หมายเหตุ
การเข้าถึงหน้านี้ต้องได้รับการอนุญาต คุณสามารถลอง ลงชื่อเข้าใช้หรือเปลี่ยนไดเรกทอรีได้
การเข้าถึงหน้านี้ต้องได้รับการอนุญาต คุณสามารถลองเปลี่ยนไดเรกทอรีได้
Defender for Containers uses the Microsoft Defender Antivirus anti-malware engine to scan nodes for malicious files.
When malware is detected, Defender for Cloud generates security alerts that you can investigate and remediate in Defender for Cloud and Defender XDR. This article explains the prerequisites for malware scanning on Kubernetes nodes, how to review malware alerts in the Azure portal, and how to follow the recommended remediation steps.
Prerequisites
Before you begin, ensure that:
An Azure subscription. If you don't have an Azure subscription, create a free Azure account.
Defender for Cloud enabled on your subscription with one of the following plans. If it's not enabled, see Connect your Azure subscription.
- Defender for Containers
- Defender for Servers P2
Agentless scanning for machines enabled.
Review and remediate Kubernetes node malware alerts
To review and remediate malware alerts for Kubernetes nodes, follow these steps:
Sign in to the Azure portal.
Go to Microsoft Defender for Cloud > Security alerts.
Select the relevant malware alert for the Kubernetes node.
Select View full details to review the detected malware, including affected node pools and malware files.
Select Next: Take Action >> to open the remediation guidance.
Follow the recommended steps to remediate the threat.