Prove on-access scanning works, then show what an exclusion lets through
Task
Install an antivirus engine on lin-srv, prove it detects the EICAR test file both on demand and on access, then add a folder exclusion of the kind database servers need and show that the same file placed there is not detected. Exclusions are necessary; this lab shows exactly what each one costs.
Steps
- Update the signatures with
freshclamwhile briefly connected, then return lin-srv to the isolated network. - Create
/srv/incomingand/srv/dbdata. Copy the EICAR test string from the EICAR organisation's website into a file/srv/incoming/eicar-test.txtby hand. - Run
clamscan -r /srv/incomingand save the output tolab/av/on-demand.txt. - With on-access scanning enabled for
/srv, create the same file again and save the matching clamonacc or clamd log lines tolab/av/on-access.txt. - Add
/srv/dbdataas an on-access exclusion (OnAccessExcludePath /srv/dbdatain clamd.conf), restart the scanner, and create the test file in/srv/dbdata. Save any log output, or its absence, tolab/av/excluded.txt, and the configuration line tolab/av/exclusion.txt. - Record in
lab/av/exclusions-policy.txtthe three rules you would apply to every exclusion on a production server.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -Eic 'Eicar.*FOUND|Infected files: [1-9]' lab/av/on-demand.txt
grep -Eic 'eicar.*FOUND' lab/av/on-access.txt
grep -Eic 'eicar.*FOUND' lab/av/excluded.txt
grep -c '/srv/dbdata' lab/av/exclusion.txt
grep -Eic 'narrow|document|review|specific' lab/av/exclusions-policy.txt
The on-demand scan found the test file and the on-access scanner logged it, and the excluded folder produced no detection -- the third command prints 0. That zero is the lesson: anything placed in an excluded path is invisible to the scanner, so exclusions stay as narrow as the vendor's list, documented, and reviewed.
Notes
EDR products add behaviour-based detection that can still notice activity in an excluded folder, such as a process encrypting many files quickly. Signature scanning alone cannot.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.