How can I enable third party anti-virus signatures within Warden to improve the ClamAV detection rate?

Warden supports enabling third party anti-virus signatures to improve the detection rate. These signatures can block phishing, double attachments, macro malware, javascript malware, zero-day malware and even on zero-hour malware. Full documentation about each provider can be found below:

  1. Navigate to Warden Anti-spam and Virus Protection -> Settings -> Anti-virus Settings -> Signature Providers
  2. We recommend enabling at least the SaneSecurity and URLhaus providers. If you want the very best protection and have the server memory then we also recommend enabling the SecuriteInfo provider. Additionally SecuriteInfo paid signatures are very reasonable and well worth it at only €29 per year for up to 10 servers. Paid plans can add the securiteinfo.mdb and securiteinfo0hour.hdb files from the SecuriteInfo provider files select list to download additional generic and 0-hour anti-virus signatures. Users can purchase the SecuriteInfo signatures here after creating an account, logging in, and pressing the subscribe button in the client area.
  3. Press the update button on the page then the restart button to restart the Anti-virus signature service. You can view the signature download logs under Warden Anti-spam and Virus Protection -> Logs -> Signature log.
  4. Once the new signatures have been downloaded to the /var/lib/clamav/ directory they will be loaded into ClamAV within the hour. You can press the Signature widget reload button on the dashboard or issue the command clamdscan --reload if you want to load them earlier.

  • signatures, anti-virus
  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

How can I change the interface language of the extension?

You can change the interface language under Settings -> Application Settings -> Locale...

Why isn't autolearning working for me (autolearn=no) ?

Lots of people seem to be confused by the "autolearn=no" statement in the default X-Spam-Status...

How can I disable admin email notifications in Amavis?

Amavis has different default options for controlling where virus, spam, banned file attachments,...

Where are the configuration files for Warden located?

Centos/RHEL/CloudLinux/AlmaLinux Configuration files: // amavis (Content Filter Settings)...

How can I override the score for a specific rule in Warden?

To Override a Rule Score Navigate to Warden -> Rules -> Click on Add then select the...