Docs/Threats & quarantine

Threats & quarantine

How SimSweep detects malware-like behavior in script mods, what severity labels mean, and how to quarantine, restore, or delete flagged files.


Script mods run code inside your game. SimSweep checks them for known malware signatures and suspicious patterns, then shows the findings for you to review.

How threat detection works#

SimSweep targets .ts4script files, which are ZIP archives containing compiled Python bytecode. Each one gets hashed and checked against a community safe list. If a file doesn't clear that, SimSweep inspects it for red flags: dangerous system imports, raw IP addresses, Discord webhooks, OS and process access, and paths that have no business being in a Sims mod.

Threat results can lower your overall health score on the Home dashboard.

What the results do not prove#

A suspicious import or system-access pattern can also have a legitimate use. A heuristic flag is not proof that a mod is malicious, and a result with no flags does not guarantee that a file is safe. Check the Details view, the mod's source, and the creator's instructions before deciding what to do.

SimSweep's threat checks do not establish compatibility with another security tool. If another tool reports a warning, keep that report and the exact file version when asking for help.

Severity levels#

When threats appear, they're labeled by severity:

LabelWhat it means
Known MalwareMatches a confirmed malicious signature. Remove this.
High RiskDangerous patterns found, not yet in the known-bad list. Treat with caution.
FlaggedSuspicious patterns that warrant a closer look.
Low ConcernSomething caught the scanner's attention but is probably fine. Worth noting.

If nothing is flagged, Threats shows "All clear - no flagged files."

Reviewing threats#

After a scan, if flagged files exist, a Threats card appears in Diagnostics. You can also filter My CC by "Flagged as threat" to find specific files across your library. Each flagged file shows its severity and a Details view with more information.

From the detail modal you can:

  • Show in Explorer (Windows) or Show in Finder (Mac) to locate the file on disk
  • Copy SHA256 to share the hash with the community or verify it elsewhere
  • Mark as Safe if you've investigated and trust the file (this only affects your local machine, not anyone else's)
  • Report to flag something for community review

Quarantine#

Quarantine moves selected files out of your active Mods folder into a sibling .simsweep-quarantine folder. They remain on disk, outside the folder the game loads mods from. A threat finding does not automatically move a file there.

To quarantine one or more files, select them in the Threats view or My CC and choose Quarantine selected.

The Quarantine panel is available from Diagnostics, Home quick actions, and the file inspector. Inside you'll find:

  • Restore selected to move files back into Mods
  • Delete selected to remove files permanently
  • Empty quarantine to delete everything in the quarantine folder at once
  • Show in Explorer / Show in Finder to open the quarantine folder on disk

Heads up: Permanent delete cannot be undone from SimSweep. Make sure before you use "Delete permanently" or "Empty quarantine."

Restoring a file#

If you decide to put a quarantined file back, select it and choose Restore selected. SimSweep attempts to return it to its recorded location in your Mods folder. Check the result before assuming every selected file was restored. An occupied destination, locked file, or unavailable drive can prevent a move.

Note: The quarantine manifest tracks files and their original locations. If it is corrupt or unreadable, an empty list does not prove that the quarantine folder is empty. Check the warning and use "Show in Explorer" or "Show in Finder" to inspect the folder. Keep the folder and its records while you get help.

If a move or restore is interrupted#

SimSweep keeps a recovery record for an unfinished file operation. Open the recovery panel and read the result for that operation. It offers the continuation or rollback actions available for that record, and reports files that still need attention.

If a drive is disconnected, reconnect it before retrying. Avoid moving or renaming files by hand while recovery is pending.

Save copies of my files copies recoverable files to a folder you choose without resolving the original operation. Check the copy result: some files may be missing or unreadable, and working files may be incomplete.

Discard recovery record closes tracking for that operation. It is not confirmation that every file was restored. Save copies and review any unresolved files before choosing it. If you need help, keep the recovery message and contact Discord support.

About "Mark as Safe"#

Marking a file safe dismisses it locally. It doesn't change the community safe list, and it doesn't mean the file is actually clean. Use it when you've done your own research and made a deliberate call to keep the file. The scanner won't flag it again for you, but another installation would still see it flagged.

Next up#

Wondering whether your mods might also be crashing the game? See Crash logs & CrashGuard for how SimSweep reads exception files and watches for new crashes in real time.