Preprint Open access
MARS: Malware Analysis with Rule-Based Scoring of LLM Claims
Large language models can triage malware through direct verdicts or behavioral claims scored by an external policy. We present MARS, a malware triage framework, and compare direct classification with single-pass claim scoring using the same evidence collector and identical static evidence bundles for each model. The ev …