Metadefender Core V4.19.0
Total Page:16
File Type:pdf, Size:1020Kb
MetaDefender Core v4.19.0 © 2019 OPSWAT, Inc. All rights reserved. OPSWAT®, MetadefenderTM and the OPSWAT logo are trademarks of OPSWAT, Inc. All other trademarks, trade names, service marks, service names, and images mentioned and/or used herein belong to their respective owners. Table of Contents About This Guide 14 Key Features of MetaDefender Core 15 1. Quick Start with MetaDefender Core 16 1.1. Installation 16 Basic setup 16 1.1.1. Configuration wizard 16 1.2. License Activation 22 1.3. Process Files with MetaDefender Core 22 2. Installing or Upgrading MetaDefender Core 23 2.1. Recommended System Configuration 23 Microsoft Windows Deployments 24 Unix Based Deployments 26 Data Retention 28 Custom Engines 28 Browser Requirements for the Metadefender Core Management Console 28 2.2. Installing MetaDefender 29 Installation 29 Installation notes 29 2.2.1. MetaDefender Core 4.18.0 or older 30 2.2.2. MetaDefender Core 4.19.0 or newer 33 2.3. Upgrading MetaDefender Core 38 Upgrading from MetaDefender Core 3.x to 4.x 38 Upgrading from MetaDefender Core older version to 4.18.0 (SQLite) 38 Upgrading from MetaDefender Core 4.18.0 or older (SQLite) to 4.19.0 or newer (PostgreSQL): 39 Upgrading from MetaDefender Core 4.19.0 to newer (PostgreSQL): 40 2.4. MetaDefender Core Licensing 41 2.4.1. Activating Metadefender Licenses 41 2.4.2. Checking Your Metadefender Core License 46 2.5. Performance and Load Estimation 47 What to know before reading the results: Some factors that affect performance 47 How test results are calculated 48 Test Reports 48 2.5.1. MetaDefender Core 4.19.0 or newer (PostgreSQL) 48 2.5.2. MetaDefender Core 4.18.0 or older (SQLite) 54 2.6. Special installation options 60 Use RAMDISK for the tempdirectory 60 3. Configuring MetaDefender Core 64 3.1. Management Console 64 3.1.1. Password Recovery 65 3.2. MetaDefender Configuration 72 3.2.1. Startup Core Configuration 73 3.2.2. Startup Node Configuration 82 3.2.3 Nginx related configuration 89 3.3. User management 98 3.3.1. Users and groups 99 3.3.2. Roles 104 3.3.3. User directories 109 3.3.4. Active Directory attributes 116 3.3.5. Change user password 119 3.3.6. Single Sign-On (SSO) 120 3.4. Update settings 143 Internet 144 Folder 145 Manual 145 3.5. Clean up scan database 146 Technology Note: 146 3.6. Policy configuration 146 3.6.1. How MetaDefender Core policies work 147 3.6.2. Workflow template configuration 147 3.6.3. Security zone configuration 161 3.6.4. Workflow rule configuration 162 3.6.5. Quarantine 167 3.7. Logging 175 3.7.1. Configuration 175 3.7.2 Log message format 176 3.7.3 Syslog message format 177 3.7.4 Error Message Description Table 181 3.8 Security settings on web console 222 3.8.1 Enabling HTTPS 222 3.8.2 Session timeout 227 3.8.3 Password Policy 227 3.9. Configuring proxy settings 229 How can I set proxy server for the product 229 3.10. External Scanners And Post Actions 230 External Scanners 230 Post Actions 233 3.11. Yara rule sources 235 3.12 Server Configurations 238 3.12.1 Email Configuration 238 3.12.2 Proxy Configuration 239 4. Process files with MetaDefender Core 241 Process Files via REST API 241 Process Files via Web Interface 241 Choose what to process and how 242 5. Deep CDR (Data Sanitization) 243 6. Proactive DLP 245 7. Operating MetaDefender Core 246 7.1. Dashboard 246 Overview page 247 Processing history 247 Quarantine 248 Update history 248 7.2. Inventory Management 249 7.2.1. Certificates 249 7.2.2. Modules 252 7.2.3. Nodes 262 7.2.4. Skip by hash 264 7.3. Regular Maintenance 266 Checking for Upgrades 266 Checking Engines / Databases Health 266 7.4 Import/Export configuration 267 Export 267 Import 267 Note 268 7.5. Database Defragmentation and Optimization 268 7.6. Reporting 271 7.7. Statistics 273 8. MetaDefender Core Developer Guide 274 How to Interact with MetaDefender Core using REST 274 File scan process 274 8.1. MetaDefender API 274 8.1.1. Sessions 275 8.1.2. Licensing 278 8.1.3. Processing files 283 8.1.4. Processing files in batch 312 8.1.5. Download Sanitized Files 324 8.1.6. Vulnerability Info In Processing Result 326 8.1.7. Skip by hash 329 8.1.8. Get version of components 335 8.1.9. Configuration related APIs 337 8.1.10. Yara 474 8.1.11. Webhooks 481 8.2. MetaDefender API Code Samples 486 9. (NEW) MetaDefender Core Developer Guide 488 10. Advanced MetaDefender Deployment 489 10.1. Scripted license management 489 Requirements 489 Activation steps 489 Deactivation steps 491 Important notes 492 10.2. Deployment automation support 492 Installation 493 Initialization 494 Configuration 498 10.3. Cloud Deployment 498 10.3.1. AWS Deployment 498 10.4. Multi-node deployment 518 Setting up several Metadefender Core nodes 518 10.5. Using external load-balancer 522 10.5.1. HTTP(S) - Layer 7 load balancing 522 10.5.2. DNS load balancing 525 11. Troubleshooting MetaDefender Core 528 Installation issues 528 Issues with nodes 528 Where are the Metadefender Core logs located? 528 How can I create a support package? 528 Issues under high load 528 Debug logging 529 Engine Clean-up Tool 529 MetaDefender Core 4.19.0 database information to connect 530 Example usages 530 How to Create Support Package? 534 Creating the package on Linux 534 Creating the package on Windows 534 Content of the created package 535 How to Read the Metadefender Core Log? 535 Files 535 Format 535 Severity levels of log entries 536 Inaccessible Management Console 536 How to detect 536 Solution 537 Possible Issues on Nodes 537 Q. Node detected 3rd party product on system 537 Q. There is no scan node connected 537 Too Many Sockets or Files Open 538 How to detect 538 Solution 538 Too Many TIME_WAIT Socket 539 How to detect 539 Solution 540 Technical Insights 540 12. Release notes 542 12.2 Proactive DLP Release Notes 544 v2.4.1 544 v2.4 545 v2.3.2 545 v2.3.1 545 v2.3.0 545 v2.2.1 546 v2.2 546 v2.1.2 546 v2.1.1 546 v2.1 546 v2.0.1 547 v2.0 547 v1.0.3 547 12.3 File Type module Release Notes 547 v5.2.26 547 v5.2.25 547 v5.2.24 547 v5.2.23 548 12.4 Archive module Release Notes 548 v5.3.5 548 v5.3.4 548 v5.3.3 548 v5.3.2 548 12.4 MetaDefender Core archived release notes 548 Version v4.18.0 548 Version v4.17.3 551 Version v4.17.2 553 Version v4.17.1 556 Version v4.17.0.1 557 Version v4.17.0 557 Version v4.16.3 559 Version v4.16.2 559 Version v4.16.1 560 Version v4.16.0 560 Version v4.15.2 561 Version v4.15.1 561 Version v4.15.0 562 Version v4.14.3 563 Version v4.14.2 564 Version v4.14.1 564 Version v4.14.0 565 Version v4.13.2 565 Version v4.13.1 565 Version v4.13.0 565 Version v4.12.2 566 Version v4.12.1 566 Version v4.12.0 566 Version v4.11.3 567 Version v4.11.2 567 Version v4.11.1 568 Version v4.11.0 568 Version v4.10.2 568 Version v4.10.1 569 Version v4.10.0 569 Version 4.9.1 570 Version 4.9.0 570 Version 4.8.2 571 Version 4.8.1 571 Version 4.7.2 573 Version 4.7.1 573 Version 4.6.3 574 Version 4.6.2 574 Version 4.6.1 574 Version 4.6.0 575 Version 4.5.1 576 Version 4.5.0 576 Version 4.4.1 576 Version 4.3.0 577 Version 4.2.0 578 Version 4.1.0 579 Version 4.0.1 579 Version 4.0.0 579 13. Legal 581 Copyright 581 DISCLAIMER OF WARRANTY 581 COPYRIGHT NOTICE 581 MetaDefender Export Classification 581 14. Knowledge Base Articles 583 Are MetaDefender Core v4 upgrades free? 584 Are there any limitations regarding the MetaDefender Core v4 scan engines? 585 Can I control access to the RAM disk in MetaDefender Core v4? 586 Does Metadefender Core v4 offer real-time antivirus protection on the system where it is installed? 586 Does MetaDefender Core v4 Detect the NotPetya Ransomware? 586 Does the fixing updates for Meltdown and Spectre vulnerabilities affect any engines in MetaDefender Core v4? 588 Engine clean-up instructions 589 External scanners in MetaDefender core v4.8.0 and above 592 How can I configure the maximum queue size in Metadefender Core v4 ? 595 How can I find a sanitized file scanned with MetaDefender Core v4? 596 How can I increase the scaling up performance? 596 How can I run tests to see the different scan results on MetaDefender Core v4? 599 How can I upgrade from Core v4.7.0/v4.7.1 to a newer Core v4.7 release 600 How can the TEMP folder be changed? 602 How do I check if "noexec" flag exists on a Linux OS? 603 How do I collect verbose debug packages on MetaDefender Core v4 for Linux? 604 How do I deploy MetaDefender Core v4 to an offline Linux environment? 605 Installing MetaDefender Core 606 Activate your license 606 Installing the MetaDefender Update Downloader utility 608 Applying offline updates 610 Contacting OPSWAT Support 610 How do I deploy MetaDefender Core v4 to an offline Windows environment? 611 Installing MetaDefender Core 611 Activate your license 612 Installing the MetaDefender Update Downloader utility 614 Applying offline updates 616 Contacting OPSWAT Support 617 How do I disable real-time protection of my anti-malware software if it is not allowed by corporate policy for use with MetaDefender Core v4? 617 How do I remove an engine from my MetaDefender v4 instance? 618 How do I use MetaDefender Core v4 Workflows ? 619 Defining and administering Workflow Templates in MetaDefender Core v4 619 How long is the support life cycle for a specific version/release of MetaDefender Core v4? 620 How to install MSE on Windows Server 2012 R2 and Windows Server 2016 623 MSE on Windows Server 2012 R2 623 MSE on Windows Server 2016 627 How to transfer your Metadefender Core v4 scan history database 633 Installing .NET Core runtime 3.1 on Linux for Proactive DLP 2.4.0+ 633 Is Metadefender Core compromised while scanning files? 637 Is there a virus test I could use to test MetaDefender Core v4? 637 MetaDefender Core v4 shows a large number of files that failed to scan.