Scanning for malware in files uploaded to Azure

Viewed 5709

I am building a .net app (Azure app service) with file upload feature that would upload pdf/docx files to Azure blob storage.

I was just wondering if a malicious user uploads a virus infected file, bad macro in word file, is Azure able to scan and remove/quarantine that file?

In the app, admin user will be able to download the file using a url. Will that file be virus free? Or do I need to explicitly call antivirus like Symantec End Point after the admin downloads the file.

Please let me know your expert thoughts.

3 Answers

There is an open source solution that my team implemented, Its a small antivirus system that sends all uploaded blobs from a specific container to antivirus scan (using VM with Microsoft defender) and the blob is moved based on the scan results to a different container. Also the remediation can be modified.

You can use that solution to send to scan each blob uploaded and download blobs only from a "clean-container".

here's a link to the repo azure-storage-av-automation.

Related