Long-time Linux user, have never run AV on my Linux machines.
A few years back, I was forced by compliance rules at work to install AV on a Linux server and started looking for solutions. I shopped around a bit and what I found was that even the commercial AV vendors who supported Linux had no more than 4 or 5 actual signatures to detect Linux malware, and they were all 5 or more years old.
Things may have changed since then, but this may be a good way to think about it… how much Linux malware can these tools actually detect?
Yes, Linux rootkits are a thing but if your AV doesn’t detect them, there’s no point running it.
Long-time Linux user, have never run AV on my Linux machines.
A few years back, I was forced by compliance rules at work to install AV on a Linux server and started looking for solutions. I shopped around a bit and what I found was that even the commercial AV vendors who supported Linux had no more than 4 or 5 actual signatures to detect Linux malware, and they were all 5 or more years old.
Things may have changed since then, but this may be a good way to think about it… how much Linux malware can these tools actually detect?
Yes, Linux rootkits are a thing but if your AV doesn’t detect them, there’s no point running it.