Warden Performance Record
MRG Effitas — Q1 2025
360° assessment against live malware and financial-fraud samples. Open the PDF →
Baseline, direction, outcome.
Telemetry, reported as operating states: devices known good, risk held inside containment, unknown files adjudicated and whether anything escaped to cause harm. Three things are being measured, and they answer different questions. Read them in this order.
The large percentage is a lifetime average
It averages every valid weekly observation in the published record, not this week, and not a probability of compromise.
Three windows show which way it is moving
Week compares the latest completed week with the one before it. 4-week and 52-week compare that block's average with the block before it. All in percentage points.
Only one number measures harm
Containment percentages show where risk was controlled. Impacted or breached shows whether any of it reached operational impact.
Real-time endpoint integrity
Where endpoint risk existed and whether it stayed inside containment.
Compared with: —
Known Good State
The share of active protected devices running with no unknown files or activity that required containment.
Potential Threats in Containment
Unknown or potentially malicious activity was isolated so it could be analyzed without unrestricted execution.
Confirmed Malicious Activity
Activity was confirmed malicious, and remained inside the prevention and containment boundary.
Proactive threat neutralization
What unknown files turned out to be, after deterministic containment and analysis.
Compared with: —
Clean
Files first treated as unknown were analyzed and confirmed safe.
Unwanted Apps in Containment
Applications judged undesirable or risky, though not classified as malware.
Malware in Containment
Unknown files confirmed malicious while still inside containment.
Impacted or breached, across — reported weeks.
Unknown and malicious activity exists in every environment. The decisive question is whether it escaped containment and reached operational impact. In this record it has not.
The record, week by week.
The latest twelve periods are shown first. Load more, open the whole archive, download the CSV, or go to the source data.
| Week | Device view | File view | |||||
|---|---|---|---|---|---|---|---|
| Known Good ? | Potential Threats ? | Confirmed Malicious ? | Infections / Breaches ? | Clean ? | Unwanted Apps ? | Malware ? | |
| Loading the weekly archive… | |||||||
How these figures are calculated
- Card values
- Arithmetic means across every valid weekly row in the published record.
- Week window
- The latest completed week minus the week immediately before it.
- 4 & 52-week
- The mean of the most recent block against the mean of the block before it.
- Units
- All movement is reported in percentage points, never relative percentages.
- Color logic
- Green marks the favorable direction for that metric: up for Known Good and Clean, down for every risk, containment and malware measure.
- Freshness
- Values come from a locally cached copy of the source record. No visitor request triggers a remote call, and a failed refresh preserves the last successful dataset.
See How Warden Prevents Impact.
The record above is the outcome of a containment-first model. The next step is applying it to your endpoint environment.