{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/",
        "slug": "dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/"
        },
        "title": "Do not mistake Linux archive-scan settings for real-time archive inspection",
        "summary": "Does enabling scanArchives make Defender inspect compressed archives during Linux real-time protection?",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:53+00:00",
        "modified_at": "2026-09-10T02:01:56+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 249,
        "potentially_affected": "Microsoft Defender for Endpoint on Linux archive-scanning configuration.",
        "dse_recommendation": "Choose an explicit on-demand archive inspection step when the workflow requires a decision before extraction.",
        "primary_source": {
            "name": "Configure security settings in Microsoft Defender for Endpoint on Linux - Microsoft Defender for Endpoint | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-endpoint/linux-preferences",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>On Linux, Defender for Endpoint&#8217;s scanArchives preference affects on-demand antivirus scans only. Microsoft states that archives are not scanned during real-time protection; files inside them are scanned after extraction. Enabling the preference therefore does not add real-time inspection of the compressed archive. The setting is available from Defender version 101.45.00 and defaults to true. <a href=\"https://learn.microsoft.com/en-us/defender-endpoint/linux-preferences\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review Microsoft Defender for Endpoint on Linux archive-scanning configuration. Separate a workflow that stores an archive unopened from one that extracts files before processing them. This brief does not claim support for every archive format or promise that a scan finds every threat.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends identifying the point at which an archive must be assessed before another process consumes it. Where the required decision precedes extraction, define an approved on-demand inspection step and its failure handling rather than relying on the real-time protection label. Review the effective preference with the endpoint owner and keep it separate from the application&#8217;s own acceptance rules. Do not copy unrelated settings from the source&#8217;s full configuration example just to enable archive inspection.</p>\n<h2>Verification</h2>\n<p>Use approved harmless test material to distinguish an on-demand scan of the archive from handling its extracted files. Record the agent version, effective preference, scan type and observed completion. Confirm the operational workflow waits for the required result and escalates an incomplete scan. Preserve the two test paths separately so later reviews do not confuse archive storage with extracted-file inspection.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-endpoint/linux-preferences\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Defender for Endpoint Linux security settings</a>.</p>",
        "content_text": "Source facts\nOn Linux, Defender for Endpoint’s scanArchives preference affects on-demand antivirus scans only. Microsoft states that archives are not scanned during real-time protection; files inside them are scanned after extraction. Enabling the preference therefore does not add real-time inspection of the compressed archive. The setting is available from Defender version 101.45.00 and defaults to true. Microsoft Learn.\nApplicability\nReview Microsoft Defender for Endpoint on Linux archive-scanning configuration. Separate a workflow that stores an archive unopened from one that extracts files before processing them. This brief does not claim support for every archive format or promise that a scan finds every threat.\nDSE recommendation\nDSE recommends identifying the point at which an archive must be assessed before another process consumes it. Where the required decision precedes extraction, define an approved on-demand inspection step and its failure handling rather than relying on the real-time protection label. Review the effective preference with the endpoint owner and keep it separate from the application’s own acceptance rules. Do not copy unrelated settings from the source’s full configuration example just to enable archive inspection.\nVerification\nUse approved harmless test material to distinguish an on-demand scan of the archive from handling its extracted files. Record the agent version, effective preference, scan type and observed completion. Confirm the operational workflow waits for the required result and escalates an incomplete scan. Preserve the two test paths separately so later reviews do not confuse archive storage with extracted-file inspection.\nOfficial references\nMicrosoft Learn: Defender for Endpoint Linux security settings.",
        "content_markdown": "## Source facts\n\nOn Linux, Defender for Endpoint’s scanArchives preference affects on-demand antivirus scans only. Microsoft states that archives are not scanned during real-time protection; files inside them are scanned after extraction. Enabling the preference therefore does not add real-time inspection of the compressed archive. The setting is available from Defender version 101.45.00 and defaults to true. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/linux-preferences).\n\n## Applicability\n\nReview Microsoft Defender for Endpoint on Linux archive-scanning configuration. Separate a workflow that stores an archive unopened from one that extracts files before processing them. This brief does not claim support for every archive format or promise that a scan finds every threat.\n\n## DSE recommendation\n\nDSE recommends identifying the point at which an archive must be assessed before another process consumes it. Where the required decision precedes extraction, define an approved on-demand inspection step and its failure handling rather than relying on the real-time protection label. Review the effective preference with the endpoint owner and keep it separate from the application’s own acceptance rules. Do not copy unrelated settings from the source’s full configuration example just to enable archive inspection.\n\n## Verification\n\nUse approved harmless test material to distinguish an on-demand scan of the archive from handling its extracted files. Record the agent version, effective preference, scan type and observed completion. Confirm the operational workflow waits for the required result and escalates an incomplete scan. Preserve the two test paths separately so later reviews do not confuse archive storage with extracted-file inspection.\n\n## Official references\n\n[Microsoft Learn: Defender for Endpoint Linux security settings](https://learn.microsoft.com/en-us/defender-endpoint/linux-preferences)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not mistake Linux archive-scan settings for real-time archive inspection",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/",
                "headline": "Do not mistake Linux archive-scan settings for real-time archive inspection",
                "description": "Does enabling scanArchives make Defender inspect compressed archives during Linux real-time protection?",
                "abstract": "Does enabling scanArchives make Defender inspect compressed archives during Linux real-time protection?",
                "articleBody": "Source facts\nOn Linux, Defender for Endpoint’s scanArchives preference affects on-demand antivirus scans only. Microsoft states that archives are not scanned during real-time protection; files inside them are scanned after extraction. Enabling the preference therefore does not add real-time inspection of the compressed archive. The setting is available from Defender version 101.45.00 and defaults to true. Microsoft Learn.\nApplicability\nReview Microsoft Defender for Endpoint on Linux archive-scanning configuration. Separate a workflow that stores an archive unopened from one that extracts files before processing them. This brief does not claim support for every archive format or promise that a scan finds every threat.\nDSE recommendation\nDSE recommends identifying the point at which an archive must be assessed before another process consumes it. Where the required decision precedes extraction, define an approved on-demand inspection step and its failure handling rather than relying on the real-time protection label. Review the effective preference with the endpoint owner and keep it separate from the application’s own acceptance rules. Do not copy unrelated settings from the source’s full configuration example just to enable archive inspection.\nVerification\nUse approved harmless test material to distinguish an on-demand scan of the archive from handling its extracted files. Record the agent version, effective preference, scan type and observed completion. Confirm the operational workflow waits for the required result and escalates an incomplete scan. Preserve the two test paths separately so later reviews do not confuse archive storage with extracted-file inspection.\nOfficial references\nMicrosoft Learn: Defender for Endpoint Linux security settings.",
                "datePublished": "2026-09-10T00:25:53+00:00",
                "dateModified": "2026-09-10T02:01:56+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-363-do-not-mistake-linux-archive-scan-settings-for-real-time-archive-inspection/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not mistake Linux archive-scan settings for real-time archive inspection"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Explainer",
                    "Information priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 249,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure security settings in Microsoft Defender for Endpoint on Linux - Microsoft Defender for Endpoint | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-endpoint/linux-preferences"
                }
            }
        ]
    }
}