← All detection heuristics · General
info
ANALYSIS_TIMEOUT_PARTIAL
What it means
Analysis exceeded the wall-clock timeout; phases that had completed before the timeout are preserved.
Why it fires
Some scanners (regex-heavy parsers, large structured documents) can hit the per-file wall-clock budget. Unlike SCAN_INCOMPLETE this finding does not flag the result as needing retry — re-scanning the same bytes will hit the same timeout, so the partial result is cached as-is. Operators investigating individual cases can force a fresh scan via the rescan API.
Other General heuristics
POLYGLOT_PDF_APPENDED_ZIP_CVE_BUNDLE EXTRACTED_FILE_CLAMAV POLYGLOT_GIF_PDF_FORCEDENTRY_SHAPE SPEC_DIVERGENCE_HIGH PDF_EXTENSION_MISMATCH POLYGLOT_PDF_ZIP_APPENDED EXTRACTED_FILE_STATIC_TRIAGE CORPUS_HISTORICALLY_MALICIOUS POLYGLOT_TEXT_PDF POLYGLOT_ZIP_PREFIXED FORMAT_NEUTRAL_SCAN PPT_FOPT_COMPLEX_DATA_OVERFLOW PPT_FOPT_PROPERTY_TABLE_TRUNCATED CORPUS_RARE_COMBINATION CORPUS_RARE_STRUCTURAL_FEATURE_SET EMBEDDED_URL MACRO_VALID_PUBLISHER_SIGNATURE SCAN_OPTIONAL_STAGES_SKIPPED POLYGLOT_PDF_APPENDED_ZIP_SCAN_INCOMPLETE SCAN_INCOMPLETE UNKNOWN_FORMAT