Malware Detection Module

11 articles in this topic.

Articles

BitNinja Malware signature system

Proactive Malware detection: Our Malware detection system is getting better and better. The BitNinja malware detection module, not just quarantines malware but also proactively in…

Does the Inotifywait process increase the server load? Change Inotify to AuditD

Info Inotify is the Malware Detection module’s filesystem monitoring tool. It detects if a file has been uploaded to the server or has been modified and triggers the Malware Detec…

Error: dispatch err (pipe full) event lost, dispatch error reporting limit reached - ending report notification

Info This error is because the q_depth value is to low. Increase the q_depth You just have to increase the q_depth value to solve the issue. Open the /etc/audisp/audispd.conf file…

Fine-tuning the Malware Detection / Scanner module

Inotify user Watches The Inotify user watches are increased by BitNinja to 30000000. In case you need to increase the value even further, you can use the echo 35000000 > /proc/sys…

How to add malware signatures to the BitNinja Malware database

If a malware’s signature is not in our malware signature database then BitNinja can not detect the malware. But you can easily add a malware signature to the database. And You can…

How to check if the Malware scan is running

Check the status of the Malware scanner from your Dashboard To monitor the ongoing malware scans on the servers, simply navigate to the Anti-Malware/Overview page. Check the curre…

MalwareDetection load optimization

If your server's load is high while the MalwareDetection module is enabled, follow this troubleshooting guide to resolve the issue. Find out what causes the issue. Inotifywait pro…

The Defense Robot module adds malware signatures

The Defense Robot module will add malware signatures to the Malware database. The malware signatures are generated from the files that were used to upload malware. To avoid any po…

The scheduled Malware scan didn't start on the server

Let's check You can check if the scheduled malware scan was complete or not in the /var/log/bitninja/mod.malware_scanner.log files ' date of creation or the timestamps in the log…

Validating suspicious files

Our Defense Robot module is proactively looking for backdoors and malware on the server. However, the file signatures generated by the Defense Robot are in a validating state by d…

Where can I find the malware BitNinja caught

You can find all the Malwares BitNinja caught on your servers under the Anti-Malware / Infected Files menu point on the Dashboard Go to the Anti-Malware menu point at the top of t…