Skip to main content
AI Malware Guardian
Features How It Works Download
Download Sign In

Product & SEO Summary

Last updated: June 12, 2026

This page is the human-readable product summary (footer: Product summary). /llms.txt and /llms-full.txt are plain-text files: crawlers and AI tools download the file body (markdown in the HTTP response), not page metadata. Browsers show them as unstyled text on a white background — use this page for reading in a browser. We also publish HTML meta descriptions, JSON-LD on key pages, and sitemap.xml for search engines.

Windows desktop security software that detects unknown and AI-assisted malware using on-device ETW and behavioral ML. Local-first: behavioral data stays on your PC. A free website account gates installer download; core detection does not phone home for scoring.

Product

  • Homepage — Overview and download
  • How it works (Nerds) — ETW Layer 1a, behavioral Layer 1b, baseline, Respond workflow
  • User Manual — Setup and usage
  • Download — Windows installer (free account required)
  • Accessibility — Accessibility statement and contact

Trust & legal

  • Legal hub — Privacy, terms, and policies
  • Support — Contact and help

Developers

  • Developers — AGPL source, build prerequisites, security disclosure
  • Download — Windows installer (account required)

Extended summary

Same content as /llms-full.txt (plain text for automated tools only — not a second website).

AI Malware Guardian is a Windows 11 (x64) desktop application that detects novel and AI-assisted malware using local ETW telemetry, behavioral machine learning (Layer 1b), and structural ONNX models (Layer 1a). Detection runs on-device under AGPL-3.0. Optional signed app updates and authenticated installer download are the primary website touchpoints.

What it does

  • Monitors process and system activity via ETW with a low-overhead background service.
  • Learns a per-machine behavioral baseline during recording sessions you control.
  • Scores live activity against baseline and structural models; Tier 4 alerts open a Respond guide (no automated quarantine in OSS).
  • Complements signature-based antivirus (e.g. Windows Defender) for unknown threats.

Privacy posture

  • No upload of file contents, ETW payloads, or behavioral feature vectors to the vendor cloud.
  • Account session is used for website sign-in and installer download gating only.

Glossary

  • ETW — Event Tracing for Windows, used for monitoring.
  • Layer 1a — Structural ONNX model on process images.
  • Layer 1b — Behavioral ML on ETW-derived features vs baseline.
  • Baseline — Trusted recording windows for normal activity on this PC.
  • Respond — Step-by-step guidance on Tier 4 alerts; hand off to Windows Security.

For AI/search crawlers only (plain text, unstyled in most browsers): /llms.txt (short index) and /llms-full.txt (extended). Prefer this page for reading in a browser.