That’s generally too slow though; these things run in kernel space as they scan every I/O stream. Context switching and memory copies would kill performance.
https://i.imgur.com/t5jDXrt.png
"Why don't we unpack malware in the kernel" - "And so the search for intelligent life continues..."
https://i.imgur.com/t5jDXrt.png
"Why don't we unpack malware in the kernel" - "And so the search for intelligent life continues..."