Users with Admin or API Admin authorization can initiate malware scans on their host endpoints. Malware scans are configured as either a Full Scan or Custom Scan. A Full Scan includes all local and mounted disk drives, while a Custom Scan gives you the option of specifying folder names or file paths.
Important
Malware Protection must first be enabled in the agent policy for this feature to work. See the steps below to enable Malware Protection.
Enable malware protection on an agent policy
To enable malware protection on an agent policy:
In the Configure menu, select Policies.
Under Policy Name, click on the policy that you want to edit.
In the Configurations group, select Malware Protection.
Under the Malware Detection group, click tab for the operating system type used on the agent.
Set Signature and Heuristic Detection to ON.
Click the Save button in the top right corner.
Enable malware protection for Linux
To enable malware protection on an agent policy:
In the Configure menu, select Policies.
Under Policy Name, click on the policy that you want to edit.
In the Configurations group, select Malware Protection.
Under the Malware Detection group, click on the Linux tab.
Set Signature and Heuristic Detection to ON.
.png)
Click the Save button in the top right corner.
Scan Now for malware
To scan a host or host set for malware:
Select the Manage Hosts menu at the top of the screen.
Select a host or set of hosts in the hosts list.
From the Actions drop-down menu, select Run a Malware Scan and click Go.
Enter a name for the scan.
For the scan depth, choose either Full Scan or Custom Scan For Windows endpoints, you can also choose Active Memory scan.
If Custom Scan is chosen, specify the file or folder path, and then click Add.
Click Scan Now to run the malware scan.
Click the Expand icon (
) for the host you scanned to view the status of the scan request and to view the scan now results.
Cancel Scan Now
In cases when a requested scan causes a spike in resource consumption, canceling a requested Scan Now event for a host could restore performance.
Note
Only Scan Now events in the REQUESTED state can be canceled.
To cancel a requested scan for a host:
Select the Manage Hosts menu at the top of the screen.
Click the Expand icon (
) of the host which has a requested scan.From the list of Scan Now events, select the checkbox of the requested Scan Name that you wish to cancel.
From the Actions drop-down menu, select Cancel Scan and click Go.
Select Proceed to confirm.