Threat Search Components

Component

Description

Component for monitoring network traffic and URLs.

It is designed to scan data downloaded from the network to the local host and passed from it to the external network for threats. The component also prevents connections with the network hosts added to the unwanted categories of web resources or black lists created by the system administrator.

Used by the Dr.Web MailD component in the mode of the transparent proxy of email protocols (SMTP, POP3, and IMAP).

Uses the Dr.Web Network Checker component to scan received data.

If allowed by the user, sends requested URLs to the Dr.Web Cloud service for scanning.

The component is supplied only with the distributions designed for GNU/Linux OSes.


Executable file: drweb-gated.

Logged internal name: GateD

Network connection monitor.

Used by SpIDer Gate and provides connection routing for applications that operate on a host to scan traffic of these connections.

The component is supplied only with the distributions designed for GNU/Linux OSes.


Executable file: drweb-firewall.

Logged internal name: LinuxFirewall

Component for scanning email messages.

Analyzes email messages and prepares them for scanning for threats. It can operate in two modes.

1)Filter for mail servers (Sendmail, Postfix, and so on) connected via the Milter interface, Spamd or Rspamd interfaces.

2)Transparent proxy of email protocols (SMTP, POP3, and IMAP). SpIDer Gate is used in this mode.

Uses the Dr.Web Network Checker component to scan data extracted from email messages


Executable file: drweb-maild.

Logged internal name: MailD

Component for scanning email messages for signs of spam.

Used by the Dr.Web MailD component. Can be unavailable depending on distribution. If it is unavailable, scanning email messages for sings of spam is not performed by the Dr.Web MailD component.

The component is not supported for ARM64, E2K and IBM POWER (ppc64el) architectures.


Executable file: drweb-ase.

Logged internal name: Antispam