Comment on Alternative to ClamAV?

NaibofTabr@infosec.pub ⁨1⁩ ⁨year⁩ ago

The core problem with this approach is that antivirus scanning is generally based on signature recognition of malicious binaries. Behavior-based antivirus scanning mostly doesn’t work and tends to generate a lot of false positives. No freely available antivirus is going to have a signature library that is kept up to date enough to be worth the effort of running it on Linux - most vulnerabilities are going to be patched long before a free service gets around to creating a signature for malware that exploits those vulnerabilities, at which point the signature would be moot. If you want antivirus that is kept up to date on a weekly or better basis, you’re going to have to pay for a professional service.

That said, there are other, simple (and probably more effective) options for hardening your systems:

source
Sort:hotnewtop