Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Defender for Containers uses the Microsoft Defender Antivirus anti-malware engine to scan nodes for malicious files.
When malware is detected, Defender for Cloud generates security alerts that can be investigated and remediated in Defender for Cloud and Defender XDR. This article explains the prerequisites for malware scanning on Kubernetes nodes, how to review malware alerts in the Azure portal, and how to follow the recommended remediation steps.
Prerequisites
Before you begin, make sure that:
You have an Azure subscription. If you don’t have an Azure subscription, create a free Azure account before you begin.
Microsoft Defender for Cloud is enabled on your subscription with one of the following plans. If it isn't enabled, see Connect your Azure subscription.
- Defender for Containers
- Defender for Servers P2
Agentless scanning for machines is enabled.
Review and remediate Kubernetes node malware alerts
To review and remediate malware alerts for Kubernetes nodes, follow these steps:
Sign in to the Azure portal.
Go to Microsoft Defender for Cloud > Security alerts.
Select the relevant malware alert for the Kubernetes node.
Select View full details to review the detected malware, including affected node pools and malware files.
Select Next: Take Action >> to open the remediation guidance.
Follow the recommended steps to remediate the threat.