AgileBase

Antivirus and device security, term by term

AgileBase is a reference to the vocabulary consumer security software is sold in, written for readers in Australia. Look up a word, see what it actually commits a vendor to, and find the question worth asking next.

AgileBase carries paid links. One product covered here, TotalAV, is an advertiser: if you follow a link from this site to the TotalAV website and go on to buy a subscription, the publisher of AgileBase is paid a commission by the advertising network that manages the arrangement. You pay the vendor's own price either way — the commission comes out of the vendor's marketing budget, not out of your purchase.

That payment buys placement, not conclusions. It does not change how a term is defined on this site, and the definitions were written to be usable by someone who buys nothing at all. The affiliate disclosure page sets out the arrangement in full, including what it does and does not decide.

What a reference like this is for

Consumer security software is sold in a vocabulary that the buyer is assumed to already understand. A product page promises real-time protection, heuristic detection, a firewall, a password vault and coverage for five devices, and expects the reader to work out which of those matter to them, which overlap with what their computer already does, and which are simply names for the same mechanism described twice.

AgileBase takes the vocabulary one word at a time. Each entry says what the term means, what it does not mean, and what question it should prompt you to ask before you pay for anything. The entries are cross-linked, because the terms are: you cannot understand a false positive without understanding a signature, and you cannot judge a device licence without knowing how the vendor counts a device.

This is a reference, not a testing laboratory. AgileBase runs no malware samples, scores no products and publishes no detection rates; where a number is needed, the page points to the organisation that publishes it.

Ten words that decide most antivirus purchases

These are the terms that most often separate what a buyer thinks they are getting from what they have actually bought. Each links to its full entry in the glossary.

Real-time protection
Scanning that happens as files are opened, written or downloaded, rather than only during a scan you start. The useful question is what it inspects and what it leaves alone.
Signature
A pattern that identifies a known piece of malicious software. Signature matching is exact and cheap, which is why it is fast, and why it is blind to anything written after the last update.
Heuristic analysis
Judging a file by its structure and instructions rather than by a known pattern. It catches variants no signature covers, and causes most false positives.
False positive
A clean file flagged as malicious. The cost is rarely the alert; it is the quarantined file that some other program needed.
Device licence
The unit a subscription is sold in. Vendors differ on whether a phone counts as a device and on whether a licence moves between machines.
Auto-renewal
The default on most security subscriptions. The renewal price and the introductory price are separate numbers, and the gap between them causes most complaints in this category.
Potentially unwanted program
Software that is not malicious but that few people would knowingly install — toolbars, bundled utilities, aggressive adware. Default handling varies by product.
Zero-day
A weakness being exploited before a fix exists. It describes the timing of a flaw, not a product feature, though marketing copy often uses it as one.
Quarantine
A holding area for files the product has judged unsafe. Knowing how to look inside it and restore from it matters more than buyers expect.
VPN
A tunnel that hides your traffic from the network you are using and your address from the site you visit. Bundled with many suites; it answers a different question from detection.

A worked example: reading a vendor's feature list

Take a typical line from a product page: real-time protection with cloud-based threat detection across all your devices. Three separate claims are packed into eleven words, and each of them has a question attached.

  1. Real-time protection tells you the scanning is continuous. It does not tell you which file types are inspected, whether archives are opened, or whether scripts running in memory are covered. Those are separate capabilities.
  2. Cloud-based threat detection means an unknown file's fingerprint is checked against the vendor's servers. Reaction times improve, the product depends more on a connection, and data about what you run leaves your machine — a privacy question the vendor's own policy should answer.
  3. All your devices means all the devices your licence covers. The number, the platforms and the counting rule are in the subscription terms, not the headline.

None of this makes the sentence dishonest. It makes it compressed. Expand each phrase back into the question it answers, then check the vendor's documentation for the part it left out.

TotalAV is the product AgileBase covers in this way, and it is an advertiser here. Its own site is the authoritative source for what its subscriptions currently include, which platforms are supported and what the renewal terms are — figures that change, and that this site therefore does not restate.

Visit the TotalAV website

Paid link. AgileBase receives a commission if a subscription is purchased after you follow it. The price you pay is set by the vendor and is the same either way.

What this site covers, and what it leaves out

The glossary is general: it explains the category, and the definitions apply to any product in it. The product coverage is narrow, and deliberately so. AgileBase writes about TotalAV because the publisher has a commercial relationship with it, and it says so on every page where that product appears. There is no second product being quietly ranked below it, and no comparison table in which the advertiser happens to come first.

Treat this site as a way to arrive at a vendor's page knowing what to look for, not as a survey of the market. The products covered page sets out exactly where that boundary sits.

Where the pages fit together

  • Glossary

    The core of the site: around fifty terms, defined and cross-linked, from adware to zero-day.

  • How detection works

    What happens between clicking a file and seeing an alert, method by method.

  • Choosing software

    The comparison questions worth asking, and the billing terms to read first.

  • Device coverage

    How licences are counted across desktops, phones and tablets.

  • Products covered

    What AgileBase can and cannot tell you about TotalAV, and how to verify the rest.

  • Scams and your rights

    Australian reporting routes, consumer guarantees, and the regulators behind them.

  • Questions

    Short answers to the questions people actually type.

Australian services worth knowing about

Several public bodies publish free guidance in this area.

  • The Australian Cyber Security Centre, part of the Australian Signals Directorate, publishes practical guidance for individuals and families and operates the ReportCyber service for reporting cybercrime.
  • Scamwatch, run by the National Anti-Scam Centre at the ACCC, collects scam reports and describes current scam types, including the fake technical-support calls and pop-ups that borrow the language of antivirus software.
  • The ACCC is the national competition and consumer regulator and administers the Australian Consumer Law.
  • The Office of the Australian Information Commissioner regulates the Privacy Act 1988 and handles privacy complaints.
  • The eSafety Commissioner is Australia's independent regulator for online safety.

How the definitions are written

Method

Every entry is written to be readable without the entry above it, and to say plainly where a term is used loosely by vendors. Where a definition depends on a vendor's implementation rather than on an agreed meaning, the entry says so instead of picking one vendor's usage.

No entry cites a statistic unless it links the body that published it, and product statements are limited to what the vendor publishes about itself. Nothing here reports test results, because AgileBase runs no tests.