1. A computer-implemented method, comprising:
receiving, at a content transformation sub-system, content requested by a client device;
accessing annotation information that identifies one or more portions of the content to be transcoded, wherein the annotation information is generated by a content analysis sub-system;
transcoding the content, by the content transformation sub-system, at the one or more portions, wherein the transcoding comprises inserting additional executable code, that, when executed on the client device, identifies attempted interaction on the client device with the content by malware and transmits a report from the client device comprising data corresponding to the attempted interaction; and
after transforming the content, providing the content to the client device that requested the content;
wherein the computer-implemented method is performed by one or more computing devices.