, database version.
yara Your rulesets, for families, tooling and packer artefacts. severity=high or a family tag counts malicious; the rest stays suspicious.
pe_heuristics Entropy, imports, imphash, overlay, signing state. Weighted structural indicators.
capa Capability detection mapped to MITRE ATT&CK techniques. Only high-signal namespaces grade suspicious.
oletools VBA and XLM macros from Office containers. Macros analysed, not skipped.
fuzzyhash ssdeep and TLSH against your corpus. Catches variants that break a hash lookup.
detectiteasy Packer, compiler and protector ID. UPX, VMProtect, Themida.

A missing engine reports itself unavailable, and never counts as a vote for “clean”.

What a scan costs

Metered per scan, not per seat
Static analysis
1 credit per sample. New accounts start with free credits.
Dynamic execution
2 credits: executed in a disposable guest, with the AV's behavioral verdict.
API keys
Own balance, so a build server never sees the account. Only the SHA-256 is stored.
Credit ledger
Every balance change writes a row. Any balance can be replayed.

Find out if your software is detected

Run a check, read the reasons, and ship a build that users can install without warnings.