ClamAV
ClamAV is a free, open-source (GPL) antivirus engine maintained by Cisco Talos since 2007, used by mail gateway operators, ISPs, and security researchers to detect trojans, viruses, and malware in email and file traffic.
- Company typePrivate
- Founded2002
- HeadquartersSan Francisco, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What ClamAV does
ClamAV is an open-source (GPL) antivirus engine introduced in 2002 and maintained since 2007 by Cisco Talos, the threat-intelligence division of Cisco Systems. The software is purpose-built to detect trojans, viruses, malware, and other malicious threats in email traffic, file servers, endpoints, and network scans, and is widely positioned as the de facto open-source standard for mail gateway scanning. Its primary user base comprises mail gateway operators, ISPs/network operators, IT security researchers, and individual open-source users — none of whom pay licensing fees.
ClamAV firmographics
Firmographics- Name
- ClamAV
- Legal name
- ClamAV (maintained by Cisco Talos)
- Website
- https://clamav.net
- Company type
- Private
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- ClamAV is a free, open-source (GPL) antivirus engine maintained by Cisco Talos since 2007, used by mail gateway operators, ISPs, and security researchers to detect trojans, viruses, and malware in email and file traffic.
- Ownership category
- akta.pro rank
Where ClamAV is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Markets served
ClamAV business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Infrastructure, Technology or R&D, Operations
Revenue model
- Open-source distribution: ClamAV is a free, open-source antivirus engine. No revenue is generated from the software itself. The project is maintained by Cisco Talos as part of their threat intelligence and security research mission.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Annual | Free Open-Source |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels7 records
ClamAV product offering
Product offeringCore offering
ClamAV is an open-source (GPL) antivirus engine used to detect trojans, viruses, malware, and other malicious threats. It includes a multi-threaded scanner daemon (ClamD), command-line utilities for on-demand file scanning, automatic signature database updates via FreshClam, and support for multiple file formats, signature languages, and archive unpacking. The project is maintained by Cisco Talos and is the de facto open-source standard for mail gateway-scanning software.
Product overview
ClamAV is an open-source antivirus engine for detecting trojans, viruses, malware, and other malicious threats. The product consists of the core ClamAV engine with multi-threaded scanner daemon and command-line utilities for on-demand file scanning, augmented by continuously updated CVD signature databases (main.cvd, daily.cvd, bytecode.cvd) distributed via the Freshclam updater. ClamAV supports multiple file formats and signature languages and includes archive unpacking capabilities. Deployment options include Docker containers for Alpine and Debian, and the scanning engine is available as libclamav for application integration. A community signatures program allows third-party contributions for review. A former Safe Browsing feature (now a separate project) provided Google Safe Browsing integration.
Differentiator
Problem solved
Functional benefit
Brands
- ClamAV Virus Database (CVD): The virus signature database distributed with ClamAV, including main.cvd, daily.cvd, and bytecode.cvd files
- clamav-safebrowsing
- libclamav
Products and services
- ClamAV Antivirus Engine Open-source antivirus engine for detecting trojans, viruses, malware, and other malicious threats. Includes a multi-threaded scanner daemon, command-line utilities for on-demand file scanning, and automatic signature updates. Supports multiple file formats and signature languages, as well as file and archive unpacking.
- CVD Signature Databases Virus signature databases distributed as CVD files including main.cvd (~85 MiB), daily.cvd (~22 MiB), and bytecode.cvd (~275 KiB). Databases are distributed via the ClamAV mirror network and updated through FreshClam. Supports external .cvd.sign signature files for FIPS-compliant verification.
- ClamAV Docker Containers Containerized deployments of ClamAV available via Docker Hub for Alpine and Debian base images. Container images are maintained for supported ClamAV versions including 1.5, 1.4 LTS, and 1.0 LTS. Users are recommended to select feature release tags rather than specific minor release tags.
- libclamav C library providing the core scanning engine and public APIs for applications to integrate ClamAV scanning functionality. Exposes functions for scanning files, descriptors, and memory maps; engine configuration; scan callbacks; and CVD verification (cl_scanfile, cl_scandesc, cl_scanmap, cl_engine_set_num, cl_cvdverify_ex, etc.).
Quantifiable outcome
- ~50% reduction in signature database size
- +1 more outcomes
Companies that use ClamAV
Customer profileSegments4 records
Ideal customer profiles4 records
ClamAV technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature12 records
ClamAV partnerships and signals
Strategic signalScale indicators4 records
Recent moves6 records
Expansion highlights5 records
ClamAV competitors and assessment
Company assessmentBroad incumbents
- Trend Micro: Trend Micro offers a broad security portfolio including ScanMail for mail gateways and endpoint antivirus, overlapping with ClamAV's primary use cases as a larger incumbent security vendor.
- Microsoft Defender: Microsoft Defender for Endpoint is a broad incumbent antivirus and EDR solution bundled with Windows and expanding into Linux/server protection, competing with ClamAV across endpoint and server scanning use cases.
Direct peers
- Bitdefender: Bitdefender GravityZone is a commercial endpoint security platform with antivirus engines used for mail scanning and file server protection, directly comparable to ClamAV's mail/file scanning functionality.
- Wazuh: Wazuh is an open-source security platform providing endpoint detection, file integrity monitoring, and threat detection - overlapping with ClamAV's use cases in open-source security deployments for Linux servers and endpoints.
- ESET: ESET NOD32 is a commercial antivirus engine widely deployed for endpoint protection and mail gateway scanning, directly competing with ClamAV in enterprise and SMB security deployments.
- Kaspersky: Kaspersky Security for Mail Servers and Kaspersky Endpoint Security provide commercial antivirus solutions directly comparable to ClamAV's mail gateway and file scanning capabilities.
- Sophos: Sophos offers commercial antivirus and endpoint security products, including Sophos Anti-Virus for Linux and Sophos Mail Security, directly competing with ClamAV's primary use cases in mail gateway and file server scanning.
Emerging players
- SentinelOne: SentinelOne Singularity is an AI-powered endpoint security platform using behavioral detection rather than signature-based scanning, representing the next-generation approach competing with ClamAV's traditional model.
- CrowdStrike: CrowdStrike Falcon is a next-generation endpoint detection and response (EDR) platform that increasingly competes with traditional signature-based antivirus like ClamAV by offering behavioral analysis and cloud-native architecture.
Others
- VirusTotal: VirusTotal (owned by Google) is a multi-engine malware scanning service that aggregates dozens of antivirus engines including ClamAV, providing an adjacent ecosystem for threat intelligence and detection validation.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
ClamAV social profiles
Digital presenceClamAV financial estimates
Financial estimateRevenue estimate
Valuation estimate
ClamAV leadership team
Management profileNumber of profiles
ClamAV funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
ClamAV M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about ClamAV
What does ClamAV do?
ClamAV is an open-source (GPL) antivirus engine used to detect trojans, viruses, malware, and other malicious threats. It includes a multi-threaded scanner daemon (ClamD), command-line utilities for on-demand file scanning, automatic signature database updates via FreshClam, and support for multiple file formats, signature languages, and archive unpacking. The project is maintained by Cisco Talos and is the de facto open-source standard for mail gateway-scanning software.
Is ClamAV a public or private company?
ClamAV is a private company. It is classified as corporate owned and is currently operating.
When was ClamAV founded?
ClamAV was founded in 2002. It employs 1 to 10 people.
Where is ClamAV based?
ClamAV is headquartered in San Francisco, United States, in the North America region.
How does ClamAV make money?
One revenue line is on record: open-source distribution.
Who are ClamAV's main competitors?
Broad incumbents on record are Trend Micro and Microsoft Defender. Direct peers are Bitdefender, Wazuh, ESET, Kaspersky and Sophos. Emerging players are SentinelOne and CrowdStrike. VirusTotal is listed as an others.
Does ClamAV have an API?
No public API is recorded for ClamAV.