Does Microsoft Defender for Endpoint on Linux Quick Scan re-scan mounted directories after a reboot or engine update?

2026-09-14T02:45:24.4466667+00:00

I would like to confirm the behavior and design specifications of Quick Scan in Microsoft Defender for Endpoint on Linux.

Environment

  • OS: Linux
  • Microsoft Defender for Endpoint for Linux deployed
  • Quick Scan configured to run on a scheduled basis

Observed Behavior

Historically, Quick Scan has scanned approximately 10,000 files per execution. However, after applying OS patches and rebooting the server, the subsequent Quick Scan scanned approximately 5 million files.

Questions

Does Quick Scan in Microsoft Defender for Endpoint for Linux re-evaluate or re-scan areas that have previously been scanned after a system reboot, Defender engine update, or security intelligence update?

Is there a published list of directories that are included in a Quick Scan on Linux?

  • If so, where can this information be found?
    • Can the set of directories targeted by Quick Scan change depending on the Defender version?
    During a Quick Scan, can files located under NFS, SMB/CIFS, or other mounted file systems be scanned?
    - If so, under what conditions?
    
    What factors could cause the number of scanned files during a Quick Scan to increase significantly, for example from approximately 10,000 files to approximately 5 million files?
    
    Is there a log, diagnostic method, or other mechanism that can be used to identify the actual file paths scanned during a Quick Scan?
    

Based on the public documentation, my understanding is that Quick Scan focuses on locations where malware is commonly executed, loaded, or registered. However, I would like to better understand the possible causes of the substantial increase in the number of scanned files observed in this case.

Thank you for your assistance.I would like to confirm the behavior and design specifications of Quick Scan in Microsoft Defender for Endpoint on Linux.

Environment

  • OS: Linux
  • Microsoft Defender for Endpoint for Linux deployed
  • Quick Scan configured to run on a scheduled basis

Observed Behavior

Historically, Quick Scan has scanned approximately 10,000 files per execution. However, after applying OS patches and rebooting the server, the subsequent Quick Scan scanned approximately 5 million files.

Questions

Does Quick Scan in Microsoft Defender for Endpoint for Linux re-evaluate or re-scan areas that have previously been scanned after a system reboot, Defender engine update, or security intelligence update?

Is there a published list of directories that are included in a Quick Scan on Linux?

  • If so, where can this information be found?
    • Can the set of directories targeted by Quick Scan change depending on the Defender version?
    During a Quick Scan, can files located under NFS, SMB/CIFS, or other mounted file systems be scanned?
    - If so, under what conditions?
    
    What factors could cause the number of scanned files during a Quick Scan to increase significantly, for example from approximately 10,000 files to approximately 5 million files?
    
    Is there a log, diagnostic method, or other mechanism that can be used to identify the actual file paths scanned during a Quick Scan?
    

Based on the public documentation, my understanding is that Quick Scan focuses on locations where malware is commonly executed, loaded, or registered. However, I would like to better understand the possible causes of the substantial increase in the number of scanned files observed in this case.

Thank you for your assistance.

Microsoft Security | Microsoft Defender | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.