Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Every Windows endpoint ships with antivirus, and businesses still buy more of it. Brand matters far less than two other things: what the scanner covers, and what walks straight past it. This guide breaks down how antivirus software finds malware, what separates a business product from the consumer one, and where detection and response has to take over.

TL;DR

  • Antivirus software. Software that finds and blocks known malicious files on an endpoint, using signatures, code analysis, behavior rules and cloud lookups.
  • Business vs consumer. Same engine, different plumbing: central policy, reporting and per-seat licensing.
  • The limit. CrowdStrike counted 82% of 2025 detections as malware-free, so there's often no file to scan.
  • The call. Keep antivirus as the file-blocking floor. Add detection and response for anything that logs in rather than infects.

What Antivirus Software Does

Antivirus software watches the files arriving on a machine and stops the ones it recognizes as malicious. It's a filter with a memory. Something lands on disk, gets written, gets opened or gets executed, and the scanner checks it before the operating system hands over control.

Three jobs sit inside that one description. Real-time protection inspects files as they appear, which is the part doing most of the work. Scheduled scanning sweeps the disk for anything that slipped in while the agent was off or out of date. Remediation quarantines or deletes what it finds and tries to undo the changes.

The name has drifted from the job. "Antivirus" dates from when viruses were the threat and antimalware became the more accurate label, covering trojans, worms, ransomware droppers, cryptominers, adware and info-stealers. Vendors now use the terms interchangeably. Treat antivirus and antimalware as the same category and read the feature list instead of the label.

What antivirus is good at is volume. Commodity malware still arrives constantly through email attachments, fake installers and USB keys, and a scanner kills it silently thousands of times before anyone files a ticket. That's unglamorous and worth paying for. The trouble starts when the attack doesn't involve a file at all.

The Four Ways Antivirus Finds Malware

Detection isn't one technique. Modern engines stack four, and knowing which one caught something tells you how much confidence to put in the alert.

Signature matching compares a file's hash or byte patterns against a database of known-bad samples. It's fast, cheap and close to zero false positives, because a match means this exact thing has been seen and classified before. It also means the sample had to be caught somewhere first. Change one byte and the hash changes, which is why polymorphic malware rewrites itself on every delivery.

Static heuristics read the file without running it. The engine looks at structure instead of identity: packed or obfuscated code, imports that a normal document has no business calling, a macro that reaches for PowerShell. No prior sample needed, so it catches new variants of old families. The cost is false positives, which is why a badly tuned engine quarantines a legitimate installer.

Behavioral monitoring watches what a process does once it's running. Mass file encryption, shadow copy deletion, credential store access, a Word process spawning a shell. This is the layer that stops something the first two missed, and it's the layer that overlaps with EDR. Detection here happens after execution starts, so the question becomes how fast the response fires.

Cloud lookups and sandboxing send a hash or the file itself to the vendor's backend. A reputation query returns a rating in milliseconds based on what the vendor has seen across its whole install base. Full sandbox detonation runs the sample in an isolated VM and reports what it did. Both move the heavy analysis off the endpoint, and both need connectivity, so a laptop offline on a plane falls back to local signatures.

Vendors call the combination next-generation antivirus. The label mostly signals that machine learning classifiers and behavioral rules carry more weight than the signature file. Useful, and still scoped to things that run on the endpoint.

Worth knowing which layer fired when an alert lands. A signature hit is a settled fact and you can close it. A heuristic or machine learning hit is a probability, so it deserves a look before someone adds a permanent exclusion to make the noise stop. A behavioral hit means the thing was already running, which changes the question from whether to block it to what it touched first.

Business Antivirus vs Consumer Antivirus

The detection engine is usually identical. A vendor doesn't maintain two malware databases. What you pay extra for is everything around the engine.

Central management is the real dividing line. A business product reports every endpoint into one console, pushes policy from that console, and tells you which machines are unprotected, out of date or excluded from scanning. Consumer antivirus reports to the person sitting at the keyboard. At ten endpoints that difference is an inconvenience. At two hundred it's the whole product, because nobody can confirm coverage by walking the floor.

Microsoft makes the split unusually clear. Defender Antivirus ships in Windows and does the scanning. Without Intune or Business Premium behind it there's no central management, no fleet reporting and no policy enforcement, which is exactly the thing that turns a scanner into something an IT team can run. Defender for Business adds the console and the response tooling for organizations with up to 300 users.

A new business owner on r/sysadmin asked the same question in October 2025: Windows already ships Defender, so why pay for Defender for Business? The replies land on the console and reporting.

Consumer antivirusBusiness antivirus
ManagementLocal, per deviceCentral console, policy push
ReportingOn-screen alertsFleet-wide, exportable, auditable
LicensingPer household, 1-5 devicesPer seat or per endpoint, contract term
Server supportNoneWindows Server, often Linux and hypervisors
ExclusionsUser-setPolicy-controlled, logged
SupportForum and chatNamed contacts, response targets
EULAPersonal use onlyCommercial use permitted

That last row catches people. Free consumer antivirus licenses usually prohibit business use, so a fleet running them is out of compliance regardless of how well the scanning works. Auditors ask.

Server coverage is the other line that gets crossed by accident. A file server, a domain controller and a hypervisor host each need different exclusion sets, and a workstation product pointed at them either refuses to install or scans database files it should leave alone. That's where the performance complaints come from, and it's why server licensing is priced separately rather than as an upsell.

What Antivirus Misses in 2026

The numbers have moved decisively, and they all point the same direction. Attackers stopped shipping files.

CrowdStrike's 2026 Global Threat Report counted 82% of 2025 detections as malware-free. The intruder signs in with credentials bought or phished, then works with tools already on the box: PowerShell, WMI, certutil, the RMM agent, the remote desktop client. There's no malicious binary for a scanner to match, because nothing malicious was installed.

Speed compounds it. CrowdStrike measured average breakout time, the gap between landing on one machine and moving to a second, at about 29 minutes in 2025, with the fastest at 27 seconds. Mandiant's M-Trends 2026 found that initial access brokers now hand a fresh foothold to the next group in 22 seconds. In 2022 that hand-off took more than eight hours.

Then the dwell time. Mandiant's global median rose to 14 days from 11, and some intruders now persist in edge devices that carry no standard endpoint telemetry. A firewall or VPN appliance doesn't run an antivirus agent. Nothing is scanning it.

Coverage gaps inside the fleet work the same way. Antivirus protects what the agent is installed on, which in practice means the Windows laptops and desktops somebody remembered to enroll. Network appliances, printers, hypervisors, IoT and the unmanaged contractor machine on the guest network are all outside that boundary. So is a virtual machine spun up last Thursday and never added to the console. The report says 100% compliant because it only counts what it knows about.

Put those together and the shape of the problem is clear. The file-blocking layer is doing fine at what it does. The activity that follows a stolen password generates no file events at all, and the window to notice is measured in minutes.

Detection rates aren't where the difference lies either. AV-Comparatives tested 16 enterprise and SMB products on Windows 11 in its H1 2026 Business Security Test, covering Bitdefender, Cisco, CrowdStrike, Elastic, ESET, Kaspersky, ManageEngine, Microsoft, Sophos, Trellix and others. In the malware protection part of the test, one product, Elastic Security, blocked 100% of samples with zero false alarms on common business software. The rest clustered close behind. When the field is that tight on file detection, the thing worth comparing is what happens after something gets through.

Antivirus vs EDR vs MDR

Three tiers, and the boundaries blur because vendors sell across all of them. What separates them is telemetry, retention and who's watching. For the tier above EDR, see our EDR vs XDR guide.

Antivirus / NGAVEDRMDR
Question answeredIs this file bad?What happened on this endpoint?Someone tell me what happened
TriggerFile written or executedProcess, network, registry, identity eventsSame as EDR
RetentionAlerts and quarantine logWeeks to months of raw telemetrySame, held by provider
ResponseQuarantine, delete, blockIsolate host, kill process, roll back, huntProvider acts on your behalf
Catches malware-free intrusionRarelyYes, if tuned and watchedYes
Needs an analystNoYesProvided
Runs itself overnightYesOnly the automated rulesYes, staffed

The practical relationship: EDR products include a next-generation antivirus engine, so deploying EDR generally replaces the standalone scanner rather than sitting beside it. Running two file-scanning engines on one endpoint causes conflicts and performance complaints, and one of them usually ends up disabled.

Pro Tech Show walks through where EDR, MDR and XDR differ, and why the tooling alone isn't the whole answer.

MDR exists because EDR generates alerts that need a human at 3am. An unwatched EDR console is an expensive log file. If nobody is rostered overnight, buy the watching with the tooling. Our breakdown of a working MSP security stack covers how those layers fit together with identity, email and backup.

Check the cyber insurance renewal too. If the questionnaire asks whether EDR runs on every endpoint and server, a partial deployment won't pass, and that settles the question.

The r/msp thread below asks whether Windows Defender is "good now". The top replies draw the line this section draws: the built-in antivirus and Microsoft's EDR are different products, and either one only works as well as it's configured.

When Antivirus Alone Is Enough

There are real cases, and pretending otherwise just sells things nobody needs.

Antivirus on its own holds up when the blast radius is small and the basics are done. That means multi-factor authentication on every account including remote access, no standing local administrator rights, patching that completes rather than merely runs, tested offline backups, and no regulated data on the endpoints. A small architecture practice with eight laptops, everything in a managed cloud tenant, no client financial or health records, and a day of downtime that costs a day of work: strong antivirus plus tight identity hygiene is a defensible position.

The calculation flips on any of these. Regulated or sensitive data, anything covered by HIPAA, PCI DSS or a client contract with security schedules. Downtime that costs real money per hour. Inconsistent patching or MFA, because those are what make a stolen credential useful. A cyber insurance policy, since the questionnaire decides for you. Servers, domain controllers or hypervisors, which is where an intruder goes second. And an environment nobody watches after 6pm.

There's a middle position that gets skipped. Antivirus plus centrally managed identity, conditional access and application control covers a surprising amount of the malware-free case, because it attacks the login rather than the payload. That stack won't tell you what a process did after it started, so it isn't detection and response, but it's a real step up from a scanner alone and it's usually already paid for inside an existing Microsoft 365 tenant. Turning on what you own beats buying a tier nobody will watch.

Notice that none of those triggers are about headcount. A 12-person medical billing operation needs detection and response more than a 200-person warehouse running kiosks. Size is a poor proxy for exposure, which is why "you're too small for EDR" is bad advice in either direction.

What to Check Before You Buy

Detection rate is table stakes now. These are the things that separate products once the independent lab scores come back near-identical.

Read the console first, not the feature list. Ask whether it shows you unprotected endpoints without building a report, because that single view is what stops a machine sitting agentless for four months. Check what happens to a laptop that's offline for two weeks and whether it reports on reconnection or silently drops out of inventory. Confirm server and hypervisor licensing separately, since workstation pricing rarely covers them and the surprise arrives at renewal.

Then the operational details. Find out how exclusions are set and whether they're logged, because exclusions are how antivirus gets quietly neutered and they're the first thing an auditor pulls. Ask about false positive handling and how fast a mistaken quarantine gets reversed across a fleet, not on one machine. Get the actual contract term and the mid-term seat reduction policy in writing, since per-seat licensing that only ratchets upward is how a shrinking client becomes an unprofitable one.

Finally, the integration question. Whatever runs your fleet needs to deploy the agent, verify it and alert on its absence. If the antivirus console and the RMM don't talk to each other, somebody reconciles two lists by hand every month and eventually stops. OpenFrame, the open, AI-native infrastructure layer for IT and security we build at Flamingo, can run a Defender status check as a script across a client's devices and collect the output. Which detection engine you run stays a separate decision.

Where Antivirus Fits Now

Antivirus earned its place and keeps it. It's the cheapest control in the stack per threat blocked, it works without supervision, and it handles the commodity flood that would otherwise fill the queue. Keep it, license it commercially, manage it centrally, and confirm coverage from a console rather than from memory.

Just size it correctly. It answers one question, about files, and 82% of detections last year involved no malware at all. Everything an attacker does with a working password happens somewhere antivirus isn't looking, and the gap between landing and spreading is now under half an hour. Decide deliberately whether you're covering that, and if the answer is a renewal questionnaire you haven't filled in yet, start there. For the layer above this one, read our guide to endpoint security.

Vladislav Marchenko

Head Of Marketing

Hi all! My name is Vlad and I’ve been brought on to head the marketing team at Flamingo. Thankfully, this isn’t the first time I will be building a marketing department from scratch, so the experience should come in handy. Now it’s time to dive into the world of MSPs and find myself in this new world.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Antivirus Software

Nothing meaningful today. Antivirus is the older name from when viruses dominated; antimalware describes the same scanning against trojans, worms, ransomware droppers and info-stealers. Vendors use both labels interchangeably, so compare the feature list and detection layers rather than the product name.
The engine scores well in independent testing, but Defender Antivirus alone gives you no central console, no fleet reporting and no policy enforcement without Intune or Business Premium. For a managed fleet, that management layer is the part worth paying for.
Usually not legally. Free consumer editions are licensed for personal use only, so a company fleet running them breaches the agreement regardless of how well detection performs. Auditors and insurers check licensing, and commercial editions also add the central management free tiers omit.
It stops known ransomware files and often catches mass encryption through behavioral rules. It rarely stops the intrusion that precedes them, since attackers now arrive with stolen credentials and move using built-in Windows tools, leaving no file for the scanner to inspect.
No. EDR products generally ship with a next-generation antivirus engine built in, so EDR replaces the standalone scanner rather than running beside it. Two file-scanning engines on one endpoint cause conflicts and slowdowns, and one usually ends up switched off.
Business endpoint pricing is typically quoted per seat or per endpoint on an annual term, with servers licensed separately. Microsoft Defender for Business lists at 3 dollars per user per month, billed annually, as listed in September 2026. Get seat-reduction terms in writing.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.