Defender for Storage alternative SMB scan

Luke Uhren 201 Reputation points
2022-06-14T17:11:46.237+00:00

I recently came into information that there are limitations with Azure Defender for Storage for files copied say via SMB. Example we have files that get copied via NFS on Linux and was wanting it to pick up infected files if possible.

I learned these are the limitations, so an alert will not fire if they are copied that way.

211339-image.png

https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-introduction#limitations-of-hash-reputation-analysis

I am wondering what other solutions people may have come up with for say scanning azure files other than azure defender for storage if they have these limitations? I can only think of other methods like this https://github.com/Azure/azure-storage-av-automation

Although, I am curious if there is anyone else that has a solid method they used and just seeing what else is out there,.

Thanks

Azure Files
Azure Files
An Azure service that offers file shares in the cloud.
1,360 questions
Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
3,366 questions
{count} votes

1 answer

Sort by: Most helpful
  1. SaiKishor-MSFT 17,326 Reputation points
    2022-06-24T22:22:47.87+00:00

    @Luke Uhren Thanks for your patience while I was looking into your issue.

    I reached out to our internal PM team regarding this question. Currently, we do not have any particular solution that we are endorsing for this purpose. However, you can use any 3rd party virus scan products running in Azure VMs. Hope this helps.

    Please let us know if you have any further questions and we will be glad to assist you further. Thank you!

    Remember:

    Please accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer. Here is how.

    Want a reminder to come back and check responses? Here is how to subscribe to a notification.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.