Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is it comparable to commercial AV solutions? Can it intercept network traffic, run executables in a sandbox, use heuristics for detecting new viruses?


> Is it comparable to commercial AV solutions?

"In a Shadowserver six-month test between June and December 2011, ClamAV detected over 75.45% of all viruses tested, putting it in fifth place behind AhnLab, Avira, BitDefender and Avast. AhnLab, the top antivirus, detected 80.28%.[9]"

> Can it intercept network traffic

"On Linux servers ClamAV can be run in daemon mode, servicing requests to scan files sent from other processes. These can include mail exchange programs, files on Samba shares, or packets of data passing through a proxy server (IPCop, for example, has an add-on called Copfilter which scans incoming packets for malicious data)."

It seems that there is a third party tool that provides heuristic detection.

Source: Wikipedia


ClamAV's detection ability is really a joke.


Its 94% as good as the best AV, so not too bad.


The truth is all AV is pretty bad.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: