Metadefender Core V4.14.0
Total Page:16
File Type:pdf, Size:1020Kb
MetaDefender Core v4.14.0 © 2018 OPSWAT, Inc. All rights reserved. OPSWAT®, MetadefenderTM and the OPSWAT logo are trademarks of OPSWAT, Inc. All other trademarks, trade names, service marks, service names, and images mentioned and/or used herein belong to their respective owners. Table of Contents About This Guide 12 Key Features of Metadefender Core 13 1. Quick Start with Metadefender Core 14 1.1. Installation 14 Operating system invariant initial steps 14 Basic setup 15 1.1.1. Configuration wizard 15 1.2. License Activation 20 1.3. Scan Files with Metadefender Core 20 2. Installing or Upgrading Metadefender Core 21 2.1. Recommended System Requirements 21 System Requirements For Server 21 Browser Requirements for the Metadefender Core Management Console 23 2.2. Installing Metadefender 23 Installation 23 Installation notes 24 2.2.1. Installing Metadefender Core using command line 24 2.2.2. Installing Metadefender Core using the Install Wizard 26 2.3. Upgrading MetaDefender Core 26 Upgrading from MetaDefender Core 3.x 26 Upgrading from MetaDefender Core 4.x 27 2.4. Metadefender Core Licensing 27 2.4.1. Activating Metadefender Licenses 27 2.4.2. Checking Your Metadefender Core License 34 2.5. Performance and Load Estimation 35 What to know before reading the results: Some factors that affect performance 35 How test results are calculated 36 Test Reports 36 Performance Report - Multi-Scanning On Linux 36 Performance Report - Multi-Scanning On Windows 40 2.6. Special installation options 45 Use RAMDISK for the tempdirectory 45 3. Configuring Metadefender Core 49 3.1. Management Console 49 3.2. Metadefender Configuration 50 3.2.1. Startup Core Configuration 50 3.2.2. Startup Node Configuration 54 3.2.3 Nginx related configuration 57 3.3. User management 57 3.3.1. Users and groups 58 3.3.2. Roles 63 3.3.3. User directories 65 3.3.4. Active Directory attributes 73 3.3.5. Change user password 76 3.4. Update settings 77 Internet 78 Folder 79 Manual 79 3.5. Clean up scan database 80 Technology Note: 80 3.6. Policies configuration 80 3.6.1. How MetaDefender Core policies work 81 3.6.2. Workflow template configuration 81 3.6.3. Security zone configuration 96 3.6.4. Workflow rule configuration 96 3.6.5. Quarantine 101 3.7. Logging 110 3.7.1. Configuration 110 3.7.2. Debug logging 111 3.8 Security settings on web console 111 3.8.1 Enabling HTTPS 112 3.8.2 Session timeout 115 3.9. Configuring proxy settings 116 How can I set proxy server for the product 116 3.10. External Scanners And Post Actions 117 External Scanners 117 Post Actions 120 3.11. Yara rule sources 122 4. Scan files with Metadefender Core 124 Scan Files via REST API 124 Scan Files via Web Interface 125 Choose what to scan and how 125 Start scanning 125 Progress of scanning 125 5. Data Sanitization 127 6. Operating Metadefender Core 128 6.1. Dashboard 128 Overview page 128 Scan history 129 Quarantine 129 Update history 129 6.2. Inventory Management 130 Certificates 130 Nodes 133 Skip by hash 135 Technologies 137 6.3. Regular Maintenance 145 Checking for Upgrades 145 Checking Engines / Databases Health 145 6.4 Import/Export configuration 145 Export 146 Import 146 Note 146 7. Metadefender Core Developer Guide 147 How to Interact with Metadefender Core using REST 147 File scan process 147 7.1. MetaDefender API 147 7.1.1. Sessions 148 7.1.2. Licensing 151 7.1.3. Processing files 155 7.1.4. Processing files in batch 171 7.1.5. Download Sanitized Files 180 7.1.6. Vulnerability Info In Processing Result 181 7.1.7. Skip by hash 185 7.1.8. Get version of components 190 7.1.9. Configuration related APIs 193 7.1.10. Yara 311 7.2. MetaDefender API Code Samples 318 7.3. Deployment automation support 319 Installation 319 Initialization 320 Configuration 324 8. Advanced Metadefender Deployment 325 8.1. Scripted license management 325 Requirements 325 Activation steps 325 Deactivation steps 327 Important notes 328 8.2. Multi-node deployment 328 Setting up several Metadefender Core nodes 328 8.3. Using external load-balancer 331 8.3.1. HTTP(S) - Layer 7 load balancing 332 8.3.2. DNS load balancing 334 8.4. Cloud Deployment 337 8.4.1. AWS Deployment 337 9. Troubleshooting Metadefender Core 358 Installation issues 358 Issues with nodes 358 Where are the Metadefender Core logs located? 358 How can I create a support package? 358 Issues under high load 358 How to Create Support Package? 359 Creating the package on Linux 359 Creating the package on Windows 359 Content of the created package 360 How to Read the Metadefender Core Log? 360 Files 360 Format 360 Severity levels of log entries 361 Inaccessible Management Console 361 How to detect 361 Solution 361 Possible Issues on Nodes 362 Q. Node detected 3rd party product on system 362 Q. There is no scan node connected 362 Too Many Sockets or Files Open 363 How to detect 363 Solution 363 Too Many TIME_WAIT Socket 364 How to detect 364 Solution 364 Technical Insights 365 10. Release notes 366 Version v4.14.0 366 Version v4.13.2 366 Version v4.13.1 366 Version v4.13.0 367 Version v4.12.2 367 Version v4.12.1 367 Version v4.12.0 368 Version v4.11.3 368 Version v4.11.2 368 Version v4.11.1 369 Version v4.11.0 369 Version v4.10.2 370 Version v4.10.1 370 Version v4.10.0 371 Version 4.9.1 371 Version 4.9.0 372 Version 4.8.2 372 Version 4.8.1 373 Version 4.7.2 374 Version 4.7.1 374 Version 4.6.3 375 Version 4.6.2 375 Version 4.6.1 376 Version 4.6.0 376 Version 4.5.1 377 Version 4.5.0 377 Version 4.4.1 378 Version 4.3.0 379 Version 4.2.0 380 Version 4.1.0 380 Version 4.0.1 381 Version 4.0.0 381 11. Metadefender / Client 382 About This Guide 382 Key Features of MetaDefender Client 382 Supported Operating Systems 382 1. MetaDefender Client Packages 383 MetaDefender Free Client 383 MetaDefender Premium Client 383 2. MetaDefender Premium Client 384 2.1 Install using the Install Wizard 384 2.2 Install using the Command Line 386 2.3 Using the MetaDefender Premium Client 387 2.4 Configuring through the config file 402 2.5 Configuring through Central Management 409 3. MetaDefender Free Client 414 4. Command Line Interface 414 Example: 414 Command Line Options 414 4.1 Generating and using the Administrator Password 418 5. MetaDefender Client Release Notes 420 Tips and Known Issues 420 5.1. Archived MetaDefender Client Release Notes 421 12. Legal 435 Copyright 435 DISCLAIMER OF WARRANTY 435 COPYRIGHT NOTICE 435 Export Classification EAR99 435 13. Knowledge Base Articles 436 Are MetaDefender Core v4 upgrades free? 437 Are there any dependencies that need to be fulfilled for MetaDefender Core v4 engines ? 437 Does Metadefender Core v4 offer real-time antivirus protection on the system where it is installed? 438 Does MetaDefender Core v4 Detect the NotPetya Ransomware? 439 Does the fixing updates for Meltdown and Spectre vulnerabilities affect any engines in MetaDefender Core v4? 441 External scanners in MetaDefender core v4.8.0 and above 442 How can I configure the maximum queue size in Metadefender Core v4 ? 444 How can I find a sanitized file scanned with MetaDefender Core v4? 445 How can I increase the scaling up performance? 446 How can I upgrade from Core v4.7.0/v4.7.1 to a newer Core v4.7 release 448 How can the TEMP folder be changed? 449 How do I collect verbose debug packages on MetaDefender Core v4 for Linux? 450 How do I deploy MetaDefender Core v4 to an offline Linux environment? 451 Installing MetaDefender Core 451 Activate your license 452 Installing the MetaDefender Update Downloader utility 453 Applying offline updates 455 Contacting OPSWAT Support 456 How do I deploy MetaDefender Core v4 to an offline Windows environment? 456 Installing MetaDefender Core 457 Activate your license 457 Installing the MetaDefender Update Downloader utility 458 Applying offline updates 460 Contacting OPSWAT Support 461 How do I disable real-time protection of my anti-malware software if it is not allowed by corporate policy for use with MetaDefender Core v4? 461 How do I remove an engine from my MetaDefender v4 instance? 463 How do I use MetaDefender Core v4 Workflows ? 463 Defining and administering Workflow Templates in MetaDefender Core v4 464 How long is the support life cycle for a specific version/release of MetaDefender Core v4? 465 How to transfer your Metadefender Core v4 scan history database 467 Is action needed because Metadefender v4's AVG license is expiring on 2018-06-15? 468 What do I need to do? 468 What if I don't take action by June 15, 2018? 469 Why is the license for AVG expiring? 469 What if I need more assistance from OPSWAT on this topic? 469 Is Metadefender Core compromised while scanning files? 469 Is there a virus test I could use to test MetaDefender Core v4? 469 MetaDefender Core v4 shows a large number of files that failed to scan. What can I do? 470 Post actions in MetaDefender core V4.8.0 and above 471 Queue mechanism on Metadefender Core v4 473 Queue mechanism in general 473 Queue size for requests 473 Limit of concurrent connections 473 Max file size allowed 474 Using MetaDefender core V4 BLACKLIST/WHITELIST feature 474 Using filetype groups VS.