Metadefender Core V4.16.1
Total Page:16
File Type:pdf, Size:1020Kb
MetaDefender Core v4.16.1 © 2018 OPSWAT, Inc. All rights reserved. OPSWAT®, MetadefenderTM and the OPSWAT logo are trademarks of OPSWAT, Inc. All other trademarks, trade names, service marks, service names, and images mentioned and/or used herein belong to their respective owners. Table of Contents About This Guide 12 Key Features of MetaDefender Core 13 1. Quick Start with MetaDefender Core 14 1.1. Installation 14 Operating system invariant initial steps 14 Basic setup 15 1.1.1. Configuration wizard 15 1.2. License Activation 20 1.3. Process Files with MetaDefender Core 20 2. Installing or Upgrading MetaDefender Core 21 2.1. System Requirements 21 System Requirements For Server 21 Browser Requirements for the Metadefender Core Management Console 25 2.2. Installing MetaDefender 26 Installation 26 Installation notes 26 2.2.1. Installing Metadefender Core using command line 26 2.2.2. Installing Metadefender Core using the Install Wizard 29 2.3. Upgrading MetaDefender Core 29 Upgrading from MetaDefender Core 3.x 29 Upgrading from MetaDefender Core 4.x 30 2.4. MetaDefender Core Licensing 30 2.4.1. Activating Metadefender Licenses 30 2.4.2. Checking Your Metadefender Core License 36 2.5. Performance and Load Estimation 37 What to know before reading the results: Some factors that affect performance 37 How test results are calculated 38 Test Reports 38 Performance Report - Multi-Scanning On Linux 38 Performance Report - Multi-Scanning On Windows 42 2.6. Special installation options 45 Use RAMDISK for the tempdirectory 45 3. Configuring MetaDefender Core 49 3.1. Management Console 49 3.1.1. Password Recovery 50 3.2. MetaDefender Configuration 57 3.2.1. Startup Core Configuration 58 3.2.2. Startup Node Configuration 62 3.2.3 Nginx related configuration (for API Rate Limiting) 68 3.3. User management 70 3.3.1. Users and groups 70 3.3.2. Roles 75 3.3.3. User directories 77 3.3.4. Active Directory attributes 85 3.3.5. Change user password 88 3.4. Update settings 89 Internet 90 Folder 91 Manual 91 3.5. Clean up scan database 92 Technology Note: 92 3.6. Policy configuration 92 3.6.1. How MetaDefender Core policies work 93 3.6.2. Workflow template configuration 93 3.6.3. Security zone configuration 107 3.6.4. Workflow rule configuration 108 3.6.5. Quarantine 113 3.7. Logging 121 3.7.1. Configuration 121 3.7.2 Log message format 122 3.7.3 Syslog message format 123 3.7.4 Error Message Description Table 127 3.8 Security settings on web console 168 3.8.1 Enabling HTTPS 168 3.8.2 Session timeout 172 3.8.3 Password Policy 173 3.9. Configuring proxy settings 174 How can I set proxy server for the product 174 3.10. External Scanners And Post Actions 175 External Scanners 175 Post Actions 178 3.11. Yara rule sources 180 3.12. Configuring mail settings 183 Server configuration 183 User authentication 184 4. Process files with MetaDefender Core 185 Process Files via REST API 185 Process Files via Web Interface 186 Choose what to process and how 186 Start processing 187 Progress of scanning 187 5. Deep CDR (Data Sanitization) 188 6. Proactive DLP 189 Detect and then block approach 189 Prevent and then allow approach 189 6.1 Detect sensitive information 189 Sensitive Data 189 Certainty score 190 Supported File Types 190 6.2 Redact sensitive information 192 Supported File Types 192 Supported Sensitive Information 192 To set redaction 192 6.3 Remove metadata 194 Supported File Types 194 To set remove metadata 194 6.4 Watermark images 195 Supported File Types 195 To set watermark 195 7. Operating MetaDefender Core 198 7.1. Dashboard 198 Overview page 198 Scan history 199 Quarantine 199 Update history 200 7.2. Inventory Management 200 Certificates 200 Modules 203 Nodes 212 Skip by hash 214 7.3. Regular Maintenance 216 Checking for Upgrades 216 Checking Engines / Databases Health 216 7.4 Import/Export configuration 217 Export 217 Import 217 Note 218 8. MetaDefender Core Developer Guide 219 How to Interact with MetaDefender Core using REST 219 File scan process 219 8.1. MetaDefender API 219 8.1.1. Sessions 220 8.1.2. Licensing 223 8.1.3. Processing files 227 8.1.4. Processing files in batch 249 8.1.5. Download Sanitized Files 261 8.1.6. Vulnerability Info In Processing Result 263 8.1.7. Skip by hash 266 8.1.8. Get version of components 272 8.1.9. Configuration related APIs 275 8.1.10. Yara 403 8.2. MetaDefender API Code Samples 410 9. Advanced MetaDefender Deployment 412 9.1. Scripted license management 412 Requirements 412 Activation steps 412 Deactivation steps 414 Important notes 415 9.2. Deployment automation support 415 Installation 416 Initialization 416 Configuration 420 9.3. Cloud Deployment 420 9.3.1. AWS Deployment 420 9.4. Multi-node deployment 441 Setting up several Metadefender Core nodes 441 9.5. Using external load-balancer 445 9.5.1. HTTP(S) - Layer 7 load balancing 445 9.5.2. DNS load balancing 447 10. Troubleshooting MetaDefender Core 451 Installation issues 451 Issues with nodes 451 Where are the Metadefender Core logs located? 451 How can I create a support package? 451 Issues under high load 451 Debug logging 452 How to Create Support Package? 452 Creating the package on Linux 452 Creating the package on Windows 453 Content of the created package 453 How to Read the Metadefender Core Log? 454 Files 454 Format 454 Severity levels of log entries 454 Inaccessible Management Console 455 How to detect 455 Solution 455 Possible Issues on Nodes 455 Q. Node detected 3rd party product on system 455 Q. There is no scan node connected 456 Too Many Sockets or Files Open 456 How to detect 456 Solution 457 Too Many TIME_WAIT Socket 458 How to detect 458 Solution 458 Technical Insights 459 11. Release notes 461 11.1 Archived release notes 463 Version v4.16.0 463 Version v4.15.2 463 Version v4.15.1 464 Version v4.15.0 464 Version v4.14.3 465 Version v4.14.2 466 Version v4.14.1 466 Version v4.14.0 467 Version v4.13.2 467 Version v4.13.1 467 Version v4.13.0 468 Version v4.12.2 468 Version v4.12.1 468 Version v4.12.0 469 Version v4.11.3 469 Version v4.11.2 469 Version v4.11.1 470 Version v4.11.0 470 Version v4.10.2 471 Version v4.10.1 471 Version v4.10.0 471 Version 4.9.1 472 Version 4.9.0 473 Version 4.8.2 473 Version 4.8.1 473 Version 4.7.2 475 Version 4.7.1 475 Version 4.6.3 476 Version 4.6.2 476 Version 4.6.1 476 Version 4.6.0 477 Version 4.5.1 478 Version 4.5.0 478 Version 4.4.1 478 Version 4.3.0 479 Version 4.2.0 480 Version 4.1.0 481 Version 4.0.1 481 Version 4.0.0 482 11.2 Proactive DLP Release Notes 482 v2.0.1 482 v2.0 482 v1.0.3 482 12. Legal 483 Copyright 483 DISCLAIMER OF WARRANTY 483 COPYRIGHT NOTICE 483 Export Classification EAR99 483 13. Knowledge Base Articles 484 Are MetaDefender Core v4 upgrades free? 485 Are there any dependencies that need to be fulfilled for MetaDefender Core v4 engines ? 485 Does Metadefender Core v4 offer real-time antivirus protection on the system where it is installed? 486 Does MetaDefender Core v4 Detect the NotPetya Ransomware? 487 Does the fixing updates for Meltdown and Spectre vulnerabilities affect any engines in MetaDefender Core v4? 489 External scanners in MetaDefender core v4.8.0 and above 490 How can I configure the maximum queue size in Metadefender Core v4 ? 492 How can I find a sanitized file scanned with MetaDefender Core v4? 493 How can I increase the scaling up performance? 494 How can I upgrade from Core v4.7.0/v4.7.1 to a newer Core v4.7 release 496 How can the TEMP folder be changed? 497 How do I collect verbose debug packages on MetaDefender Core v4 for Linux? 498 How do I remove an engine from my MetaDefender v4 instance? 499 How do I use MetaDefender Core v4 Workflows ? 500 Defining and administering Workflow Templates in MetaDefender Core v4 500 How long is the support life cycle for a specific version/release of MetaDefender Core v4? 502 How to install MSE on Windows Server 2012 R2 and Windows Server 2016 504 MSE on Windows Server 2012 R2 504 MSE on Windows Server 2016 508 How to transfer your Metadefender Core v4 scan history database 514 Is action needed because Metadefender v4's AVG license is expiring on 2018-06-15? 514 What do I need to do? 515 What if I don't take action by June 15, 2018? 515 Why is the license for AVG expiring? 515 What if I need more assistance from OPSWAT on this topic? 515 Is Metadefender Core compromised while scanning files? 516 Is there a virus test I could use to test MetaDefender Core v4? 516 MetaDefender Core v4 shows a large number of files that failed to scan. What can I do? 516 Post actions in MetaDefender core V4.8.0 and above 518 Queue mechanism on Metadefender Core v4 520 Queue mechanism in general 520 Queue size for requests 520 Limit of concurrent connections 520 Max file size allowed 521 Using MetaDefender core V4 BLACKLIST/WHITELIST feature 521 Using filetype groups VS.