[clamav-users] Question regarding Metasploit signatures

G.W. Haywood clamav at jubileegroup.co.uk
Sat Aug 31 14:59:56 EDT 2019

Hi there,

On Sat, 31 Aug 2019, J.R. via clamav-users wrote:

> If the virus pattern is in one of the database files, then you are
> alerted... If it's not, then no alert... That's how every antivirus
> works...

There's a bit more to it than that.  Some detection is based on other
characteristics, such as behaviour.  But I think it's true to say that
the mainstay of detection by ClamAV is through the signature databases.
That's how I use it - there are a few excellent third-party databases.



