Title
Page icon
Create new category
Edit page index title
Edit category
Edit link
How is the Main Result Determined in MetaDefender Core Scanning?
Check Your Version:
This article applies to all MetaDefender Core releases deployed on Windows and Linux systems.
MetaDefender Core scanning involves multiple sequential checks to determine the security status of a file.
Each step in the process contributes to the final decision, but the main result displayed is based on the earliest decisive action in the scanning flow.
Scanning Flow
The scanning process follows this order:

Archive Extraction
File Type Analysis
Blocklist / Allowlist Check
Country of Origin
Reputation
Cloud Hash Lookup
Vulnerability Assessment
YARA Rules
Metascan (+ External Scan)
Proactive DLP
Deep CDR (Content Disarm & Reconstruction)
Adaptive Sandbox
Software Bill of Materials
Post Action
Main Result Logic
If a file is blocked for multiple reasons during the scanning process, the main result will reflect the highest-priority decisive reason based on the scanning flow.
For example:
If a file is:
Known Bad (due to Reputation),
flagged as Potentially Vulnerable (by Vulnerability Assessment),
and infected (detected by Metascan),
The main result will display Known Bad, because Reputation is evaluated earlier in the flow and takes precedence.
Other block reasons (e.g., Vulnerability Assessment, Metascan infection) will not appear in the main result but can be viewed by clicking the three dots (…) in the scan report for detailed information.
Support:
If Further Assistance is required, please proceed to log a support case or chatting with our support engineer.