Can Azure Defender for storage find virus in encrypt files?

Hsuan-Kai Huang 21 Reputation points
2020-10-26T01:44:48+00:00

Hi team, we're evaluating Azure Defender for storage (https://learn.microsoft.com/en-us/azure/security-center/defender-for-storage-introduction) as a solution to help us find infected files reactively.

However, we do encrypt file at the application layer before being saved to the storage. Wonder if Azure Defender will be able to pick up the virus in this scenario.

Thanks!

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
2,534 questions
0 comments No comments
{count} votes

Accepted answer
  1. deherman-MSFT 34,356 Reputation points Microsoft Employee
    2020-10-26T16:53:28.967+00:00

    @Hsuan-Kai Huang To determine whether an uploaded file is suspicious, Azure Defender for Storage uses hash reputation analysis supported by Microsoft Threat Intelligence. The threat protection tools don’t scan the uploaded files, rather they examine the storage logs and compare the hashes of newly uploaded files with those of known viruses, trojans, spyware, and ransomware. Since the file you uploaded is encrypted, Azure Defender will not have any reputation of the file. You will need to scan the file prior to encrypting in your application. There are some other solutions posted in this thread which might be helpful for your use-case.

    -------------------------------

    Please don’t forget to "Accept the answer" and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

    0 comments No comments

0 additional answers

Sort by: Most helpful