A malware scanner has a risk that most software doesn't: it deliberately opens files that may contain attacker-written code. If a scanner tries to "unpack" obfuscated malware by running it, the scanner itself becomes a way to run attacker code on your server.
PowerSEC's design rule
The PowerSEC malware scanner analyses files using static pattern matching only. It:
- Reads file contents and matches them against fixed signatures with bounded regular expressions.
- Never calls
eval(),create_function(),assert(),call_user_func(), or dynamic includes on anything it reads. - Never "deobfuscates by running" — it detects obfuscation (e.g.
eval(base64_decode(...))) as a pattern, without ever executing it.
Because the scanner does not execute the code it inspects, a scanned file is treated only as text and is never run by the scanner. This rule is part of the scanner's design and is checked by our test suite.