I was setting up a sophos named scan for our Red Hat Linux environment but I noticed that in the named scan there is no option to quarantine a file if it is found to be infected. I only see threataction=donothing|delete. Our security posture is to quarantine infected files - am I missing something?
Or should I go with on-demand scans then? With on-demand scanning I see there is an option to --quarantine and -move=/path/to/move/infected/files/to. In the install pdf it even references doing this in a crontab, but its a dead link: To schedule an on-demand scan, use the command crontab. For details, see Sophos supportknowledgebase article 12176. Anything special about running this in a crontab?
savscan -di -ns -nc -all -rec -nremove --stay-on-machine --quarantine -move=/opt/sophos-av/quarantine -bs -sc -f -p /opt/sophos-av/log/weekly-scan.log
Thanks.
Joe.
This thread was automatically locked due to age.