← Field Notes · Industry
No Antivirus Catches Everything, and That's Worth Saying
The industry rarely advertises its own limits. It should, because understanding them is what makes the rest of a security strategy make sense.
Antivirus marketing has a genre convention, and the convention is the promise of completeness: total protection, all-in-one security, peace of mind. Independent testing labs that evaluate detection rates across large malware samples routinely publish numbers in the high nineties for major products, and those numbers are real, but they describe performance against samples the testing lab could collect, which by definition excludes malware novel enough that nobody has collected a sample of it yet.
This is not a criticism of any specific product. It is a structural fact about the category. Detection, whichever method it uses, signature matching, heuristics, behavioral analysis, machine-learning classification, is fundamentally reactive to some degree: it depends on having encountered, or having built a model that generalizes from, something resembling the threat in front of it. A sufficiently novel, sufficiently targeted piece of malware, custom-built for one victim and never reused, is a genuinely hard problem for the entire industry, not a solved one that only weaker products fail at.
Security researchers who study the field for a living talk about defense in depth for exactly this reason: no single control, including antivirus software, is expected to be sufficient on its own. Patching known vulnerabilities promptly, limiting what a compromised account or process can actually reach, backing up data in a way an attacker cannot also encrypt, and training people to recognize social engineering all sit alongside detection software as layers, each catching what the others miss, none of them claimed as complete.
The honest version of an antivirus product's pitch is narrower than the marketing genre usually allows: it catches what it is built to catch, reliably and without pretending otherwise, and it says plainly what it does not do. A hash-based scanner that only claims to catch exact matches to known-malicious files is making a smaller promise than a product that claims to stop all threats, and it is, for exactly that reason, a promise it can actually keep.
That smaller promise is not a weaker one in practice. Most real-world compromises, the ones that hit ordinary users and small organizations rather than nation-state targets, involve reused, commodity malware, not custom-built zero-days. A tool that is honest about only catching the known threats still catches the overwhelming majority of what people actually encounter. What it should not do, and what too much of the industry still does, is imply it catches the rest too.