The terminal antivirus feature integrates with the Alibaba Cloud malicious file detection service and automatically uses the latest antivirus engine versions to effectively protect your enterprise endpoints. This helps prevent significant business losses. This topic describes the supported detection items and scan methods, and explains how to create scan tasks, configure real-time protection, manage file blacklists/whitelists, and view scan results.
Supported detection items and scan methods
|
Category |
Description |
|
Detection items |
You can scan for threats such as reverse shells, DDoS trojans, trojan downloaders, engine test programs, hacker tools, high-risk programs, tainted basic software, malicious scripts, malicious programs, mining programs, proxy tools, ransomware, riskware, rootkits, password stealers, scanners, suspicious programs, infectious viruses, webshells, worms, cracking programs, exploits, private server tools, adware, and malicious documents. |
|
Scan methods |
|
Create scan tasks and handling methods
To use the terminal antivirus feature, you must create a scan task and configure its scan method, Perf Preference, and handling method for malicious files. SASE then scans endpoints based on your task settings.
Create a scheduled scan task to scan your endpoints periodically. Create an on-demand scan task to scan your endpoints immediately. An on-demand scan task is valid for 24 hours after it starts. If a user does not sign in to the SASE client app during this 24-hour period, SASE does not scan their endpoint.
Scheduled task
-
Sign in to the SASE console. In the left-side navigation pane, choose .
-
On the Terminal Antivirus page, click Configure Policy.
-
On the Scheduled Scan tab, click Create Scheduled Task.
-
Configure the parameters for the scheduled task as described in the following table, and then click OK.
Parameter
Description
Example
Task Name
The name of the policy.
Antivirus_Policy_Test
Description
The description of the policy.
This policy is used for antivirus scans on all company endpoints.
Priority
The priority of the policy.
Valid values: 1 to 10. A smaller value indicates a higher priority.
1
Policy Status
The policy applies only when it is enabled.
Enabled
Check Item
You can scan for threats such as reverse shells, DDoS trojans, trojan downloaders, engine test programs, hacker tools, high-risk programs, tainted basic software, malicious scripts, malicious programs, mining programs, proxy tools, ransomware, riskware, rootkits, password stealers, scanners, suspicious programs, infectious viruses, webshells, and worms.
Select All
Scan Mode
-
Quick Scan
Scans critical system paths, such as services, drivers, startup items, running processes, and download, desktop, and document directories.
-
Custom Scan
Scans specific paths that you define based on your business requirements.
-
Full Disk Scan
Scans all files on the disk.
Quick scan
Frequency
The schedule for the scan.
Every 3 days, 00:00-24:00
Perf Preference
-
Experience First
This mode uses fewer resources to ensure a smooth user experience. In extreme cases, the scan task may be paused or canceled.
-
Balanced Mode
This mode balances resource allocation between work applications and security scans, completing the scan without affecting the user experience.
-
Security First
This mode prioritizes completing the scan to ensure security, which may result in higher performance consumption.
Experience First
Handling Method
Based on the file risk levels determined by the Alibaba Cloud malicious file detection service, you can configure a handling method for each risk level.
-
High
Supports Notify User and Notify User and Quarantine Malicious Files.
-
Medium
Supports Notify User and Notify User and Quarantine Malicious Files.
-
Low
Supports Do Not Handle, Notify User, and Notify User and Quarantine Malicious Files.
-
High
Notify User and Quarantine Malicious Files
-
Medium
Notify User and Quarantine Malicious Files
-
Low
Notify User
Applicable User
Specifies the users to whom the policy applies. You can select All Users or Some Users. If you select Some Users, you must select the user groups to include.
All Users
Exception User
The users who are exempt from this policy. The policy does not apply to users added as exceptions.
-
-
Scan now
-
Sign in to the SASE console. In the left-side navigation pane, choose .
-
In the Scan Task section, click Scan Now.
-
Configure the Scan Now task as described in the following table, and then click OK.
Parameter
Description
Example
Task Name
The name of the policy.
Antivirus_Policy_Test
Check Item
You can scan for threats such as reverse shells, DDoS trojans, trojan downloaders, engine test programs, hacker tools, high-risk programs, tainted basic software, malicious scripts, malicious programs, mining programs, proxy tools, ransomware, riskware, rootkits, password stealers, scanners, suspicious programs, infectious viruses, webshells, and worms.
Select All
Scan Mode
-
Quick Scan
Scans critical system paths, such as services, drivers, startup items, running processes, and download, desktop, and document directories.
-
Custom Scan
Scans specific paths that you define based on your business requirements.
-
Full Disk Scan
Scans all files on the disk.
Quick scan
Perf Preference
-
Experience First
This mode uses fewer resources to ensure a smooth user experience. In extreme cases, the scan task may be paused or canceled.
-
Balanced Mode
This mode balances resource allocation between work applications and security scans, completing the scan without affecting the user experience.
-
Security First
This mode prioritizes completing the scan to ensure security, which may result in higher performance consumption.
Experience First
Handling Method
-
High
Supports Notify User and Notify User and Quarantine Malicious Files.
-
Medium
Supports Notify User and Notify User and Quarantine Malicious Files.
-
Low
Supports Do Not Handle, Notify User, and Notify User and Quarantine Malicious Files.
-
High
Notify User and Quarantine Malicious Files
-
Medium
Notify User and Quarantine Malicious Files
-
Low
Notify User
Applicable User
The users to whom the policy applies. You can select Certain Users or All Users. If you select Certain Users, you must select the User Group to include.
All Users
Exception User
The users who are exempt from this policy. The policy does not apply to users added as exceptions.
-
-
Real-time protection and handling methods
When a new file is saved to the disk or a new process starts on a client, the system triggers a real-time virus scan. Real-time monitoring helps you quickly detect potential security threats or attacks and take immediate action to block or mitigate them. This reduces the blast radius.
-
Sign in to the SASE console. In the left-side navigation pane, choose .
-
On the Terminal Antivirus page, click Configure Policy.
-
On the Real-time Protection tab, click Modify Configuration Item, configure the parameters as described in the following table, and then click OK.
|
Parameter |
Description |
|
Policy Status |
Enables or disables real-time protection. |
|
Check Items |
The threat types to detect. You can select multiple items. Available threat types include reverse shells, DDoS trojans, trojan downloaders, engine test programs, hacker tools, high-risk programs, tainted basic software, malicious scripts, malicious programs, mining programs, proxy tools, ransomware, riskware, rootkits, password stealers, scanners, suspicious programs, infectious viruses, webshells, worms, cracking programs, exploits, private server tools, adware, and malicious documents. |
|
Handling Method |
Based on the file risk levels determined by the Alibaba Cloud malicious file detection service, you can configure a handling method for each risk level.
|
|
Applicable User |
The users to whom this policy applies.
|
|
Exception User |
The users who are exempt from this policy. The policy does not apply to users added as exceptions. |
File blacklists and whitelists
The terminal antivirus feature allows you to add specific files to a blacklist/whitelist. For example, if you do not want to scan .exe files in the Windows operating system, you can add them to the whitelist. If you want to prohibit a specific file type on user endpoints, you can add it to the blacklist. When SASE detects a blacklisted file, it notifies the user or quarantines the file, depending on the handling method configured in your scan task.
-
On the Terminal Antivirus page, click Configure Policy.
-
On the Blacklist/Whitelist tab, configure file exceptions.
You can add exceptions for files on Windows and macOS based on the following criteria:
-
File Name Extensions: The string after the last period (.) in a full file name.
For example, the file name extension of
scan_file.exeisexe. -
File Name: The full name of the file, including its extension.
For example, the file name is
scan_file.exe. -
Folder Path: The absolute path of the folder.
For example, a folder path is
C:\scan_dir. -
File Path: The absolute path of the file.
For example, a file path is
C:\scan_dir\scan_file.exe. -
File MD5: The MD5 hash of the file's content.
For example, the file MD5 of
scan_file.exeis56486982bc352eb0e29efd54f7f0****.
-
Virus statistics
After you configure and run terminal antivirus policies, you can view the protection status of your endpoints on the **Terminal Antivirus** page.
By default, the Terminal Antivirus page displays virus statistics and distribution data from the last 30 days.
|
Section |
Description |
|
① |
|
|
② |
|
|
③ |
|
|
④ |
Displays the top 5 devices and users with the most detected viruses. Click Details to view virus counts for all devices and users. |
|
⑤ |
|