this might be dumb, but why do we even use scanning in this day and age? Why not use kernel callbacks which notify when executables and files load for, say, the first time after being modified? Surely that'd be less race-y and waste less battery?
> Adload for a period of 8 seconds, once or so each day
They're scanning daily irrespective of signature updates, which makes no sense.
If you want to catch real zero-days, you have to approach things very differently. Do behavioral analytics, seeing what a process is up to and if it's poking into things it shouldn't.
Many leading AV suppliers like SentinelOne, Cylance, Crowdstrike do this and are very successful at it. However Apple is just starting in the antimalware market so I forgive them that they're just scanning for some known-bads for now.