All Products
Search
Document Center

Secure Access Service Edge:Configure terminal antivirus

Last Updated:Aug 21, 2026

The terminal antivirus feature integrates with the Alibaba Cloud malicious file detection service and automatically uses the latest antivirus engine versions to effectively protect your enterprise endpoints. This helps prevent significant business losses. This topic describes the supported detection items and scan methods, and explains how to create scan tasks, configure real-time protection, manage file blacklists/whitelists, and view scan results.

Supported detection items and scan methods

Category

Description

Detection items

You can scan for threats such as reverse shells, DDoS trojans, trojan downloaders, engine test programs, hacker tools, high-risk programs, tainted basic software, malicious scripts, malicious programs, mining programs, proxy tools, ransomware, riskware, rootkits, password stealers, scanners, suspicious programs, infectious viruses, webshells, worms, cracking programs, exploits, private server tools, adware, and malicious documents.

Scan methods

  • Quick scan

    Scans critical system paths, such as services, drivers, startup items, running processes, and download, desktop, and document directories.

  • Custom scan

    Scans specific paths that you define based on your business requirements.

  • Full disk scan

    Scans all files on the disk.

  • Real-time protection

    When a new file is saved to the disk or a new process starts, the system automatically triggers a real-time virus scan based on the configured detection items.

Create scan tasks and handling methods

To use the terminal antivirus feature, you must create a scan task and configure its scan method, Perf Preference, and handling method for malicious files. SASE then scans endpoints based on your task settings.

Create a scheduled scan task to scan your endpoints periodically. Create an on-demand scan task to scan your endpoints immediately. An on-demand scan task is valid for 24 hours after it starts. If a user does not sign in to the SASE client app during this 24-hour period, SASE does not scan their endpoint.

Scheduled task

  1. Sign in to the SASE console. In the left-side navigation pane, choose Endpoint Protection > Antivirus.

  2. On the Terminal Antivirus page, click Configure Policy.

  3. On the Scheduled Scan tab, click Create Scheduled Task.

  4. Configure the parameters for the scheduled task as described in the following table, and then click OK.

    Parameter

    Description

    Example

    Task Name

    The name of the policy.

    Antivirus_Policy_Test

    Description

    The description of the policy.

    This policy is used for antivirus scans on all company endpoints.

    Priority

    The priority of the policy.

    Valid values: 1 to 10. A smaller value indicates a higher priority.

    1

    Policy Status

    The policy applies only when it is enabled.

    Enabled

    Check Item

    You can scan for threats such as reverse shells, DDoS trojans, trojan downloaders, engine test programs, hacker tools, high-risk programs, tainted basic software, malicious scripts, malicious programs, mining programs, proxy tools, ransomware, riskware, rootkits, password stealers, scanners, suspicious programs, infectious viruses, webshells, and worms.

    Select All

    Scan Mode

    • Quick Scan

      Scans critical system paths, such as services, drivers, startup items, running processes, and download, desktop, and document directories.

    • Custom Scan

      Scans specific paths that you define based on your business requirements.

    • Full Disk Scan

      Scans all files on the disk.

    Quick scan

    Frequency

    The schedule for the scan.

    Every 3 days, 00:00-24:00

    Perf Preference

    • Experience First

      This mode uses fewer resources to ensure a smooth user experience. In extreme cases, the scan task may be paused or canceled.

    • Balanced Mode

      This mode balances resource allocation between work applications and security scans, completing the scan without affecting the user experience.

    • Security First

      This mode prioritizes completing the scan to ensure security, which may result in higher performance consumption.

    Experience First

    Handling Method

    Based on the file risk levels determined by the Alibaba Cloud malicious file detection service, you can configure a handling method for each risk level.

    • High

      Supports Notify User and Notify User and Quarantine Malicious Files.

    • Medium

      Supports Notify User and Notify User and Quarantine Malicious Files.

    • Low

      Supports Do Not Handle, Notify User, and Notify User and Quarantine Malicious Files.

    • High

      Notify User and Quarantine Malicious Files

    • Medium

      Notify User and Quarantine Malicious Files

    • Low

      Notify User

    Applicable User

    Specifies the users to whom the policy applies. You can select All Users or Some Users. If you select Some Users, you must select the user groups to include.

    All Users

    Exception User

    The users who are exempt from this policy. The policy does not apply to users added as exceptions.

    -

Scan now

  1. Sign in to the SASE console. In the left-side navigation pane, choose Endpoint Protection > Antivirus.

  2. In the Scan Task section, click Scan Now.

  3. Configure the Scan Now task as described in the following table, and then click OK.

    Parameter

    Description

    Example

    Task Name

    The name of the policy.

    Antivirus_Policy_Test

    Check Item

    You can scan for threats such as reverse shells, DDoS trojans, trojan downloaders, engine test programs, hacker tools, high-risk programs, tainted basic software, malicious scripts, malicious programs, mining programs, proxy tools, ransomware, riskware, rootkits, password stealers, scanners, suspicious programs, infectious viruses, webshells, and worms.

    Select All

    Scan Mode

    • Quick Scan

      Scans critical system paths, such as services, drivers, startup items, running processes, and download, desktop, and document directories.

    • Custom Scan

      Scans specific paths that you define based on your business requirements.

    • Full Disk Scan

      Scans all files on the disk.

    Quick scan

    Perf Preference

    • Experience First

      This mode uses fewer resources to ensure a smooth user experience. In extreme cases, the scan task may be paused or canceled.

    • Balanced Mode

      This mode balances resource allocation between work applications and security scans, completing the scan without affecting the user experience.

    • Security First

      This mode prioritizes completing the scan to ensure security, which may result in higher performance consumption.

    Experience First

    Handling Method

    • High

      Supports Notify User and Notify User and Quarantine Malicious Files.

    • Medium

      Supports Notify User and Notify User and Quarantine Malicious Files.

    • Low

      Supports Do Not Handle, Notify User, and Notify User and Quarantine Malicious Files.

    • High

      Notify User and Quarantine Malicious Files

    • Medium

      Notify User and Quarantine Malicious Files

    • Low

      Notify User

    Applicable User

    The users to whom the policy applies. You can select Certain Users or All Users. If you select Certain Users, you must select the User Group to include.

    All Users

    Exception User

    The users who are exempt from this policy. The policy does not apply to users added as exceptions.

    -

Real-time protection and handling methods

When a new file is saved to the disk or a new process starts on a client, the system triggers a real-time virus scan. Real-time monitoring helps you quickly detect potential security threats or attacks and take immediate action to block or mitigate them. This reduces the blast radius.

  1. Sign in to the SASE console. In the left-side navigation pane, choose Endpoint Protection > Antivirus.

  2. On the Terminal Antivirus page, click Configure Policy.

  3. On the Real-time Protection tab, click Modify Configuration Item, configure the parameters as described in the following table, and then click OK.

Parameter

Description

Policy Status

Enables or disables real-time protection.

Check Items

The threat types to detect. You can select multiple items.

Available threat types include reverse shells, DDoS trojans, trojan downloaders, engine test programs, hacker tools, high-risk programs, tainted basic software, malicious scripts, malicious programs, mining programs, proxy tools, ransomware, riskware, rootkits, password stealers, scanners, suspicious programs, infectious viruses, webshells, worms, cracking programs, exploits, private server tools, adware, and malicious documents.

Handling Method

Based on the file risk levels determined by the Alibaba Cloud malicious file detection service, you can configure a handling method for each risk level.

  • High

    Supports Notify User and Notify User and Quarantine Malicious Files.

  • Medium

    Supports Notify User and Notify User and Quarantine Malicious Files.

  • Low

    Supports Do Not Handle, Notify User, and Notify User and Quarantine Malicious Files.

Applicable User

The users to whom this policy applies.

  • Certain Users: Select the user groups to which the policy applies. You can select multiple user groups.

  • All Users: The policy applies to all users.

Exception User

The users who are exempt from this policy. The policy does not apply to users added as exceptions.

File blacklists and whitelists

The terminal antivirus feature allows you to add specific files to a blacklist/whitelist. For example, if you do not want to scan .exe files in the Windows operating system, you can add them to the whitelist. If you want to prohibit a specific file type on user endpoints, you can add it to the blacklist. When SASE detects a blacklisted file, it notifies the user or quarantines the file, depending on the handling method configured in your scan task.

  1. On the Terminal Antivirus page, click Configure Policy.

  2. On the Blacklist/Whitelist tab, configure file exceptions.

    You can add exceptions for files on Windows and macOS based on the following criteria:

    • File Name Extensions: The string after the last period (.) in a full file name.

      For example, the file name extension of scan_file.exe is exe.

    • File Name: The full name of the file, including its extension.

      For example, the file name is scan_file.exe.

    • Folder Path: The absolute path of the folder.

      For example, a folder path is C:\scan_dir.

    • File Path: The absolute path of the file.

      For example, a file path is C:\scan_dir\scan_file.exe.

    • File MD5: The MD5 hash of the file's content.

      For example, the file MD5 of scan_file.exe is 56486982bc352eb0e29efd54f7f0****.

Virus statistics

After you configure and run terminal antivirus policies, you can view the protection status of your endpoints on the **Terminal Antivirus** page.

By default, the Terminal Antivirus page displays virus statistics and distribution data from the last 30 days.

Section

Description

①

  • High-risk Virus: The number of unquarantined malicious files that the malicious file detection service has classified as high-risk.

    Click the number to view details about these files in the list in Section ⑤.

  • Quarantined File: The number of malicious files that SASE has quarantined based on your configured handling methods.

    Click the number to view all quarantined files. You can click Whitelist to restore a specific file.

②

  • Scan Task: Create an on-demand scan task, view all created tasks, and check the details of ongoing scans.

  • Antivirus engine version: The latest version of the antivirus engine from the malicious file detection service and its last update time.

③

  • Type Distribution: Statistics on the number of detected viruses by type.

  • Level Distribution: Statistics on the number of detected viruses by risk level.

④

Displays the top 5 devices and users with the most detected viruses.

Click Details to view virus counts for all devices and users.

⑤

  • Pending: A list of unquarantined malicious files that contain high-risk viruses.

    You must handle these high-risk files based on your business requirements. You can choose to Whitelist or Quarantine them.

  • Handled: A list of malicious files that SASE has quarantined, whitelisted, or failed to handle.

    • For quarantined files, you can restore them by clicking Whitelist.

    • For whitelisted files, you can click Remove from Whitelist to allow SASE to scan them again.

    • For files that SASE failed to handle, you can click Ignore to restore them after you confirm that they are safe.