You can't just scan for known bad fingerprints anymore -- most malware these days is polymorphic and has already gone through a virus checking service run by other blackhats (kind of like VirusTotal).
You can't just analyze the code in a virtual environment -- it's too easy for a malware author to determine if they're running in some sort of VM and then choose not to activate.
Moreover, most antivirus software is poorly written and is a bigger security risk than not having it at all. Many malware authors will specifically attack antivirus software, because that's the easiest way to get maximum permissions.
I do use anti-malware programs on my Mac. But it's all based on looking for system activity signatures that are typical of malware attacks. Classic antivirus software just isn't that useful.
Little Flocker is a good start, but has recently been sold to F-Secure, and I'm not sure if it will remain good.
BlockBlock is good. So is KnockKnock. And OverSight. And RansomWhere. All by the same author. Lots of these things are also covered by Little Flocker, if you prefer that option.
Little Snitch is great, but takes a bit of work at first to train it for what kind of behavior is okay on your system.
I still have ClamAV on my machine, but it is far from the first line of defense. It may catch the dreckage that is still out there and hasn't been updated with more modern obfuscation methods, but that could still be a net positive.
Of course, I also have FileVault turned on for volume encryption, and the Sierra network/application firewall enabled, and GateKeeper to ensure that all apps have good crypto signatures or they can't be installed or run.
And then there might be some other things that I won't talk about publicly. ;)
Don't listen to hearsay... you need protection.
- https://raw.githubusercontent.com/Homebrew/homebrew-core/mas...
- http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/security/clam...
It's unobtrusive, and I can fully control its behaviour (under usual circumstances a simple `freshclam && clamscan -i -r $PATH` is enough).
2017 will be even bigger. The more users you have - the more malware you get.
[0] https://www.macrumors.com/2017/04/06/mac-malware-up-744-perc...
For example suppose you have only "1" malware for your OS. Next year you have "2", a 100% growth rate.
Now suppose you have a shitty OS with 1000 malware. Next year it has 1200 malware, a 20% growth rate.
Someone without this knowledge would go about and claim the second OS is "safer", but the truth is both OS's are just experiencing an exponential growth rate, the first OS is just at the first stages of the curve.
Desktop-wise I've been on Linux for well over a decade, I've never used AV except to (rarely) clean out infected files I might share and infect others with, not necessarily for my own protection.
on linux i mostly feel content with SELinux
I'm a GNU/Linux user since 2000.