Hello everyone, I have some questions and need food for thought about clamAV. First, do you use it and why ? If yes, how are you running it ? I plan to maybe use it for nextcloud (and *arr stack later)

  • LunchMoneyThief@links.hackliberty.org
    link
    fedilink
    English
    arrow-up
    1
    ·
    17 days ago

    I do use ClamAV. Most users just run some sort of daily scan, but this is remedial and not preventative.

    In order to truly harness clamav’s potential, you need to configure clamonacc on-access scanning. It passes items off to clamd with lowered privileges and prevents file access through inotify until its realtime scan has cleared.

  • psmgx@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    24 days ago

    Antivirus as a thing is mostly dead, or has morphed into more aggressive endpoint protection. In that sense ClamAV is mostly to scan for known malware in things like mail servers. Make sure people aren’t sending malicious stuff, albeit mostly low hanging fruit.

    Nextcloud, wikis, or other similar aggregation sites are also a usecase, but again low hanging fruit.

    Set up a cron job and have it run periodically, like once an hour / day / week, whatever. Make sure you set up something that alerts you if/when it hits on something.