Additional Microsoft Defender tools and services that provide security across various platforms and environments
How to perform malware scan for file uploaded to Sharepoint in realtime immediately
Context: Looking for real-time scan on file uploaded to Sharepoint and getting the status of each file uploaded to SharePoint
Constraint1: We cant use Storage blob with Microsoft Defender for Cloud (MDC)
Constraint2: We cant use third party Virus scan Tools, as Black duck security reasons, also as an alternate we have AWS with guardduty to scan.
Requirement:
In Ms SharePoint, once the user uploads the files in a particular folder, immediately scanning should perform for Virus threat using MS Defender tool & notify via email on the Virus Scan Status.
We must ensure all the files are scanned, hence using MS Defender how can we be 100% guarantee(refer Tool1:MDO Section) that the file is scanned
and no threat found immediately (real-time), as we can’t rely on batch mode option like Purview log & other tools, as it takes 4 to 48 hours to get reflected on the infected files list.
We are interested in individual file scan status with automation to scan 1000 files avg on a daily basis.
- Tool1: MDO - Microsoft Defender office 365 :
- Microsoft Defender 365 virus detection engine scans files asynchronously
- Anti-malware heuristics determine the files to scan
- If the file meets the criteria for a scan, the virus detection engine scans the file.
- Only if virus found, then only property on file set to indicate the file is infected
- Tool2: MDE - Microsoft Defender Endpoint Plan2 for API:
- Manually uploaded file in [via security.microsoft.com -> submission page -> File tab] - took 2 hours.
- In The submission of API using curl command to MDE isn’t working, as permission to SUBMIT/filewrite isn’t present for API WindowsDefenderATP Command Used: curl -v --location --request POST 'https://api.securitycenter.microsoft.com/api/files/submitForAnalysis' \ --header "Authorization: Bearer ${access_token}" \ --header "Accept: application/json" \ --form File=@test.zip \ --form "FileName=test.zip" \ --form "Comment=Testing submission with verbose mode"