Metadefender Core V4.13.1
Total Page:16
File Type:pdf, Size:1020Kb
MetaDefender Core v4.13.1 © 2018 OPSWAT, Inc. All rights reserved. OPSWAT®, MetadefenderTM and the OPSWAT logo are trademarks of OPSWAT, Inc. All other trademarks, trade names, service marks, service names, and images mentioned and/or used herein belong to their respective owners. Table of Contents About This Guide 13 Key Features of Metadefender Core 14 1. Quick Start with Metadefender Core 15 1.1. Installation 15 Operating system invariant initial steps 15 Basic setup 16 1.1.1. Configuration wizard 16 1.2. License Activation 21 1.3. Scan Files with Metadefender Core 21 2. Installing or Upgrading Metadefender Core 22 2.1. Recommended System Requirements 22 System Requirements For Server 22 Browser Requirements for the Metadefender Core Management Console 24 2.2. Installing Metadefender 25 Installation 25 Installation notes 25 2.2.1. Installing Metadefender Core using command line 26 2.2.2. Installing Metadefender Core using the Install Wizard 27 2.3. Upgrading MetaDefender Core 27 Upgrading from MetaDefender Core 3.x 27 Upgrading from MetaDefender Core 4.x 28 2.4. Metadefender Core Licensing 28 2.4.1. Activating Metadefender Licenses 28 2.4.2. Checking Your Metadefender Core License 35 2.5. Performance and Load Estimation 36 What to know before reading the results: Some factors that affect performance 36 How test results are calculated 37 Test Reports 37 Performance Report - Multi-Scanning On Linux 37 Performance Report - Multi-Scanning On Windows 41 2.6. Special installation options 46 Use RAMDISK for the tempdirectory 46 3. Configuring Metadefender Core 50 3.1. Management Console 50 3.2. Metadefender Configuration 51 3.2.1. Startup Core Configuration 51 3.2.2. Startup Node Configuration 55 3.2.3 Nginx related configuration 58 3.3. User management 58 3.3.1. Users and groups 59 3.3.2. Roles 64 3.3.3. User directories 66 3.3.4. Active Directory attributes 74 3.3.5. Change user password 77 3.4. Update settings 78 Internet 79 Folder 80 Manual 80 3.5. Clean up scan database 81 Technology Note: 81 3.6. Policies configuration 81 3.6.1. How MetaDefender Core policies work 82 3.6.2. Workflow template configuration 82 3.6.3. Security zone configuration 95 3.6.4. Workflow rule configuration 95 3.6.5. Quarantine 100 3.7. Logging 100 3.7.1. Configuration 101 3.7.2. Debug logging 101 3.8 Security settings on web console 102 3.8.1 Enabling HTTPS 102 3.8.2 Session timeout 106 3.9. Configuring proxy settings 107 How can I set proxy server for the product 107 3.10. External Scanners And Post Actions 108 External Scanners 108 Post Actions 111 3.11. Yara rule sources 113 4. Scan files with Metadefender Core 115 Scan Files via REST API 115 Scan Files via Web Interface 116 Choose what to scan and how 116 Start scanning 116 Progress of scanning 116 5. Data Sanitization 118 6. Operating Metadefender Core 119 6.1. Dashboard 119 Overview page 119 Scan history 120 Quarantine 120 Update history 120 6.2. Inventory Management 121 Certificates 121 Nodes 124 Skip by hash 126 Technologies 128 6.3. Regular Maintenance 136 Checking for Upgrades 136 Checking Engines / Databases Health 136 6.4 Import/Export configuration 136 Export 137 Import 137 Note 137 7. Metadefender Core Developer Guide 138 How to Interact with Metadefender Core using REST 138 File scan process 138 7.1. MetaDefender API Code Samples 138 Activate License Online 139 Successful response 139 Error response 140 Cancel Batch 140 Cancel Scan Batch 140 Cancel File Scan 142 Cancel Scan File 142 Close Batch 143 Close Scan Batch 143 Download Batch Signed Result 144 Download Batch Signed Result 144 Download Sanitized Files 147 Download Sanitized Files Using Data Id 147 Error response 147 Fetching Available Scan Rules 148 Successful response 149 Error response 150 Fetching Engine/Database Versions 150 Successful response 150 Error response 151 Fetch Scan Result 152 Retrieving Scan Reports Using Data ID 152 Successful response 152 Successful response with archive detection 158 Response (not existing data_id) 160 Error response 160 Fetch Scan Result by File Hash 161 Retrieve Scan Results Using Hash 161 Request http header parameters 161 The retrieved result is always the most recent for the processed item, if rule is set then it will be the most recent - if exists - under the given rule. 161 Successful response 161 Successful response with archive detection 165 Response (not existing hash) 167 Error response 167 Get Current License Information 168 Successful response 168 Error response 169 Get Product Version 169 Successful response 170 Error response 170 Initiate Batch 171 Initiate Scan Batch 171 Login / Create a Session 172 Successful response 172 Error response 173 Logout / Destroy a Session 173 Successful response 174 Error response 174 Scan A File 174 Successful response 175 Error response 175 Scan file in batch 176 Scan file in batch 176 Status of Batch 177 Status of Scan Batch 177 Uploading License Key File 178 Successful response 179 Error response 179 Vulnerability Info In Scan Result 180 Example 180 8. Advanced Metadefender Deployment 184 8.1. Scripted license management 184 Requirements 184 Activation steps 184 Deactivation steps 186 Important notes 187 8.2. Multi-node deployment 187 Setting up several Metadefender Core nodes 187 8.3. Using external load-balancer 190 8.3.1. HTTP(S) - Layer 7 load balancing 191 8.3.2. DNS load balancing 193 8.4. Cloud Deployment 196 8.4.1. AWS Deployment 196 9. Troubleshooting Metadefender Core 217 Installation issues 217 Issues with nodes 217 Where are the Metadefender Core logs located? 217 How can I create a support package? 217 Issues under high load 217 How to Create Support Package? 218 Creating the package on Linux 218 Creating the package on Windows 218 Content of the created package 219 How to Read the Metadefender Core Log? 219 Files 219 Format 219 Severity levels of log entries 220 Inaccessible Management Console 220 How to detect 220 Solution 220 Possible Issues on Nodes 221 Q. Node detected 3rd party product on system 221 Q. There is no scan node connected 221 Too Many Sockets or Files Open 222 How to detect 222 Solution 222 Too Many TIME_WAIT Socket 223 How to detect 223 Solution 223 Technical Insights 224 10. Release notes 225 Version v4.13.1 225 Version v4.13.0 225 Version v4.12.2 225 Version v4.12.1 226 Version v4.12.0 226 Version v4.11.3 227 Version v4.11.2 227 Version v4.11.1 227 Version v4.11.0 228 Version v4.10.2 228 Version v4.10.1 228 Version v4.10.0 229 Version 4.9.1 230 Version 4.9.0 230 Version 4.8.2 231 Version 4.8.1 231 Version 4.7.2 232 Version 4.7.1 233 Version 4.6.3 234 Version 4.6.2 234 Version 4.6.1 234 Version 4.6.0 235 Version 4.5.1 236 Version 4.5.0 236 Version 4.4.1 236 Version 4.3.0 237 Version 4.2.0 238 Version 4.1.0 239 Version 4.0.1 239 Version 4.0.0 240 11. Metadefender / Client 241 About This Guide 241 Key Features of MetaDefender Client 241 Supported Operating Systems 241 1. MetaDefender Client Packages 242 MetaDefender Free Client 242 MetaDefender Premium Client 242 2. MetaDefender Premium Client 243 2.1 Install using the Install Wizard 243 2.2 Install using the Command Line 245 2.3 Using the MetaDefender Premium Client 246 2.4 Configuring through the config file 261 2.5 Configuring through Central Management 268 3. MetaDefender Free Client 273 4. Command Line Interface 273 Example: 273 Command Line Options 273 4.1 Generating and using the Administrator Password 277 5. MetaDefender Client Release Notes 279 Tips and Known Issues 279 5.1. Archived MetaDefender Client Release Notes 281 12. Legal 293 Copyright 293 DISCLAIMER OF WARRANTY 293 COPYRIGHT NOTICE 293 Export Classification EAR99 293 13. Knowledge Base Articles 294 Are MetaDefender Core v4 upgrades free? 295 Are there any dependencies that need to be fulfilled for MetaDefender Core v4 engines ? 295 Does Metadefender Core v4 offer real-time antivirus protection on the system where it is installed? 296 Does MetaDefender Core v4 Detect the NotPetya Ransomware? 296 Does the fixing updates for Meltdown and Spectre vulnerabilities affect any engines in MetaDefender Core v4? 299 External scanners in MetaDefender core v4.8.0 and above 300 How can I configure the maximum queue size in MetaDefender Core v4 ? 302 How can I find a sanitized file scanned with MetaDefender Core v4? 303 How can I increase the scaling up performance? 304 How can I upgrade from Core v4.7.0/v4.7.1 to a newer Core v4.7 release 306 How can the TEMP folder be changed? 307 How do I collect verbose debug packages on MetaDefender Core v4 for Linux? 308 How do I deploy MetaDefender Core v4 to an offline Linux environment? 309 Installing MetaDefender Core 309 Activate your license 310 Installing the MetaDefender Update Downloader utility 311 Applying offline updates 313 Contacting OPSWAT Support 314 How do I deploy MetaDefender Core v4 to an offline Windows environment? 314 Installing MetaDefender Core 315 Activate your license 315 Installing the MetaDefender Update Downloader utility 316 Applying offline updates 318 Contacting OPSWAT Support 319 How do I disable real-time protection of my anti-malware software if it is not allowed by corporate policy for use with MetaDefender Core v4? 319 How do I remove an engine from my MetaDefender v4 instance? 321 How do I use MetaDefender Core v4 Workflows ? 321 Defining and administering Workflow Templates in MetaDefender Core v4 322 How long is the support life cycle for a specific version/release of MetaDefender Core v4? 323 Is action needed because Metadefender v4's AVG license is expiring on 2018-06-15? 325 What do I need to do? 325 What if I don't take action by June 15, 2018? 325 Why is the license for AVG expiring? 325 What if I need more assistance from OPSWAT on this topic? 326 Is there a virus test I could use to test MetaDefender Core v4? 326 MetaDefender Core v4 shows a large number of files that failed to scan.