I have both excluded /var/lib/docker and disabled LiveProtection (not normal state) but when installing/running tools in a Kali container, SAV keeps detecting and preventing tools from running (e.g. metasploit). I have restarted the SAV service and rebooted after the config changes.
$ sudo /opt/sophos-av/bin/savconfig query
ExcludeFilePaths: /var/lib/docker/...
LiveProtection: disabled
When I start the container and do something like "apt install metasploit" I get the below (only pasted a couple, there are dozens). I can see it's detecting in the container due to "(container hostname=1bfaca073770)" So what am I doing wrong? I'd like for SAV not to interfere with the kali container in any way. Thank you.
********************** Sophos Anti-Virus Alert ***********************
Threat "Troj/ExpSWF-B" detected in file
"/usr/share/metasploit-framework/data/exploits/CVE-2008-5499.swf.dpkg-new (container hostname=1bfaca073770)".The file is still infected
**********************************************************************
********************** Sophos Anti-Virus Alert ***********************
Multiple threats detected in file
"/usr/share/metasploit-framework/data/exploits/CVE-2010-0232/kitrap0d.x86.dll.dpkg-new (container hostname=1bfaca073770)".The file is still infected
**********************************************************************
This thread was automatically locked due to age.