ISO and 7Z archive file scanning with the Anti-Malware Scan Engine 6.1.xx
Last Modified: 2022-03-31 18:56:20 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
ISO and 7Z archive file scanning with the Anti-Malware Scan Engine 6.1.xx
Technical Articles ID:
KB92712
Last Modified: 2022-03-31 18:56:20 Etc/GMT EnvironmentProducts the use the SummaryScan Engine 6.1.xx can now unpack and scan the contents inside the ISO and 7Z file types without any size limitations. The scanning of these file types is treated the same as any other archive scanning before them.
Limitations on 7Z and ISO file types scanning before Scan Engine 6.1.xx:
Frequently Asked Questions: Is there any performance impact by enabling scanning of 7Z and ISO archive files during on-access scan (OAS)? With size limitations removed, these files can impact performance and can affect normal functioning if continued to be scanned during OAS. So, OAS does not involve scanning inside archives by default. For more information about configuring and collecting statistics on OAS of a product, see KB69683 - FAQs for Profiler. Can you bypass detection by putting files in 7Z and ISO archives? Although 7Z and ISO files are not unpacked during an OAS, the content is scanned for any threats if extracted manually. Is there any performance impact with scanning 7Z and ISO archive files during ODS? ISO files can be large (GBs) and scanning for malicious content inside them can increase system scan time. But, scanning improves the detection efficacy. Can I prevent an ISO file from being scanned? Yes, by using either of the following methods:
Related InformationAffected ProductsLanguages:This article is available in the following languages: |
|