Guardiantus AV
Threat Lab

You are the analyst.

Files land in your queue. Allow the safe ones, quarantine the dangerous ones. After every call the engine shows exactly what it found and which layer found it.

0Score ×1Combo 0Caught File

How to play

  • Press A to allow, Q to quarantine
  • Enter moves to the next file
  • Three lives — each missed threat costs one
  • False positives cost points, not lives

Are these real?

The samples are short, inert snippets carrying the same indicators real threats carry. None of them can do anything to your machine.

Is the engine real?

Yes. This is a port of the actual detection layers, not a scripted demo. The desktop product adds archive scanning, native YARA, PE parsing and the full signature feed.

Why false positives matter. Catching every threat is easy if you block everything. The hard part is leaving safe files alone. Try launcher_log.txt or the Windows forwarder DLL: both look alarming by the numbers and neither raises an alarm. Where the engine cannot tell two things apart it says suspicious and leaves the file where it is — and anything it does move, it can move back.

Run it on your actual machine.

Same engine, plus real-time protection, quarantine and patch management.