Sign inSign up

omitsis/antivirus

By omitsis

•Updated over 2 years ago

Image
0

1.7K

omitsis/antivirus repository overview

⁠Omitsis Antivirus Scanner

⁠Overview

This Antivirus Scanner is a simple script designed to scan directories for viruses using ClamAV and custom Yara rules. It also reports the status of the scan to a specified healthchecks.io server, if provided.

⁠Features

  • Virus Detection: Uses ClamAV and custom Yara rules for detecting threats.
  • Automatic Updates: Updates virus definitions and Yara rules.
  • Remote Reporting: Sends scan results to a remote healthchecks.io server for monitoring.

⁠Usage

You can run it with docker easily:

docker run --rm --name antivirus -v $(pwd):/var/www -it antivirus:test omscan scan /var/www

Or you can use a docker-compose.yml file to schedule runs:

version: "3.9"

# Optional: Use volumes to persist data
volumes:
  clamav_data:
    name: clamav_data
  clamav_lwyara_data:
    name: clamav_lwyara_data

services:
  ofelia:
    image: mcuadros/ofelia:latest
    pull_policy: always
    command: daemon --docker
    restart: unless-stopped
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro

  antivirus:
    image: omitsis/antivirus:latest
    pull_policy: always
    container_name: antivirus
    restart: unless-stopped
    environment:
        HC_PING_HOST: https://hc-ping.com
        HC_PING_ID: xx2CEHTPO3K4L-xxxxx
    volumes:
      - /var/www:/var/www:ro
      - /etc/hostname:/etc/hostname:ro
      - clamav_data:/var/lib/clamav
      - clamav_lwyara_data:/var/lib/lw-yara
    labels:
      ofelia.enabled: "true"
      ofelia.job-exec.clamscan.schedule: "@daily"
      ofelia.job-exec.clamscan.command: "omscan scan /var/www"

⁠Environment variables configuration

  • HC_PING_ID: Set this to your hc⁠ project's Ping key for reporting. Checks will be automatically created using the hostname of the container. You can either pass the /etc/hostname or set a hostname to it.
  • HC_PING_HOST: Set this to your hc⁠ server ping URL. For example https://hc-ping.com (protocol needed).
  • CLAM_DB_CUSTOM_URL: A list of clam DatabaseCustomURL that will be added to freshclam.conf on startup. Separate with spaces.
    • Example: CLAM_DB_CUSTOM_URL="http://example.com/clamdb/custom.ndb http://example2.com/clamdb/custom2.ndb"

⁠Reporting

  • Reports are sent to a healthchecks⁠ server.
  • Ensure this URL is reachable from your network.
  • Ensure the PING_ID is the correct one (you can get it from project's settings).

⁠Usage

The script accepts the following commands:

  • wait: The script waits indefinitely, useful for daemonized containers. Then use somethign like ofelia for triggering the omscan scan <directory>.
  • update: Updates the virus databases and Yara rules.
  • scan [directory]: Scans the specified directory for viruses.
⁠Scanning

To scan a directory, run:

omscan scan /path/to/directory

Tag summary

Content type

Image

Digest

sha256:b61b098e7…

Size

19.6 MB

Last updated

over 2 years ago

docker pull omitsis/antivirus