# Scanning the Host for malware

**URL:** <https://discuss.elastic.co/t/scanning-the-host-for-malware/369330>\
**Category:** Elastic Security\
**Created:** [October 24, 2024, 7:40am UTC](https://discuss.elastic.co/t/scanning-the-host-for-malware/369330 "2024-10-24T07:40:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [October 24, 2024, 7:40am UTC](https://discuss.elastic.co/t/scanning-the-host-for-malware/369330/1 "2024-10-24T07:40:19Z")

</div>

Hi Guys,

I'm trying to scan a host using response action.

looks like you can only scan a specific folder or directory rather than the entire host like C drive

is it possible to scan the entire host ?

And also where do you check the results of the scan after complete?

---

<div class="post-metadata">

**Author:** ![ashokaditya](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashokaditya/32/77783_2.png) [@ashokaditya](https://discuss.elastic.co/u/ashokaditya)\
**Post date:** [October 24, 2024, 9:21am UTC](https://discuss.elastic.co/t/scanning-the-host-for-malware/369330/2 "2024-10-24T09:21:12Z")

</div>

Hi Charles,

Thanks for reaching out. I presume you're trying the `scan` command via Responder? If yes, then it is indeed possible to scan the entire C drive. You should be able to enter a scan action like so, `scan --path "C:\"` and that should work. See screenshot.

#### Response console scan

 ![Response console scan](https://us1.discourse-cdn.com/elastic/original/3X/2/4/24ac49cc9b18a89c860ba043707a01d0ed4b2cf7.png)

A scan action result is going to generate an alert if a malicious file is found and you should see that alert on the **Alerts** page (`/app/security/alerts`). An alert is not generated otherwise. See the screenshot for such an alert.

#### Alert from scan

 ![Alert details](https://us1.discourse-cdn.com/elastic/original/3X/f/8/f8bf0aa68cb64c6324351c02e09084c299eaad42.png)

You can see the results of action requests, including the scan action, on the Response console, the Host's Details flyout for the host. Hosts are listed out on the Endpoint list page (`app/security/administration/endpoints`). You can also see the action's result on the **Response Actions History** page (`app/security/administration/response_actions_history`) by expanding the action item. See screenshots.

#### Response console history

 ![Response console history](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d58be585f2d5bf7e38953263ff5a2f66f34d597c.png)

#### Host details flyout

 ![Host details flyout](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c56c9e37c6ded5654f66daac3b5997dc18e222ca.png)

#### Response actions history page

 ![Response actions history page](https://us1.discourse-cdn.com/elastic/original/3X/9/3/93e50ccd26b6939b625625af7b5b38cff5a78b62.png)

Hope this helps, but please do reach out again if you need help.

---

<div class="post-metadata">

**Author:** ![Charles\_Nkuna](https://avatars.discourse-cdn.com/v4/letter/c/85e7bf/32.png) [@Charles\_Nkuna](https://discuss.elastic.co/u/Charles_Nkuna)\
**Post date:** [October 29, 2024, 7:49am UTC](https://discuss.elastic.co/t/scanning-the-host-for-malware/369330/3 "2024-10-29T07:49:18Z")

</div>

Hi,

i have tried to run the scan exactly the same way you advise its not completing the scan but stuck in a pending mode. any idea what might cause the issue ??

---

<div class="post-metadata">

**Author:** ![lesio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lesio/32/89323_2.png) [@lesio](https://discuss.elastic.co/u/lesio)\
**Post date:** [November 4, 2024, 9:11pm UTC](https://discuss.elastic.co/t/scanning-the-host-for-malware/369330/4 "2024-11-04T21:11:53Z")

</div>

Unfortunately we don't have any built-in means to observe the progress, neither end-to-end, nor on the endpoint. The action will remain pending in the UI until an outcome is received. It can be tricky as a large directory tree can take considerable time to get scanned.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 2, 2024, 9:12pm UTC](https://discuss.elastic.co/t/scanning-the-host-for-malware/369330/5 "2024-12-02T21:12:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
