Product & SEO Summary
Last updated: June 12, 2026
This page is the human-readable product summary (footer: Product summary). /llms.txt and /llms-full.txt are plain-text files: crawlers and AI tools download the file body (markdown in the HTTP response), not page metadata. Browsers show them as unstyled text on a white background — use this page for reading in a browser. We also publish HTML meta descriptions, JSON-LD on key pages, and sitemap.xml for search engines.
Windows desktop security software that detects unknown and AI-assisted malware using on-device ETW and behavioral ML. Local-first: behavioral data stays on your PC. A free website account gates installer download; core detection does not phone home for scoring.
Product
- Homepage — Overview and download
- How it works (Nerds) — ETW Layer 1a, behavioral Layer 1b, baseline, Respond workflow
- User Manual — Setup and usage
- Download — Windows installer (free account required)
- Accessibility — Accessibility statement and contact
Trust & legal
Developers
- Developers — AGPL source, build prerequisites, security disclosure
- Download — Windows installer (account required)
Extended summary
Same content as /llms-full.txt (plain text for automated tools only — not a second website).
AI Malware Guardian is a Windows 11 (x64) desktop application that detects novel and AI-assisted malware using local ETW telemetry, behavioral machine learning (Layer 1b), and structural ONNX models (Layer 1a). Detection runs on-device under AGPL-3.0. Optional signed app updates and authenticated installer download are the primary website touchpoints.
What it does
- Monitors process and system activity via ETW with a low-overhead background service.
- Learns a per-machine behavioral baseline during recording sessions you control.
- Scores live activity against baseline and structural models; Tier 4 alerts open a Respond guide (no automated quarantine in OSS).
- Complements signature-based antivirus (e.g. Windows Defender) for unknown threats.
Privacy posture
- No upload of file contents, ETW payloads, or behavioral feature vectors to the vendor cloud.
- Account session is used for website sign-in and installer download gating only.
Glossary
- ETW — Event Tracing for Windows, used for monitoring.
- Layer 1a — Structural ONNX model on process images.
- Layer 1b — Behavioral ML on ETW-derived features vs baseline.
- Baseline — Trusted recording windows for normal activity on this PC.
- Respond — Step-by-step guidance on Tier 4 alerts; hand off to Windows Security.
For AI/search crawlers only (plain text, unstyled in most browsers): /llms.txt (short index) and /llms-full.txt (extended). Prefer this page for reading in a browser.