EICAR test file write

eicar_file_write

Writes the standard 68-byte EICAR anti-malware test file into the sandbox and re-checks it for several seconds to catch asynchronous quarantine.

Severity low how bad it would be if it were real
Expected outcome Something should notice
Platforms 3 macOS, Linux, Windows
Isolation subprocess runs in its own process, so a kill is a measurement

What it needs before it will run

  • runs in --safe

    Observation only. It runs even in the inert mode, because it changes nothing and sends nothing.

Gates are cumulative and none of them is implied by another: see the three gates for why they are separate decisions.

ATT&CK techniques it exercises

MITRE ATT&CK techniques this test maps to.
Technique Name Tactic Across public reports
T1204.002 Malicious File Execution coverage statistics

How often anything notices

Not enough data: fewer than 3 public reports have run this test, so no rate is published for it. Groups below that threshold are withheld everywhere on the site — with one or two contributors an average is one organisation's result with a percent sign after it.

Other antivirus signatures tests

Other tests in the Antivirus signatures category.
Test What it does Severity
Macro-bearing document shapes macro_document_shapes Writes the document shapes phishing campaigns use — a macro-enabled OOXML package with a vbaProject part, an HTA script, a Windows script file and a s… medium
EICAR download over HTTPS eicar_download Fetches the EICAR test file from the official eicar.org endpoints (an AMTSO test resource) to observe whether the download path — proxy, TLS inspectio… low
EICAR variant battery eicar_variant_battery Writes six on-disk shapes of the EICAR test file (plain, double extension, padded, prefixed, zipped, nested zip) to compare how deeply the scanner ins… low

Catalogue generated from client 0.1.0. A test's behaviour can change between releases; this page describes the version named here.