Public | Automated Build

Last pushed: 10 days ago
Short Description
Malice Windows Defender AntiVirus Plugin
Full Description

malice-windows-defender





This repository contains a Dockerfile of Windows Defender for Docker's trusted build published to the public DockerHub.

:warning: NOTE: Will not work on Docker for Mac because CONFIG_MODIFY_LDT_SYSCALL is not enabled :warning:

Dependencies

Installation

  1. Install Docker.
  2. Download trusted build from public docker store: docker pull malice/windows-defender

Usage

docker run --init --rm malice/windows-defender EICAR

Or link your own malware folder:

$ docker run --init --rm -v /path/to/malware:/malware:ro malice/windows-defender FILE

Usage: windows-defender [OPTIONS] COMMAND [arg...]

Malice Windows Defender AntiVirus Plugin

Version: v0.1.0, BuildTime: 20170527

Author:
  blacktop - <https://github.com/blacktop>

Options:
  --verbose, -V         verbose output
  --table, -t            output as Markdown table
  --callback, -c    POST results to Malice webhook [$MALICE_ENDPOINT]
  --proxy, -x            proxy settings for Malice webhook endpoint [$MALICE_PROXY]
  --timeout value       malice plugin timeout (in seconds) (default: 60) [$MALICE_TIMEOUT]    
  --elasitcsearch value elasitcsearch address for Malice to store results [$MALICE_ELASTICSEARCH]   
  --help, -h            show help
  --version, -v            print the version

Commands:
  update    Update virus definitions
  web           Create a windows-defender scan web service  
  help        Shows a list of commands or help for one command

Run 'windows-defender COMMAND --help' for more information on a command.

This will output to stdout and POST to malice results API webhook endpoint.

Sample Output

JSON:

{
  "windows-defender": {
    "infected": true,
    "result": "Virus:DOS/EICAR_Test_File",
    "engine": "0.1.0",
    "updated": "20170527"
  }
}

STDOUT (Markdown Table):


Windows Defender

Infected Result Engine Updated
true Virus:DOS/EICAR_Test_File 0.1.0 20170527

Documentation

Issues

Find a bug? Want more features? Find something missing in the documentation? Let me know! Please don't hesitate to file an issue.

CHANGELOG

See CHANGELOG.md

Contributing

See all contributors on GitHub.

Please update the CHANGELOG.md and submit a Pull Request on GitHub.

Credit

Made possible by the awesome work by @taviso

License

MIT Copyright (c) 2017 blacktop

Docker Pull Command
Owner
malice

Comments (0)