Additional Microsoft Defender tools and services that provide security across various platforms and environments
Does Microsoft Defender for Endpoint on Linux Quick Scan re-scan mounted directories after a reboot or engine update?
I would like to confirm the behavior and design specifications of Quick Scan in Microsoft Defender for Endpoint on Linux.
Environment
- OS: Linux
- Microsoft Defender for Endpoint for Linux deployed
- Quick Scan configured to run on a scheduled basis
Observed Behavior
Historically, Quick Scan has scanned approximately 10,000 files per execution. However, after applying OS patches and rebooting the server, the subsequent Quick Scan scanned approximately 5 million files.
Questions
Does Quick Scan in Microsoft Defender for Endpoint for Linux re-evaluate or re-scan areas that have previously been scanned after a system reboot, Defender engine update, or security intelligence update?
Is there a published list of directories that are included in a Quick Scan on Linux?
- If so, where can this information be found?
- Can the set of directories targeted by Quick Scan change depending on the Defender version?
- If so, under what conditions? What factors could cause the number of scanned files during a Quick Scan to increase significantly, for example from approximately 10,000 files to approximately 5 million files? Is there a log, diagnostic method, or other mechanism that can be used to identify the actual file paths scanned during a Quick Scan?
Based on the public documentation, my understanding is that Quick Scan focuses on locations where malware is commonly executed, loaded, or registered. However, I would like to better understand the possible causes of the substantial increase in the number of scanned files observed in this case.
Thank you for your assistance.I would like to confirm the behavior and design specifications of Quick Scan in Microsoft Defender for Endpoint on Linux.
Environment
- OS: Linux
- Microsoft Defender for Endpoint for Linux deployed
- Quick Scan configured to run on a scheduled basis
Observed Behavior
Historically, Quick Scan has scanned approximately 10,000 files per execution. However, after applying OS patches and rebooting the server, the subsequent Quick Scan scanned approximately 5 million files.
Questions
Does Quick Scan in Microsoft Defender for Endpoint for Linux re-evaluate or re-scan areas that have previously been scanned after a system reboot, Defender engine update, or security intelligence update?
Is there a published list of directories that are included in a Quick Scan on Linux?
- If so, where can this information be found?
- Can the set of directories targeted by Quick Scan change depending on the Defender version?
- If so, under what conditions? What factors could cause the number of scanned files during a Quick Scan to increase significantly, for example from approximately 10,000 files to approximately 5 million files? Is there a log, diagnostic method, or other mechanism that can be used to identify the actual file paths scanned during a Quick Scan?
Based on the public documentation, my understanding is that Quick Scan focuses on locations where malware is commonly executed, loaded, or registered. However, I would like to better understand the possible causes of the substantial increase in the number of scanned files observed in this case.
Thank you for your assistance.