How to perform malware scan for file uploaded to Sharepoint in realtime immediately

A, Shankar (Cognizant) 0 Reputation points
2025-10-10T15:02:21.1166667+00:00

Context: Looking for real-time scan on file uploaded to Sharepoint and getting the status of each file uploaded to SharePoint

Constraint1: We cant use Storage blob with Microsoft Defender for Cloud (MDC)

Constraint2: We cant use third party Virus scan Tools, as Black duck security reasons, also as an alternate we have AWS with guardduty to scan.

Requirement:

In Ms SharePoint, once the user uploads the files in a particular folder, immediately scanning should perform for Virus threat using MS Defender tool  & notify via email on the Virus Scan Status.

              We must ensure all the files are scanned, hence using MS Defender how can we be 100% guarantee(refer Tool1:MDO Section) that the file is scanned 

              and no threat found immediately (real-time), as we can’t rely on batch mode option like Purview log & other tools, as it takes 4 to 48 hours to get reflected on the infected files list.

      We are interested in individual file scan status with automation to scan 1000 files avg on a daily basis.

 

  • Tool1: MDO - Microsoft Defender office 365 :
  1. Microsoft Defender 365 virus detection engine scans files asynchronously
  2. Anti-malware heuristics determine the files to scan
  3. If the file meets the criteria for a scan, the virus detection engine scans the file.
  4. Only if virus found, then only property on file set to indicate the file is infected

 

  • Tool2: MDE - Microsoft Defender Endpoint Plan2 for API:
  1. Manually uploaded file in [via security.microsoft.com -> submission  page -> File tab] -  took 2 hours.
  2. In The submission of API using curl command to MDE isn’t working, as permission to SUBMIT/filewrite isn’t present for API WindowsDefenderATP                          Command Used:                                    curl -v --location --request POST 'https://api.securitycenter.microsoft.com/api/files/submitForAnalysis' \ --header "Authorization: Bearer ${access_token}" \ --header "Accept: application/json" \ --form File=@test.zip \ --form "FileName=test.zip" \ --form "Comment=Testing submission with verbose mode"
Microsoft Security | Microsoft Defender | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.