Skip to content

Commit 7280dca

Browse files
authored
Merge branch 'main' into fix-diff-changed-behavior
2 parents 9574aa3 + 4a351ed commit 7280dca

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

README.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,16 @@ malcontent has 3 modes of operation:
3535

3636
malcontent is at its best analyzing programs that run on Linux. Still, it also performs admirably for programs designed for other UNIX platforms such as macOS and, to a lesser extent, Windows.
3737

38+
## ⚠️ Malware Disclaimer ⚠️
39+
40+
Due to how malcontent operates, other malware scanners can detect malcontent as malicious.
41+
42+
Programs that leverage Yara rules will often see other programs that also use Yara rules as malicious due to the strings looking for problematic behavior(s).
43+
44+
For example, Elastic's agent has historically detected malcontent because of this: https://github.com/chainguard-dev/malcontent/issues/78*.
45+
46+
> \*Additional scanner findings can be seen in [this](https://www.virustotal.com/gui/file/b6f90aa5b9e7f3a5729a82f3ea35f96439691e150e0558c577a8541d3a187ba4/detection) VirusTotal scan.
47+
3848
## Features
3949

4050
* 14,500+ [YARA](YARA) detection rules

0 commit comments

Comments
 (0)