eicar.com file copied from Docker container to host volume is not immediately detected and removed
search cancel

eicar.com file copied from Docker container to host volume is not immediately detected and removed

book

Article ID: 176467

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

You have a Linux server running Docker Enterprise or Community Edition and Symantec Endpoint Protection (SEP) for Linux 14.2 RU2 or lower. When you create an eicar.com file in a Docker container and copy it to a Docker host volume, the file is not immediately detected and removed. The detection and removal does not occur until you perform an operation against the file that was copied to the Docker host volume.

Environment

  • SEP for Linux 14.2 or lower
  • Docker Enterprise or Community Edition

Resolution

This issue has been fixed in 14.2 RU2 MP1, by additionally monitoring for the API call triggered by the docker executable.