11-21-2016 06:37 AM
Hi,
there were some info about the way how clamav is updated on ESA 10. But this is the first time I heard clamav is running on ESA.
Does anyone know what clamav is used for on ESA? Email scanning? Scanning system files? Something else?
Regrads,
Jernej
Solved! Go to Solution.
11-21-2016 07:48 AM
Hi Jerneg,
Cisco Advanced Malware Protection (AMP) includes a version of libclamav library.
ClamAV acts as a pre-classification engine for the AMP feature and reviews the attachments in the emails to determine if the file needs to be uploaded to the file analysis cloud server.
Async OS 10.0 for the ESA added feature - Improved AMP Reporting/Updateable ClamAV.
Prior to Async OS 10 AMP and ClamAV were not updateable from the cloud server. We now have command "ampstatus".
Thanks
Libin Varghese
11-21-2016 07:48 AM
Hi Jerneg,
Cisco Advanced Malware Protection (AMP) includes a version of libclamav library.
ClamAV acts as a pre-classification engine for the AMP feature and reviews the attachments in the emails to determine if the file needs to be uploaded to the file analysis cloud server.
Async OS 10.0 for the ESA added feature - Improved AMP Reporting/Updateable ClamAV.
Prior to Async OS 10 AMP and ClamAV were not updateable from the cloud server. We now have command "ampstatus".
Thanks
Libin Varghese
11-21-2016 08:31 PM
Hi Libin, thank you for explanation.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide