Skip to content

malice-plugins/mcafee

Repository files navigation

malice-mcafee

Circle CI License Docker Stars Docker Pulls Docker Image

Malice McAfee AntiVirus Plugin

This repository contains a Dockerfile of mcafee.


Dependencies

Installation

  1. Install Docker.
  2. Download trusted build from public docker store: docker pull malice/mcafee

Usage

docker run --rm malice/mcafee EICAR

Or link your own malware folder:

$ docker run --rm -v /path/to/malware:/malware:ro malice/mcafee FILE

Usage: mcafee [OPTIONS] COMMAND [arg...]

Malice McAfee AntiVirus Plugin

Version: v0.1.0, BuildTime: 20180903

Author:
  blacktop - <https://github.com/blacktop>

Options:
  --verbose, -V          verbose output
  --elasticsearch value  elasticsearch url for Malice to store results [$MALICE_ELASTICSEARCH_URL]
  --table, -t            output as Markdown table
  --callback, -c         POST results back to Malice webhook [$MALICE_ENDPOINT]
  --proxy, -x            proxy settings for Malice webhook endpoint [$MALICE_PROXY]
  --timeout value        malice plugin timeout (in seconds) (default: 120) [$MALICE_TIMEOUT]
  --help, -h             show help
  --version, -v          print the version

Commands:
  update  Update virus definitions
  web     Create a McAfee scan web service
  help    Shows a list of commands or help for one command

Run 'mcafee COMMAND --help' for more information on a command.

Sample Output

{
  "mcafee": {
    "infected": true,
    "result": "EICAR test file",
    "engine": "5600.1067",
    "database": "9005",
    "updated": "20180903"
  }
}

McAfee

Infected Result Engine Updated
true EICAR test file 5600.1067 20180903

Documentation

Issues

Find a bug? Want more features? Find something missing in the documentation? Let me know! Please don't hesitate to file an issue.

TODO

  • add licence expiration detection

CHANGELOG

See CHANGELOG.md

Contributing

See all contributors on GitHub.

Please update the CHANGELOG.md and submit a Pull Request on GitHub.

License

MIT Copyright (c) 2017 blacktop