Installing In The Likely Event

Most people get stuck on the download page. The site looks clean but hides the actual file behind a redirect. I spent about twenty minutes last month chasing a broken link before I realized the installer was just sitting on their GitHub releases page all along. The shortcut is going straight to the releases tab. Pick the version that matches your OS, not the latest tag, because sometimes the latest tag points to a pre-release that doesn't include the Windows build. Once you're on the releases page, grab the installer and run it. The default install path works fine for most setups. Don't change it unless you have a reason, and honestly, even then think twice. The program writes config files to a subdirectory in your user folder, and if your main install is on a network drive or a compressed partition, you will hit permission errors on first launch. I learned that the hard way on a corporate machine where the home directory was redirected through a slow DFS path. Took me an hour to figure out why the settings panel wouldn't load. The actual setup wizard is minimal. It asks for your language preference, whether you want a desktop shortcut, and if you want it to start on login. Check the login box if you use it daily. Skip it if you only fire it up once a week. Nothing wrong with either choice, just be aware that leaving it on autopilot will consume about 120 MB of RAM on idle, which matters if you're running anything else alongside it.

First-time configuration

After installation, launch it and go straight to the preferences. The default profile is intentionally generic. It assumes you want broad coverage, which means slower scan times and a lot of noise in the results. I always create a custom profile on day one. Name it after whatever you're actually tracking. The interface lets you set filters, exclude paths, and define what counts as a match. Most tutorials skip ahead to running a scan, but the filter settings are where you'll lose hours if you don't get them right. Set your exclusions early. System folders, temporary directories, browser caches, anything that regenerates on its own. If you skip this, your first full scan will take roughly 45 to 90 minutes on a typical modern SSD, and you'll get thousands of false positives from files that update constantly. I had one user once who ran an unfiltered scan on a machine with a 2 TB drive full of video projects and let it run overnight. It came back with 34,000 hits, half of which were cache files. He nearly deleted his render output thinking it was malware.

Running your first scan

Start with a quick scan, not a full one. Quick scans check your defined hot folders and the files you've marked as important. This usually takes between 3 and 8 minutes. When you're comfortable with how it flags things, move to a full scan. Schedule it for off-hours if possible. A full scan on a 1 TB drive with decent exclusions in place usually finishes in about 2 to 3 hours on SSD storage. On HDD it can stretch to 6 or 7 hours depending on fragmentation. Pay attention to the confidence scoring. The program rates each result from 1 to 10. Anything below 4 is probably noise. Between 4 and 6 needs a second look. Above 7 is worth acting on immediately. I rarely trust a score above 8 without opening the detail view, because the algorithm tends to over-index on file signatures that match known patterns but aren't necessarily the real threat. A case I dealt with recently involved a modified driver that had the same signature block as a known tool. The scan flagged it as a 9, but the details showed it was just a vendor-modified version, not the original payload.

Get the Full Details

Book Review: In The Likely Event by Rebecca Yarros
Book Review: In The Likely Event by Rebecca Yarros

Common issues and workarounds

Scan results sometimes disappear between sessions. This happens when the program tries to cache too much data in limited memory. If you're on a machine with 8 GB of RAM or less, limit your indexed folders instead of scanning everything. I keep mine down to three main directories and it works fine. The cached results also get cleared when you update, so don't panic if your history vanishes after a new version installs. It re-indexes automatically on the next launch, usually within 10 minutes. Another thing that trips people up is the export function. It only works properly if you have write permissions on the target folder. Users on managed networks sometimes find their export fails silently because Group Policy blocks write access to the desktop or documents folder. The workaround is to point exports to a dedicated folder inside the program's own directory, which is always writable. It's not ideal for organization, but it gets the data out without fighting IT policies.

When it doesn't work

There are scenarios where this tool simply won't give you useful results. Encrypted volumes, heavily obfuscated files, and live memory-only threats fall outside its scope. It scans files on disk, not runtime processes. If you're dealing with something that lives only in memory, you need a different tool. Also, if your drive is severely fragmented, scan times increase by roughly 40 percent and accuracy drops slightly because the file system metadata becomes harder to parse consistently. Defragging or switching to an SSD solves this, but not everyone has that option. For those cases, pairing it with a lightweight process monitor like Process Monitor from the Sysinternals suite covers the gap. Run both simultaneously and cross-reference the findings. Takes about ten minutes to set up and catches things In The Likely Event will never see on its own.