@Sampei.Nihira
When you encounter unexpected results, please share the links and explain what you expected and why.
Import and export is on the listm but let us first try to get the core functionality right. It is a fine balence between FP's and FN's
Yes it is post download, because that is the only way I can surpress warnings for clean VT results. Also very small downloads arrive on disk before VT results are returning.@LinuxFan58
Maybe i am silly, but with this 2.0.1 version i've always the alert after downloading the file (no the purpose of DS), so the downloaded file is already on my desktop before being checked, and no go back option!!!!.
Forget my ignorance if am mistaken.
![]()
DS oups
MediaFire is a simple to use free service that lets you put all your photos, documents, music, and video in a single place so you can access them anywhere and share them everywhere.www.mediafire.com



No Chrome Webstore is on the whitelist. I could add an option to disable internal whitelist, since it now only has a the webstores of Google, Apple and M$ now. Or remove whitelist completely.




Yes ! 2.4 aviable in store
View attachment 298949
What is new
1. Improved heuristics (thanks to @Sampei.Nihira )
2. Shortened build-in whitelist to only webstores (also thanks to Sampei-San)
3. When download URL is unknown it offers to check download at Hybrid-Analysis.com (Crowdstrike + MetaDefender)
a) Ignore email entry (works without it)
b) choose quick scan (Crowdstrike + MetaDefender)
c) upload file
@Shadowra next time when you test URL protection (although this is only download warning when a possible harmful file is downloaded = post download warning), maybe you could include download sentinel. The testing by MT-members improved heuristics a lot, so I am very interested in false negatives and false positives.
False Positive Reduction is for VT-results not for heuristics. The heuristics are factual observations and each suspicious signal is translated to a negative score (e.g. changing file type between On-download and Write to disk is more suspicious than downloading something from github raw or google cloud, Sketchy URL weighs more than a longer domain name this.is,an-example,com, etcetera) When there is an heuristics observation only, the strict calculation is applied, when VT info is available the loose calculation). That is why it classifies its own download from Githun as inclonclusive (mixed signals) and rates it as probably suspicious, to stimulate the user to run a check at Hybrid Analysis. Because the program is not yet trying to install or execute, the effects of a False Positives are zero (only some user time and energy). That is why Download Sentinel applies a ¨better be safe than sorry" approach (in regard to heuristics with no VT-info).Whether False Positive Reduction is set to Low or Medium, this is the warning displayed to the user: