/e regex modifier, shell execution through request parameters, dropped phpinfo probes, hex-obfuscated eval, long base64 blobs and known webshell tokens). Quick mode reads the first 1 MB of a file, deep mode 8 MB.
How to access: GuardForge > Malware scanner.
Free/PRO: Pro (malware_scanner). Signatures ship inside the plugin — nothing is fetched for them.
Notes:
- A finding fires
guardforge/malware_finding, which the alert channels and (if enabled) auto-lockdown both listen for.