clamav检测
#安装epel扩展仓库
yum install epel-release -y
#安装clamav
yum -y install clamav-server clamav-data clamav-update \
clamav-filesystem clamav clamav-scanner-systemd clamav-devel \
clamav-lib clamav-server-systemd
直接扫描

配置文件扫描

最后更新于
#安装epel扩展仓库
yum install epel-release -y
#安装clamav
yum -y install clamav-server clamav-data clamav-update \
clamav-filesystem clamav clamav-scanner-systemd clamav-devel \
clamav-lib clamav-server-systemd


最后更新于
[root@wazuh-centos-agent opt]# touch /var/log/clamd.log
[root@wazuh-centos-agent opt]# chmod 666 /var/log/clamd.log[root@wazuh-centos-agent opt]# cat /etc/clamd.d/scan.conf
LogFile /var/log/clamd.log #clamav文件扫描日志
LogTime yes #记录时间
LogSyslog yes #记录到syslog
LogVerbose yes #记录详细信息
ExtendedDetectionInfo yes #记录扩展检测信息
LocalSocket /run/clamd.scan/clamd.sock #本地sock监听
LogRotate yes #轮转日志记录
LogFileMaxSize 20M #最大轮转容量记录为20M[root@wazuh-centos-agent opt]# /usr/sbin/clamd[root@wazuh-manager ~]# cat /var/ossec/etc/decoders/local_decoder.xml
<decoder name="virusFound">
<prematch>FOUND</prematch>
<regex>-> (\S+): (\S+)\((\S+)\)</regex>
<order>url, extra_data, id</order>
</decoder>[root@wazuh-manager ~]# cat /var/ossec/etc/rules/local_rules.xml
<group name="clamd">
<rule id="111001" level="0" noalert="1">
<decoded_as>virusFound</decoded_as>
<description>Clamd messages grouped.</description>
</rule>
<rule id="111002" level="8">
<if_sid>111001</if_sid>
<match>FOUND</match>
<description>ClamAV: Virus detected</description>
<group>virus</group>
</rule>
</group>[root@wazuh-manager ~]# cat /var/ossec/etc/shared/default/agent.conf
<agent_config>
<localfile>
<log_format>syslog</log_format>
<location>/var/log/clamd.log</location>
</localfile>
</agent_config>