Metadefender Core V4.17.3
Total Page:16
File Type:pdf, Size:1020Kb
MetaDefender Core v4.17.3 © 2020 OPSWAT, Inc. All rights reserved. OPSWAT®, MetadefenderTM and the OPSWAT logo are trademarks of OPSWAT, Inc. All other trademarks, trade names, service marks, service names, and images mentioned and/or used herein belong to their respective owners. Table of Contents About This Guide 13 Key Features of MetaDefender Core 14 1. Quick Start with MetaDefender Core 15 1.1. Installation 15 Operating system invariant initial steps 15 Basic setup 16 1.1.1. Configuration wizard 16 1.2. License Activation 21 1.3. Process Files with MetaDefender Core 21 2. Installing or Upgrading MetaDefender Core 22 2.1. Recommended System Configuration 22 Microsoft Windows Deployments 22 Unix Based Deployments 24 Data Retention 26 Custom Engines 27 Browser Requirements for the Metadefender Core Management Console 27 2.2. Installing MetaDefender 27 Installation 27 Installation notes 27 2.2.1. Installing Metadefender Core using command line 28 2.2.2. Installing Metadefender Core using the Install Wizard 31 2.3. Upgrading MetaDefender Core 31 Upgrading from MetaDefender Core 3.x 31 Upgrading from MetaDefender Core 4.x 31 2.4. MetaDefender Core Licensing 32 2.4.1. Activating Metadefender Licenses 32 2.4.2. Checking Your Metadefender Core License 37 2.5. Performance and Load Estimation 38 What to know before reading the results: Some factors that affect performance 38 How test results are calculated 39 Test Reports 39 Performance Report - Multi-Scanning On Linux 39 Performance Report - Multi-Scanning On Windows 43 2.6. Special installation options 46 Use RAMDISK for the tempdirectory 46 3. Configuring MetaDefender Core 50 3.1. Management Console 50 3.1.1. Password Recovery 51 3.2. MetaDefender Configuration 58 3.2.1. Startup Core Configuration 59 3.2.2. Startup Node Configuration 68 3.2.3 Nginx related configuration (for API Rate Limiting) 75 3.3. User management 77 3.3.1. Users and groups 77 3.3.2. Roles 82 3.3.3. User directories 87 3.3.4. Active Directory attributes 94 3.3.5. Change user password 97 3.4. Update settings 98 Internet 99 Folder 100 Manual 100 3.5. Clean up scan database 101 Technology Note: 101 3.6. Policy configuration 101 3.6.1. How MetaDefender Core policies work 102 3.6.2. Workflow template configuration 102 3.6.3. Security zone configuration 116 3.6.4. Workflow rule configuration 117 3.6.5. Quarantine 122 3.7. Logging 130 3.7.1. Configuration 130 3.7.2 Log message format 131 3.7.3 Syslog message format 132 3.7.4 Error Message Description Table 136 3.8 Security settings on web console 177 3.8.1 Enabling HTTPS 177 3.8.2 Session timeout 181 3.8.3 Password Policy 182 3.9. Configuring proxy settings 183 How can I set proxy server for the product 183 3.10. External Scanners And Post Actions 184 External Scanners 184 Post Actions 187 3.11. Yara rule sources 189 3.12. Configuring mail settings 192 Server configuration 192 User authentication 193 4. Process files with MetaDefender Core 194 Process Files via REST API 194 Process Files via Web Interface 194 Choose what to process and how 195 5. Deep CDR (Data Sanitization) 196 6. Proactive DLP 197 Detect and then block approach 197 Prevent and then allow approach 197 6.1 Detect sensitive information 197 Sensitive Data 197 Certainty score 198 Supported File Types 198 Optical Character Recognition (OCR) 199 Sample regular expressions 201 6.2 Redact sensitive information 205 Supported File Types 205 Supported Sensitive Information 206 To set redaction 206 6.3 Remove metadata 208 Supported File Types 208 To set remove metadata 208 6.4 Watermark files 209 Supported File Types 209 To set watermark 210 7. Operating MetaDefender Core 212 7.1. Dashboard 212 Overview page 212 Processing history 213 Quarantine 214 Update history 214 7.2. Inventory Management 215 Certificates 215 Modules 218 Nodes 228 Skip by hash 230 7.3. Regular Maintenance 232 Checking for Upgrades 232 Checking Engines / Databases Health 232 7.4 Import/Export configuration 233 Export 233 Import 233 Note 234 8. MetaDefender Core Developer Guide 235 How to Interact with MetaDefender Core using REST 235 File scan process 235 8.1. MetaDefender API 235 8.1.1. Sessions 236 8.1.2. Licensing 239 8.1.3. Processing files 244 8.1.4. Processing files in batch 271 8.1.5. Download Sanitized Files 283 8.1.6. Vulnerability Info In Processing Result 285 8.1.7. Skip by hash 288 8.1.8. Get version of components 294 8.1.9. Configuration related APIs 296 8.1.10. Yara 424 8.1.11. Webhooks 431 8.2. MetaDefender API Code Samples 436 9. Advanced MetaDefender Deployment 438 9.1. Scripted license management 438 Requirements 438 Activation steps 438 Deactivation steps 440 Important notes 441 9.2. Deployment automation support 441 Installation 442 Initialization 442 Configuration 447 9.3. Cloud Deployment 447 9.3.1. AWS Deployment 447 9.4. Multi-node deployment 467 Setting up several Metadefender Core nodes 467 9.5. Using external load-balancer 471 9.5.1. HTTP(S) - Layer 7 load balancing 471 9.5.2. DNS load balancing 474 10. Troubleshooting MetaDefender Core 477 Installation issues 477 Issues with nodes 477 Where are the Metadefender Core logs located? 477 How can I create a support package? 477 Issues under high load 477 Debug logging 478 How to Create Support Package? 478 Creating the package on Linux 478 Creating the package on Windows 479 Content of the created package 479 How to Read the Metadefender Core Log? 480 Files 480 Format 480 Severity levels of log entries 480 Inaccessible Management Console 481 How to detect 481 Solution 481 Possible Issues on Nodes 481 Q. Node detected 3rd party product on system 481 Q. There is no scan node connected 482 Too Many Sockets or Files Open 482 How to detect 482 Solution 483 Too Many TIME_WAIT Socket 484 How to detect 484 Solution 484 Technical Insights 485 11. Release notes 487 11.1 Archived release notes 490 Version v4.17.2 490 Version v4.17.1 492 Version v4.17.0.1 493 Version v4.17.0 493 Version v4.16.3 495 Version v4.16.2 495 Version v4.16.1 496 Version v4.16.0 497 Version v4.15.2 497 Version v4.15.1 498 Version v4.15.0 499 Version v4.14.3 499 Version v4.14.2 500 Version v4.14.1 501 Version v4.14.0 501 Version v4.13.2 501 Version v4.13.1 501 Version v4.13.0 502 Version v4.12.2 502 Version v4.12.1 502 Version v4.12.0 503 Version v4.11.3 503 Version v4.11.2 503 Version v4.11.1 504 Version v4.11.0 504 Version v4.10.2 505 Version v4.10.1 505 Version v4.10.0 505 Version 4.9.1 506 Version 4.9.0 507 Version 4.8.2 507 Version 4.8.1 507 Version 4.7.2 509 Version 4.7.1 509 Version 4.6.3 510 Version 4.6.2 510 Version 4.6.1 510 Version 4.6.0 511 Version 4.5.1 512 Version 4.5.0 512 Version 4.4.1 512 Version 4.3.0 513 Version 4.2.0 514 Version 4.1.0 515 Version 4.0.1 515 Version 4.0.0 516 11.2 Proactive DLP Release Notes 516 v2.3.0 516 v2.2.1 516 v2.2 516 v2.1.2 517 v2.1.1 517 v2.1 517 v2.0.1 517 v2.0 517 v1.0.3 518 12. Legal 519 Copyright 519 DISCLAIMER OF WARRANTY 519 COPYRIGHT NOTICE 519 MetaDefender Export Classification 519 13. Knowledge Base Articles 521 Are MetaDefender Core v4 upgrades free? 523 Are there any limitations regarding the MetaDefender Core v4 scan engines? 523 Can I control access to the RAM disk in MetaDefender Core v4? 524 Does Metadefender Core v4 offer real-time antivirus protection on the system where it is installed? 524 Does MetaDefender Core v4 Detect the NotPetya Ransomware? 524 Does the fixing updates for Meltdown and Spectre vulnerabilities affect any engines in MetaDefender Core v4? 526 Engine clean-up instructions 527 External scanners in MetaDefender core v4.8.0 and above 530 How can I configure the maximum queue size in Metadefender Core v4 ? 533 How can I find a sanitized file scanned with MetaDefender Core v4? 534 How can I increase the scaling up performance? 534 How can I run tests to see the different scan results on MetaDefender Core v4? 537 How can I upgrade from Core v4.7.0/v4.7.1 to a newer Core v4.7 release 538 How can the TEMP folder be changed? 540 How do I check if "noexec" flag exists on a Linux OS? 541 How do I collect verbose debug packages on MetaDefender Core v4 for Linux? 542 How do I deploy MetaDefender Core v4 to an offline Linux environment? 543 Installing MetaDefender Core 544 Activate your license 544 Installing the MetaDefender Update Downloader utility 546 Applying offline updates 548 Contacting OPSWAT Support 548 How do I deploy MetaDefender Core v4 to an offline Windows environment? 549 Installing MetaDefender Core 549 Activate your license 550 Installing the MetaDefender Update Downloader utility 552 Applying offline updates 554 Contacting OPSWAT Support 555 How do I disable real-time protection of my anti-malware software if it is not allowed by corporate policy for use with MetaDefender Core v4? 555 How do I remove an engine from my MetaDefender v4 instance? 557 How do I use MetaDefender Core v4 Workflows ? 557 Defining and administering Workflow Templates in MetaDefender Core v4 558 How long is the support life cycle for a specific version/release of MetaDefender Core v4? 559 How to install MSE on Windows Server 2012 R2 and Windows Server 2016 561 MSE on Windows Server 2012 R2 561 MSE on Windows Server 2016 565 How to transfer your Metadefender Core v4 scan history database 571 Is Metadefender Core compromised while scanning files? 571 Is there a virus test I could use to test MetaDefender Core v4? 572 MetaDefender Core v4 shows a large number of files that failed to scan.