I’m wondering if malware running at user level, or possibly other levels, can be detected by antivirus solutions through real-time protection, essentially running through the logic that the malware should run or do something eventually, like call home or collecting data, and result in it being detected by the antivirus. Specifically talking about already compromised devices.

