Where exactly virus scanning is happening when a file uploaded via rest API. Could you someone help on this?

Hi, in Our organization we are using M-Files default rest API & a custom rest API. We have application & proxy server separate and both servers are defender Realtime scanning is enabled (as usual installation M-Files directory & process has been excluded from scanning), We are trying to find where exactly virus scanning is happening when a file uploaded via rest API. Could you someone help on this? (AMSI (Antimalware Scan Interface) is NOT enabled )

I tried to investigate this with help of process monitor tool in App & Proxy servers, but unable find any scan operation for uploaded files via rest API is happening.

Parents Reply
  • Yes, AMSI need to be enabled and its under investigation, currently its not.
    Before that we are trying to find where the files are processing (App server directory or Proxy directory?) when a file uploaded via rest API. As we have Defender AV already exist in servers and Realtime scanning is enabled, there must be some OS level scanning happens before the file processing to Azure blob file data. Unfortunately we are unable to find the exact temp directory in server where M-Files temporary storing and processing.

Children
No Data