Antivirus software detects, blocks and removes malicious programs. Modern products no longer rely on signatures of known threats alone; they also watch how processes behave.
At a glance
Signatures catch the known; behavioural analysis also catches the unknown.
Out-of-date antivirus is worse than none – it fakes safety.
On an endpoint it is one layer among several, not a substitute for the rest.
Antivirus is the oldest protective layer on an endpoint – and today only one of several.
Signatures and behaviour
Signatures catch the known reliably and fast. Behavioural analysis catches the unknown, at the price of false positives. Only the two together add up to usable protection.
Real-world examples
- Behavioural analysis stops an unknown encryptor because it rewrites hundreds of files in seconds.
- A false positive blocks an internal tool – with no exception process, the department stops.
Common misconception
Myth “With antivirus I am safe.”
Reality Antivirus mostly catches the known. It does nothing against phishing, misconfiguration or stolen credentials.
Frequently asked questions
Is the operating system's built-in protection enough?
For many environments yes, provided it is centrally monitored – the hardening guidance is in the CIS Benchmarks.
Why do false positives happen?
Because behavioural analysis reacts to patterns, not certainty. The BSI IT-Grundschutz recommends a defined exception process for exactly that.