Also I'm guessing it's easier for admins of mixed infra to have a single threat definition (ie. So your storage server catches the same threats as your endpoints)
5.1 Deploy anti-virus software on all systems commonly affected by malicious software (particularly personal computers and servers).
It's typically an ignorant CISO/CSO who wants to mark a checkbox...
Easier just to say "AV on everything".
At the same time, ClamAV has a terrifying CVE track record.
There's no upside, and all downside.
ClamAV: https://www.cvedetails.com/product/15657/Clamav-Clamav.html?...
Norton AV: https://www.cvedetails.com/product/398/Symantec-Norton-Antiv...
Windows Defender: https://www.cvedetails.com/product/9767/Microsoft-Windows-De...
It may be safer to say that the CVE record for most AV software isn't great.
Given that, a possible upside with ClamAV could be that you could verify the behaviour of the processes on the installed systems, to make sure you're up-to-date and have the correct software and signatures installed.
That's not unreasonable - Microsoft's software delivery pipeline should be trustworthy and their security reputation could be damaged if an issue were discovered here.
That’s true of everything installed on a system - if you don’t control the software you’re running, Defender is the least of your worries. Unless you’re doing a full analysis of every binary you’re trusting the source.
We’re in the middle of adopting HiTrust and I’ve been forced to install Cisco AMP on all of my servers. The product is absolute garbage and frequently eats up all available RAM, causing itself to crash and leave a core dump filling up my root partition.
The worst part? AMP on Linux is literally ClamAV plus a kernel module to monitor file access, network connections and process creation.
People don't give Microsoft money for a product that's not by Microsoft. If Microsoft offers one, and can even claim that they cover all platforms with one overarching offering, companies pay them for it.
You may not want a product like this on Linux. But if you do business in the DoD supply chain, even way down the chain, then you will be required to do so.
If you’re not vulnerable and don’t need the badge you can’t be taken seriously.
It’s all very amusing!
A good linux example would be httpd starting netcat that connects to a remote port. Or firefox spawning a bash shell. For windows a simple example would be when an office app starts wscript or powershell and that child process schedules taks, wmi, downloads a payload,etc... Those are simple examples but they track more complex attack scenarios, for cloud hosted solutions like defender atp and crowdstrike they also collect everything that happens on every device of every customer, so if they find new malware or an attacker with a certain TTP on one device, they will deploy rules to catch that for all their customers.
Though I have a hunch this won't be free software and will have all kinds of telemetry you can't disable.
The Linux ecoystem has consistently p it their fingers in their ears and stop informing the very real and long outstanding problems of malware and apts
Those are the options. Head completely in sand or get some sand in your eyes