Where exactly virus scanning is happening when a file uploaded via rest API. Could you someone help on this?

Hi, in Our organization we are using M-Files default rest API & a custom rest API. We have application & proxy server separate and both servers are defender Realtime scanning is enabled (as usual installation M-Files directory & process has been excluded from scanning), We are trying to find where exactly virus scanning is happening when a file uploaded via rest API. Could you someone help on this? (AMSI (Antimalware Scan Interface) is NOT enabled )

I tried to investigate this with help of process monitor tool in App & Proxy servers, but unable find any scan operation for uploaded files via rest API is happening.

Parents
  • Have you enabled the registry settings mentioned in the user guide under Antimalware support (on-premises only)?

    Based on that guidance I also think that AMSI needs to be enabled ("you must use an anti-virus software that is compatible with Windows Antimalware Scan Interface (AMSI)"), although this is not an area I'm deeply familiar with. If you need to verify this I recommend contacting M-Files Support.

  • Yes, AMSI need to be enabled and its under investigation, currently its not.
    Before that we are trying to find where the files are processing (App server directory or Proxy directory?) when a file uploaded via rest API. As we have Defender AV already exist in servers and Realtime scanning is enabled, there must be some OS level scanning happens before the file processing to Azure blob file data. Unfortunately we are unable to find the exact temp directory in server where M-Files temporary storing and processing.

Reply
  • Yes, AMSI need to be enabled and its under investigation, currently its not.
    Before that we are trying to find where the files are processing (App server directory or Proxy directory?) when a file uploaded via rest API. As we have Defender AV already exist in servers and Realtime scanning is enabled, there must be some OS level scanning happens before the file processing to Azure blob file data. Unfortunately we are unable to find the exact temp directory in server where M-Files temporary storing and processing.

Children
No Data