Metadefender Core V4.11.1
Total Page:16
File Type:pdf, Size:1020Kb
MetaDefender Core v4.11.1 © 2018 OPSWAT, Inc. All rights reserved. OPSWAT®, MetadefenderTM and the OPSWAT logo are trademarks of OPSWAT, Inc. All other trademarks, trade names, service marks, service names, and images mentioned and/or used herein belong to their respective owners. Table of Contents About This Guide 13 Key Features of Metadefender Core 14 1. Quick Start with Metadefender Core 15 1.1. Installation 15 Operating system invariant initial steps 15 Basic setup 16 1.1.1. Configuration wizard 16 1.2. License Activation 22 1.3. Scan Files with Metadefender Core 22 2. Installing or Upgrading Metadefender Core 23 2.1. Recommended System Requirements 23 System Requirements For Server 23 Browser Requirements for the Metadefender Core Management Console 25 2.2. Installing Metadefender 26 Installation 26 Installation notes 26 2.2.1. Installing Metadefender Core using command line 26 2.2.2. Installing Metadefender Core using the Install Wizard 28 2.3. Upgrading MetaDefender Core 28 Upgrading from MetaDefender Core 3.x 28 Upgrading from MetaDefender Core 4.x 28 2.4. Metadefender Core Licensing 29 2.4.1. Activating Metadefender Licenses 29 2.4.2. Checking Your Metadefender Core License 35 2.5. Performance and Load Estimation 36 What to know before reading the results: Some factors that affect performance 36 How test results are calculated 37 Test Reports 37 Performance Report - Multi-Scanning On Linux 37 Performance Report - Multi-Scanning On Windows 41 2.6. Special installation options 46 Use RAMDISK for the tempdirectory 46 3. Configuring Metadefender Core 50 3.1. Management Console 50 3.2. Metadefender Configuration 51 3.2.1. Startup Core Configuration 51 3.2.2. Startup Node Configuration 55 3.3. User management 58 3.3.1. Users and groups 58 3.3.2. Roles 63 3.3.3. User directories 65 3.3.4. Active Directory attributes 73 3.3.5. Change user password 76 3.4. Update settings 77 Internet 78 Folder 79 Manual 79 3.5. Clean up scan database 80 Technology Note: 80 3.6. Policies configuration 80 3.6.1. How MetaDefender Core policies work 81 3.6.2. Workflow template configuration 81 3.6.3. Security zone configuration 94 3.6.4. Workflow rule configuration 94 3.7. Logging 98 3.7.1. Configuration 99 3.7.2. Debug logging 99 3.8. Enabling HTTPS 100 Enabling HTTPS via Management Console 100 Enabling HTTPS via configuration files 102 3.9. Configuring proxy settings 104 How can I set proxy server for the product 104 3.10. External Scanners And Post Actions 104 External Scanners 105 Post Actions 108 4. Scan files with Metadefender Core 111 Scan Files via REST API 111 Scan Files via Web Interface 112 Choose what to scan and how 112 Start scanning 112 Progress of scanning 112 5. Data Sanitization 114 6. Operating Metadefender Core 115 6.1. Dashboard 115 Overview page 115 Scan history 116 Quarantine 116 Update history 116 6.2. Inventory Management 117 Certificates 117 Engines 120 Nodes 127 Whitelist (by hash) 129 6.3. Regular Maintenance 131 Checking for Upgrades 131 Checking Engines / Databases Health 131 6.4 Import/Export configuration 131 Export 132 Import 132 Note 132 7. Metadefender Core Developer Guide 133 How to Interact with Metadefender Core using REST 133 File scan process 133 7.1. MetaDefender API Code Samples 133 Activate License Online 134 Successful response 134 Error response 135 Cancel Batch 135 Cancel Scan Batch 135 Close Batch 137 Close Scan Batch 137 Download Batch Signed Result 138 Download Batch Signed Result 138 Download Sanitized Files 141 Download Sanitized Files Using Data Id 141 Error response 141 Fetching Available Scan Rules 142 Successful response 143 Error response 143 Fetching Engine/Database Versions 144 Successful response 144 Error response 145 Fetch Scan Result 146 Retrieving Scan Reports Using Data ID 146 Successful response 146 Successful response with archive detection 151 Response (not existing data_id) 153 Error response 153 Fetch Scan Result by File Hash 153 Retrieve Scan Results Using Hash 153 Request http header parameters 154 The retrieved result is always the most recent for the processed item, if rule is set then it will be the most recent - if exists - under the given rule. 154 Successful response 154 Successful response with archive detection 158 Response (not existing hash) 160 Error response 160 Get Current License Information 160 Successful response 161 Error response 161 Get Product Version 162 Successful response 162 Error response 163 Initiate Batch 163 Initiate Scan Batch 163 Login / Create a Session 164 Successful response 165 Error response 165 Logout / Destroy a Session 166 Successful response 166 Error response 166 Scan A File 167 Successful response 168 Error response 168 Scan file in batch 169 Scan file in batch 169 Status of Batch 170 Status of Scan Batch 170 Uploading License Key File 171 Successful response 172 Error response 172 Vulnerability Info In Scan Result 173 Example 173 8. Advanced Metadefender Deployment 177 8.1. Scripted license management 177 Requirements 177 Activation steps 177 Deactivation steps 178 Important notes 180 8.2. Multi-node deployment 180 Setting up several Metadefender Core nodes 180 8.3. Using external load-balancer 183 8.3.1. HTTP(S) - Layer 7 load balancing 183 8.3.2. DNS load balancing 186 9. Troubleshooting Metadefender Core 190 Installation issues 190 Issues with nodes 190 Where are the Metadefender Core logs located? 190 How can I create a support package? 190 Issues under high load 190 How to Create Support Package? 191 Creating the package on Linux 191 Creating the package on Windows 191 Content of the created package 192 How to Read the Metadefender Core Log? 192 Files 192 Format 192 Severity levels of log entries 193 Inaccessible Management Console 193 How to detect 193 Solution 193 Possible Issues on Nodes 194 Q. Node detected 3rd party product on system 194 Q. There is no scan node connected 194 Too Many Sockets or Files Open 195 How to detect 195 Solution 195 Too Many TIME_WAIT Socket 196 How to detect 196 Solution 196 Technical Insights 197 10. Release notes 198 Version v4.11.1 198 Version v4.11.0 198 Version v4.10.2 198 Version v4.10.1 199 Version v4.10.0 199 Version 4.9.1 200 Version 4.9.0 200 Version 4.8.2 201 Version 4.8.1 201 Version 4.7.2 203 Version 4.7.1 203 Version 4.6.3 204 Version 4.6.2 204 Version 4.6.1 204 Version 4.6.0 205 Version 4.5.1 206 Version 4.5.0 206 Version 4.4.1 207 Version 4.3.0 207 Version 4.2.0 208 Version 4.1.0 209 Version 4.0.1 209 Version 4.0.0 210 11. Metadefender / Client 211 About This Guide 211 Key Features of MetaDefender Client 211 Supported Operating Systems 211 1. MetaDefender Client Packages 212 MetaDefender Free Client 212 MetaDefender Premium Client 212 2. MetaDefender Premium Client 213 2.1 Install using the Install Wizard 213 2.2 Install using the Command Line 215 2.3 Using the MetaDefender Premium Client 216 2.4 Configuring through the config file 231 2.5 Configuring through Central Management 238 3. MetaDefender Free Client 243 4. Command Line Interface 243 Example: 243 Command Line Options 243 4.1 Generating and using the Administrator Password 247 5. MetaDefender Client Release Notes 249 Tips and Known Issues 249 4.1.6 Release 250 4.1.5 Release 250 4.1.4 Release 251 4.1.3 Release 251 4.1.2 Release 251 4.1.1 Release 252 4.1.0 Release 252 4.0.18 Release 253 4.0.17 Release 253 4.0.16 Release 253 4.0.15 Release 254 4.0.14 Release 254 4.0.13 Release 255 4.0.12 Release 255 4.0.11 Release 255 4.0.10 Release 256 4.0.9 Release 257 4.0.8 Release 257 4.0.7 Release 257 4.0.6 Release 257 4.0.5 Release 258 4.0.4 Release (Internal Only) 258 4.0.3 Release 258 4.0.2 Release 259 4.0.1 Release 259 4.0.0 Release 260 Changes in 3.12.5 260 12. Legal 261 Copyright 261 DISCLAIMER OF WARRANTY 261 COPYRIGHT NOTICE 261 Export Classification EAR99 261 13. Knowledge Base Articles 262 Are MetaDefender Core v4 upgrades free? 263 Are there any dependencies that need to be fulfilled for MetaDefender Core v4 engines ? 263 Does Metadefender Core v4 offer real-time antivirus protection on the system where it is installed? 264 Does MetaDefender Core v4 Detect the NotPetya Ransomware? 264 Does the fixing updates for Meltdown and Spectre vulnerabilities affect any engines in MetaDefender Core v4? 267 External scanners in MetaDefender core v4.8.0 and above 268 How can I configure the maximum queue size in MetaDefender Core v4 ? 270 How can I find a sanitized file scanned with MetaDefender Core v4? 271 How can I increase the scaling up performance? 272 How can I upgrade from Core v4.7.0/v4.7.1 to a newer Core v4.7 release 274 How can the TEMP folder be changed? 275 How do I collect verbose debug packages on MetaDefender Core v4 for Linux? 276 How do I deploy MetaDefender Core v4 to an offline Linux environment? 277 Installing MetaDefender Core 277 Activate your license 278 Installing the MetaDefender Update Downloader utility 279 Applying offline updates 281 Contacting OPSWAT Support 282 How do I deploy MetaDefender Core v4 to an offline Windows environment? 282 Installing MetaDefender Core 283 Activate your license 283 Installing the MetaDefender Update Downloader utility 284 Applying offline updates 286 Contacting OPSWAT Support 287 How do I disable real-time protection of my anti-malware software if it is not allowed by corporate policy for use with MetaDefender Core v4? 287 How do I remove an engine from my MetaDefender v4 instance? 289 How do I use MetaDefender Core v4 Workflows ? 289 Defining and administering Workflow Templates in MetaDefender Core v4 290 How long is the support life cycle for a specific version/release of MetaDefender Core v4? 291 Is action needed because Metadefender v4's AVG license is expiring on 2018-06-15? 293 What do I need to do? 293 What if I don't take action by June 15, 2018? 293 Why is the license for AVG expiring? 294 What if I need more assistance from OPSWAT on this topic? 294 Is there a virus test I could use to test MetaDefender Core v4? 294 MetaDefender Core v4 shows a large number of files that failed to scan.