BlueEdr runs one scan with two stages on a Windows executable. The static stage parses the PE structure and matches the BlueEdr YARA signature set and returns immediately. The dynamic stage then emulates the sample and records what it actually does: API calls, self modifying code, decrypted strings, memory protections, persistence and network activity.