Signatures Don’t Stop What They’ve Never Seen
Signatures Don’t Stop What They’ve Never Seen
When every payload is unique, what does your audit trail actually prove?
AI-assisted tooling now generates malware variants on demand. Different code, different hash, same objective. Payloads are built for a single target and never reappear. There is no hash to check, no prior observation to match against, no pattern to recognize. The artifact clears every signature-based control by design.
The same limitation applies to zero-day threats. We broke down why behavior is the only detection method that holds up when signatures have nothing to match against in Zero-Day and Unknown Malware: Why Behavior Wins When Signatures Fail.
That is the technical problem. Here is the compliance problem that follows.
“We checked the signature” is getting harder to defend
When an auditor or regulator asks why an artifact was allowed to run, the answer needs to hold up. Frameworks like the SEC’s cybersecurity disclosure rules and DORA do not mandate specific tools. They require defensible decisions. A process record showing a confidence score below threshold explains what the tool returned. It does not explain what your organization understood about the artifact before it executed.
If the payload was designed to evade signature detection and succeeded, that record shows a control ran. It does not show the control worked. That is a harder position to hold in front of an assessor, and a harder one to hold personally as the CISO signing the disclosure.
What a defensible decision looks like
Behavioral evidence answers the question that pattern matching cannot. What was this artifact capable of doing? Was that evaluated before it ran? What policy was it measured against, and what was the verdict?
That is the documentation the audit conversation is looking for: a decision with the behavioral basis attached. For organizations managing SEC or DORA obligations, that evidence exists before it is needed, not reconstructed after the fact.
Ken Ammon makes the full technical case in his Forbes piece. If signature-based controls are part of your current stack, it is worth understanding exactly where they stop working.
Read the full article “Security Has a Timing Problem, But Attackers Don’t” .





