Join our Newsletter — 33% off our NHI Course
Home› Glossary› Cyber Security› Anti-Virus
Cyber Security

Anti-Virus

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Cyber Security

Anti-Virus is a first-generation endpoint security control that stops known malicious files from running. It usually scans files when they are downloaded, copied, or written to disk, then blocks execution if the file matches known signatures or suspicious code patterns.

What anti-virus software does

Anti-virus is an endpoint control built to stop known malicious code before it runs. It still matters as a basic layer of defense because it can block common malware families quickly, especially when signatures and reputation data are current.

Its value is highest against repeatable, well-characterised threats such as commodity malware, droppers, and file-based payloads. It is weaker when threats are packed, obfuscated, fileless, or delivered through trusted tools and scripting, where detection often depends on broader telemetry and behaviour analysis.

Modern anti-virus is often better understood as part of a wider endpoint protection stack than as a stand-alone product. That stack may combine local scanning, cloud lookups, script inspection, quarantine, and behavioural detection so that a single known file hash is not the only decision point.

How detection and blocking work

Traditional anti-virus compares files against known signatures, heuristics, and sometimes machine-learned indicators. When a file is downloaded, copied, opened, or written to disk, the engine decides whether to allow execution, quarantine the file, or alert the user or security team.

Because the control is usually file-centric, it is strongest where the malicious content is already packaged as a readable object on the endpoint. It is less reliable for malicious activity that never lands as a file, or that uses legitimate binaries to perform harmful actions after launch.

In practice, the control is only as good as its update cadence, policy tuning, and coverage of the operating system and applications it protects. Organisations that treat it as a guarantee of safety often miss the gap between “known malware blocked” and “host fully protected.”

Where anti-virus fits in endpoint security

Anti-virus is a foundational preventive control, but it should be positioned alongside application control, patching, least privilege, and monitoring. A stronger endpoint posture depends on reducing the opportunity for malicious code to execute, not just detecting it after arrival.

Its role is especially useful against mass threats and opportunistic infection, where fast automated blocking can interrupt initial compromise. For higher-end intrusion paths, MITRE ATT&CK Enterprise Matrix is often a better way to reason about post-compromise behaviour, because many adversary techniques bypass file-based detection entirely.

When teams define the control narrowly, they can place it correctly in the stack, as one layer in NIST Cybersecurity Framework 2.0 protecting endpoints rather than the whole security programme.

Common limitations and failure conditions

Anti-virus can fail when attackers use packing, encryption, polymorphism, living-off-the-land tools, or staged payloads that change faster than signatures are updated. It can also underperform when exclusions are too broad, scans are disabled for performance, or alert noise causes teams to ignore genuine detections.

The control also struggles when the endpoint itself is untrusted, for example after local privilege escalation or tampering with security services. In those cases, the malware problem becomes an integrity and control problem, not just a detection problem.

Because of those limits, anti-virus works best as one defensive checkpoint, not the final barrier. Policies around CIS Benchmarks help reduce the misconfiguration and exposure that make endpoint controls easier to bypass.

Risk and Threat Considerations

Anti-virus reduces commodity malware risk, but it also creates a false sense of coverage when organisations assume detection equals prevention. The biggest exposure is not that AV is useless, it is that defenders may stop building layered controls once the endpoint shows a green status.

Failure mechanism: Attackers evade file signatures with packing, script-based delivery, trusted process abuse, or rapid payload change, then use the resulting foothold to run code, steal data, or expand access.

Impact: A missed detection can lead to endpoint compromise, lateral movement, credential theft, and broader incident response effort, especially when the malware is only the first step in a larger intrusion.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack surface, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKEnterprise MatrixMaps endpoint malware and post-compromise techniques relevant to anti-virus bypasses.
Recommendation — Map endpoint evasion and follow-on attack paths to ATT&CK techniques and tune detections accordingly.
NIST CSF 2.0PR.PS-01 — Configuration ManagementAnti-virus is an endpoint protection measure that depends on secure configuration and maintenance.
Recommendation — Keep endpoint protection controls configured, updated, and monitored as part of protective operations.
CIS Controls v8CIS-10 — Malware DefensesDirectly addresses malware prevention, detection, and response on endpoints.
CIS-4 — Secure Configuration of Enterprise Assets and SoftwareEndpoint hardening reduces the conditions that allow malware to bypass or disable anti-virus.
Recommendation — Deploy and maintain malware defenses with current updates, scanning, and response handling. Harden endpoints and remove risky settings that weaken malware prevention controls.
NIST SP 800-53 Rev 5SI-3 — Malicious Code ProtectionDefines endpoint protection against malicious code, including detection and quarantine.
SI-4 — System MonitoringAnti-virus is strongest when paired with monitoring for evasion and compromise indicators.
Recommendation — Implement malicious code protection to detect, quarantine, and block known malware. Correlate endpoint detections with system monitoring to catch malware that evades signatures.
ISO/IEC 27001:2022A.8.7 — Protection against malwareAnnex A explicitly covers malware protection as a technological control area.
Recommendation — Maintain malware protection controls and keep them effective through updates and monitoring.

Practitioner Guidance

Why practitioners should care: Anti-virus is still worth keeping, but it should be measured by what it blocks and what it cannot see, not by whether it is installed. The practical question is whether the endpoint stack can stop known malware while also surfacing behaviour that signature-based scanning misses.

Common misunderstanding: Many teams treat anti-virus as synonymous with endpoint security. In reality, it is only one preventive control, and it needs complementary monitoring, hardening, and privilege reduction to remain effective.

Practitioner takeaway: Use anti-virus as a baseline filter for known malicious files, then rely on layered endpoint controls for everything that slips past signature matching.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org