# Linux Defend doesn't detect EICAR

**URL:** <https://discuss.elastic.co/t/linux-defend-doesnt-detect-eicar/362647>\
**Category:** Endpoint Security\
**Created:** [July 6, 2024, 3:28pm UTC](https://discuss.elastic.co/t/linux-defend-doesnt-detect-eicar/362647 "2024-07-06T15:28:36Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![FranklinFurter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/franklinfurter/32/122338_2.png) [@FranklinFurter](https://discuss.elastic.co/u/FranklinFurter)\
**Post date:** [July 6, 2024, 3:28pm UTC](https://discuss.elastic.co/t/linux-defend-doesnt-detect-eicar/362647/1 "2024-07-06T15:28:36Z")

</div>

I've been testing out Elastic Endpoint/Defend for Linux and i'm not sure if it's not setup correctly or what. The standard test of downloading the eicar file (of various forms) didn't trigger the malware sigantures for defend. I have it configured to scan on file modification. I tried opening the eicar in an editor and re-saving it and stuff, but nothing could trigger the defend signature.

While it does send the information regarding process create and stuff back to ELASTIC, i'm interested in the AV/memory protection components. How do i know if those are working? Why would it not identify the basic EICAR?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 6, 2024, 4:15pm UTC](https://discuss.elastic.co/t/linux-defend-doesnt-detect-eicar/362647/2 "2024-07-06T16:15:33Z")

</div>

From #Elastic Security to #Endpoint Security

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [July 8, 2024, 10:05am UTC](https://discuss.elastic.co/t/linux-defend-doesnt-detect-eicar/362647/3 "2024-07-08T10:05:41Z")

</div>

Hi @FranklinFurter

Could you let me know a little more about your setup?

What type of Linux are you running?  
What Kernel Version?  
What File System is this happening on?  
How are you downloading the EICAR file (what program or command)?  
What editor are you using to open and re-save the file?

Based on what you're describing, I would expect you to see Malware Detection Alerts for at least some of the activity.

---

<div class="post-metadata">

**Author:** ![FranklinFurter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/franklinfurter/32/122338_2.png) [@FranklinFurter](https://discuss.elastic.co/u/FranklinFurter)\
**Post date:** [July 13, 2024, 3:01am UTC](https://discuss.elastic.co/t/linux-defend-doesnt-detect-eicar/362647/4 "2024-07-13T03:01:01Z")

</div>

Hey Nick, sure:

Linux: Ubuntu 22.04.4 LTS  
Kernel: 6.5.0-41-generic #41~22.04.2-Ubuntu SMP PREEMPT\_DYNAMIC Mon Jun 3 11:32:55 UTC 2 x86\_64 x86\_64 x86\_64 GNU/Linux  
File System: zfs  
How: Browsing to eicar website and downloading the different test files (.com/txt/zip) via chrome.  
Editor: I'm using vim when i edit the file.

I agree i'd expect to see some alert. I do see an alert when trying this on Windows, but no alert on Linux. Also unfortunate for the windows side is that alert is well after downloading. For that I mean, when Windows Defender catches eicar, it also tells me things like what the mark of the web was for it, the tempdir it was found in, etc. When Elastic Endpoint Security catches it (on windows) it finds it in the end directory after it's been "moved" and provides no information about the mark of the web or parent process that wrote it, though that would be discoverable if all the auditing features are turned on i'd suspect.

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [July 15, 2024, 12:41pm UTC](https://discuss.elastic.co/t/linux-defend-doesnt-detect-eicar/362647/5 "2024-07-15T12:41:22Z")

</div>

Thanks @FranklinFurter

You're probably seeing this because of your ZFS filesystem. ZFS is not currently on the list of default file systems that Defend monitors on linux. You can add it using the advanced options section of policy as described here: [Configure Linux file system monitoring | Elastic Security Solution [8.14] | Elastic](https://www.elastic.co/guide/en/security/current/linux-file-monitoring.html)

You specifically will want to edit `linux.advanced.fanotify.monitored_filesystems`

I believe if you set that you will start to see the events you're looking for.

---

<div class="post-metadata">

**Author:** ![FranklinFurter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/franklinfurter/32/122338_2.png) [@FranklinFurter](https://discuss.elastic.co/u/FranklinFurter)\
**Post date:** [July 19, 2024, 5:20pm UTC](https://discuss.elastic.co/t/linux-defend-doesnt-detect-eicar/362647/6 "2024-07-19T17:20:19Z")

</div>

> [@NickFritts](#):
>
> linux.advanced.fanotify.monitored\_filesystems

Great, that seems to have fixed it. There's two things that don't seem to be working as i'd expect still:

1. I didn't get any elastic notification in Gnome that it found/removed something.
2. The alert in the elastic backend doesn't contain any information about the signature. The only thing i can find is the information of the process it came from and what file was flagged, but i couldn't find any reference to EICAR. If this were a real virus, it would be helpful to know what signature caused this alert.

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [July 19, 2024, 6:08pm UTC](https://discuss.elastic.co/t/linux-defend-doesnt-detect-eicar/362647/7 "2024-07-19T18:08:35Z")

</div>

Unfortunately the user notifications for Linux go to syslog. It was the best solution we could come up with at the time based on the varied number of desktop environments and Linux versions that we support.

For what its worth, partially because of your question we're looking to extend our automated testing to include additional file systems (including ZFS) so that if everything looks good they'll end up moving to the default list of file systems and no longer need the advanced option to monitor.

For # 2, I'll look in to that. I believe the rule name is supposed to be there, if it's not, that may be a bug.

---

<div class="post-metadata">

**Author:** ![FranklinFurter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/franklinfurter/32/122338_2.png) [@FranklinFurter](https://discuss.elastic.co/u/FranklinFurter)\
**Post date:** [July 20, 2024, 12:57am UTC](https://discuss.elastic.co/t/linux-defend-doesnt-detect-eicar/362647/8 "2024-07-20T00:57:08Z")

</div>

would definitely be good to support ZFS out of the box. from my perspective it's become pretty popular and is a direct filesystem option when installing ubuntu these days.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2024, 12:57am UTC](https://discuss.elastic.co/t/linux-defend-doesnt-detect-eicar/362647/9 "2024-08-17T00:57:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
