Atomdrift Scan is a command-line malware scanner that examines files, packages, archives and software dependencies using static analysis, detection rules, known hashes and machine-learning models. Its focus extends beyond individual executables to software supply chain threats where malicious behaviour may be introduced through packages or dependencies.
The scanner can examine single files, directory trees and nested archives. It also understands package URLs and can retrieve software packages for analysis, while remote URLs can be fetched and scanned directly. Supported input covers source code, executables, package metadata, archives, documents and other common file formats.
Its analysis pipeline extracts and unpacks content, identifies capabilities and behavioural characteristics, and converts the findings into a common feature representation. Detection rules, known-good and known-malicious hashes, AST analysis and LightGBM model ensembles are then used to assess the sample. Dependency relationships and discovered references can also be followed during analysis.
Atomdrift Scan provides JSON output for integration with scripts and automated workflows. Separate exit codes distinguish benign, suspicious and hostile results from analysis failures or incomplete rule sets. Detection sensitivity can be adjusted, rule updates can be controlled, and an optional LLM facility can provide additional interpretation of findings and assist with selected edge cases.
This is free and open source software.
Key Features
- Scans individual files and directories.
- Recursively examines archives and nested content.
- Scans software packages identified by package URLs.
- Fetches remote content for analysis.
- Combines static analysis, rules, hashes and machine-learning models.
- Analyzes source code, executables, packages and documents.
- Uses AST analysis for supported source formats.
- Performs automated binary analysis.
- Follows software dependencies and discovered references.
- Provides JSON output.
- Provides distinct exit codes for automation.
- Offers configurable detection sensitivity.
- Supports automatic rule updates.
- Provides optional LLM-assisted interpretation.
Website: github.com/atomdrift-project/scan
Support:
Developer: The Atomdrift Project
License: Apache License 2.0
Atomdrift Scan is written in Rust. Learn Rust with our recommended free books and free tutorials.
Related Software
| Anti-Malware Tools | |
|---|---|
| ClamAV | Antivirus engine for detecting trojans, viruses, malware and other threats |
| YARA-X | Re-incarnation of YARA |
| YARA | Pattern matching swiss knife for malware researchers |
| Maltrail | Malicious traffic detection system |
| ClamTk | Graphical frontend for ClamAV |
| LMD | Malware scanner focusing on threats faced in shared hosted environments |
| phpMussel | PHP-based anti-virus anti-trojan anti-malware solution |
| Raspirus | Lightweight signature-based malware scanner |
| FastFinder | Fast suspicious file finder |
| Rootkit Hunter | Scans for rootkits, backdoors and possible local exploits |
| Unhide | Forensic tool to find hidden processes and TCP/UDP ports |
| Hostsblock | Malware-blocking cronscript |
| libredefender | Antivirus program using libclamav |
| Lenspect | Lightweight security threat scanner |
| chkrootkit | Locally checks for signs of a rootkit |
Read our verdict in the software roundup.
Explore our carefully curated directory of recommended free and open source software, covering every major software category.The directory forms part of our extensive collection of articles for Linux enthusiasts. It includes hundreds of detailed reviews, together with free and open source alternatives to proprietary software from companies such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk. LinuxLinks also covers interesting projects worth exploring, Linux-compatible hardware, free programming books and tutorials, and much more. Know a useful free and open source Linux application that we haven’t covered? Tell us about it using our submission form. |


Please read our Comment Policy before commenting.