Catches malware before anyone has reported it. Zero-day detection that runs anywhere, reads anything.
Most engines answer one question: has anyone reported this as malware? Atomdrift reads the artifact and decides at scan time, on your hardware. No list to wait for, no window to sit in, no code leaving your machine. Measured every day against live malware under 48 hours old.
Apache-2.0 · Linux, macOS, Windows, BSD, illumos · no telemetry · what's different ↓
2026-09-26 · 50 live samples, median 12 h old, and 50 known-good.
Caught, per engine identical cohort · most sensitive setting for everyone
What's different architecture, not features
-l is a false-positive budget — benign files flagged per
100 million, calibrated per file type — not “medium sensitivity.”Against Socket, Aikido and other reputation services. A registry lookup. 31 of this run's 50 samples weren't registry packages; of the 19 Socket could look up, it had a record for 1. Atomdrift reads the artifact, so this morning's package, a firmware image or your own code gets the same verdict.
Against VirusTotal. Dozens of engines voting on malware the world already knows is a bar we won't clear, and we don't try. On zero-day samples, latency, privacy and convenience we aim to beat it every run, and the chart above is where you check. How it decides →
Detection vs. false positives this run · hover a mark for counts
Detection and false-positive chart data
- VirusTotal: 62% caught (31 of 50), 0 false positives of 50.
- Atomdrift: 86% caught (43 of 50), 0 false positives of 50.
- ClamAV: 28% caught (14 of 50), 0 false positives of 50.
- Aikido Malware: 12% caught (6 of 50), 0 false positives of 50.
- GuardDog: 10% caught (5 of 50), 1 false positive of 50.
- Socket: 2% caught (1 of 50), 0 false positives of 50.
- SafeDep: 0% caught (0 of 50), 0 false positives of 50.
- malcontent: 44% caught, 7 false positives of 50.
Every previous run last 30 days · a fresh cohort each time
Three things move these lines: a fresh cohort each run, engine updates and changes to our own rules. Most engines swing 60 points over 30 days. Judge us on the worst night, not the best.
False positives last 7 days
5 of 639 known-good artifacts flagged, each linked to its report.
| File type | Flagged |
|---|---|
| macho | language_server |
| ooxml | FkSA3WUIlyfC |
| python_sdist | pychrome-0.0.1.tar.gz |
| vsix | moonbit.moonbit-lang-0.7.2026080402.vsix, tooltitudeteam.tooltitude-1.53.8.vsix |
Who it's built for tuned for software written by strangers
Open-source marketplaces
A malicious package goes live and your name is on the download page. Scan at publish time, before the first download, on infrastructure you run: one engine across 47 package ecosystems, and a false-positive budget you can defend to maintainers.
Security vendors
Zero-day coverage in your product without hiring a malware team. Embed the CLI, the HTTP service or the Rust libraries in a SAST, SCA, firmware, container or EDR product; every verdict ships with its evidence. OEM rights and support from the engineers who build it.
Anyone with a machine
Something on the box looks wrong. Point it at a file, a directory, an archive, a running process or the whole host. Nothing leaves the machine.
Want the rules the hour they clear QA, an API, and someone on the hook? That's isotope13.io.
Appendix — samples and methodology all 50, every one linked
How this is scored. Every engine gets the identical cohort at its most sensitive setting, and a skip counts as a miss for everyone — a file nobody scanned is a file that got through. A listing from a contestant's own feed counts only once an independent engine corroborates it. Known-good packages come from the freshest 48 hours of the open-source firehose and are re-checked later: one that turns out to be malware is dropped from that run's false-positive rates, and any engine that flagged it is credited with an early detection. We run this benchmark and we're one of the engines in it, so we publish every sample, verdict and rate.
Engine versions: Atomdrift 2.12.0-beta.2 · ClamAV 1.5.2 · GuardDog 3.2.0 · malcontent 1.26.0 (locally run engines; VirusTotal, Socket, Aikido Malware, SafeDep are hosted services queried live, so they carry no pinned version).
Point it at anything.
Apache-2.0 · runs locally · no account, no index, no gap