Welcome to TRAE Guardian
TRAE Guardian is a comprehensive terminal security protection platform built on Qt framework, integrating EDR+AV capabilities with AI-powered risk analysis. It provides real-time threat detection, automatic response, and advanced protection against sophisticated malware attacks.
Our mission is to deliver enterprise-grade endpoint security with cutting-edge detection technologies, including ETW kernel monitoring, MBR/GPT protection, AI risk evaluation, and intelligent response mechanisms.
Core Capabilities
Virus Protection
Advanced malware detection with MBR protection, physical disk access interception, and AI-powered threat analysis. Successfully intercepts Rainbow Cat (MEMZ), Petya, WannaCry, and other sophisticated threats.
Rogue Software Detection
Identifies and manages unwanted software with behavioral analysis. Detects adware, spyware, and persistent software that violates user privacy and system integrity.
AI-Powered Analysis
DeepSeek-R1-0528-Qwen3-8B model integration for multi-dimensional risk scoring. AI provides indirect influence through risk assessment and can search knowledge bases for threat intelligence.
MBR Protection
Automatic backup and restoration of boot sectors. Detects and blocks MBR/GPT modifications in real-time, protecting against bootkit attacks.
Real-time Monitoring
ETW kernel-level event monitoring combined with NtQuery handle scanning for comprehensive visibility into process activities.
State Machine
6-state process management system (Untrusted → Observed → Suspicious → Restricted → Quarantined → Removed) with time-decay scoring.
Test Results
✅ Rainbow Cat (MEMZ) Detection
- Process terminated immediately upon execution
- MBR automatically restored
- No process restart detected
- VMware Tools correctly skipped
✅ Watchdog Mutual Protection
- All 4 processes terminated simultaneously
- No race condition during termination
- Complete process removal
- Executable files deleted