The historical name is narrower than current implementations, which may address viruses and other malware using signatures, reputation, heuristics, behavior analysis, or cloud-assisted verdicts. Capability varies by operating system, product, configuration, and deployment location.
Antivirus may be built into an operating system, deployed separately, or included in an endpoint protection platform. It can inspect files and may observe scripts, processes, memory, downloads, removable media, or other activity where the platform permits. The software needs timely maintenance.
Key points
OperationsDefine which assets require coverage, keep the engine and detection content current, monitor disabled or unhealthy protection, control exclusions, centralize important events, and test compatibility before changes.
Alert handlingPreserve the detection name, file or process context, affected identity and device, time, and related behavior; validate scope rather than assuming quarantine ended the intrusion.
Security and privacyAntivirus commonly has extensive device access and may submit suspicious files or metadata for remote analysis; evaluate privileges, update trust, data handling, jurisdiction, and availability impact.
Important limitationNo antivirus method detects all malware or malicious use of legitimate tools. A detection does not establish actor, scope, or impact, while a clean scan does not prove that an endpoint is uncompromised.