What are the essential features of Avast Business Antivirus for Linux?
Standalone protection – Each server is configured locally, no console.
Server shield – Scans files written to monitored directories in real time.
Distribution coverage – Debian, Ubuntu and Red Hat family servers.
Integration ready – REST API and AMaViS mail server integration.
Offline capable – Local definition mirror for isolated networks.
Important note – No central management console and no Windows coverage.
Core scan service – On-demand and scheduled scanning through the scan command line.
File Server Shield – Real-time scanning of files written to monitored directories.
REST API service – Lets your own applications submit files for scanning.
Mail server integration – Scans messages on Linux mail servers through AMaViS.
Virus definition updates – Automatic updates every three hours plus optional streaming updates.
Important – No central console, every server is configured locally via terminal.
Avast Business Antivirus for Linux is a malware scanner for Linux servers, delivered as DEB and RPM packages from the Avast repository and updated with standard system tools. Avast documents it as an unmanaged product: there is no graphical interface and no cloud console, and every host is configured from the terminal.
No console needed – Protection runs without additional management infrastructure to operate.
Configuration as code – INI files fit existing Ansible or Puppet workflows.
Syslog output – Findings reach syslog and your existing log forwarding.
Automatic quarantine – Detected files are moved to a chest directory.
Offline update option – A local mirror serves definitions to isolated networks.
Controllable cloud contact – Telemetry and reputation lookups can be switched off.
The decisive factor is not headcount but how many Linux hosts you run and whether you already automate their configuration. Ten servers under configuration management are easy to handle; ten servers configured by hand are not. Note that the Swiss reporting obligation follows the sector, not the size of the company, while the European size threshold applies only inside the covered sectors.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | In covered sectors | In covered sectors |
| Security questionnaire from large customers | Increasing | ✓ | ✓ |
| Central console and policy enforcement expected | ✕ | Often | ✓ |
| This product fits | ✓ | With automation | As a component |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, which means that a small engineering office is normally not affected while a regional energy or health provider is, regardless of headcount. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which makes the first hours a matter of having usable facts at hand. The product supports this in a narrow but real way: every detection is written to syslog with a timestamp and the file path, the File Server Shield keeps its own virus log, and the infected file itself is moved to the chest directory so the sample is preserved for analysis instead of being deleted. What it does not provide is equally important for planning: there is no central console that shows all hosts at once, no alerting, and no attack timeline or root-cause reconstruction, so the fleet-wide picture a report needs must come from your own log collection. Practically, that means forwarding the Avast syslog output into a SIEM or log server before an incident, not during one. This text is general product information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No software product creates compliance with the NIS 2 Directive, because the directive addresses organisational risk management rather than the presence of a particular tool. NIS 2 requires a set of measure categories: risk analysis and security policies, incident handling, business continuity and backup, supply chain security, security in acquisition and maintenance including vulnerability handling, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. Avast Business Antivirus for Linux contributes to two of these, namely malware protection as part of basic cyber hygiene on server systems, and the detection and logging side of incident handling. It contributes nothing to backup and business continuity, vulnerability and patch handling, cryptography, access control, multi-factor authentication or staff training, and it produces no policy evidence because there is no console that could enforce or export one. Treat it as one control among many, and document the remaining categories with separate tools and processes.
On 22 February 2024 the United States Federal Trade Commission filed a complaint against Avast Limited and finalised the settlement order on 27 June 2024. The order requires a payment of 16.5 million US dollars, bans the sale or licensing of web browsing data for advertising purposes, requires deletion of the data transferred to the Jumpshot subsidiary, and obliges Avast to run a privacy programme reviewed by an independent assessor for 20 years. Those obligations remain in force. Avast, now part of Gen Digital, stated that it disagreed with the characterisation of the facts but was pleased to resolve the matter, and that it had already wound down Jumpshot voluntarily in January 2020. The matter concerned consumer browser extensions and consumer antivirus software, not the Linux scanner sold here, and it did not concern detection quality. For most buyers this is background rather than a blocker; it becomes a practical question in public sector procurement and in supply chain questionnaires where the vendor's regulatory history has to be declared. One point is directly relevant to the product itself: the options TELEMETRY, STATISTICS, COMMUNITY and REPUTATION_QUERIES in the configuration file can each be set to zero, so an organisation that wants no data flowing to the vendor can switch those channels off and still receive virus definition updates.
Partly, and it is worth knowing in advance which lines you can tick and which you cannot. It answers the questions on malware protection for server systems: an anti-malware agent is present on Linux servers, definitions update automatically every three hours with optional streaming updates, real-time scanning covers files written to defined shares, detections are quarantined automatically, and findings are logged with timestamps to syslog. It does not answer the questions that follow immediately afterwards: there is no central management console, so you cannot produce evidence of centrally enforced policies, no endpoint detection and response, no patch management, no encryption management, no multi-factor authentication, and no built-in reporting export that an auditor could accept as a report. Coverage is also Linux only, so a questionnaire asking about the whole device fleet is not answered by this product alone. To close the gaps, the cheaper route is usually to stay inside the same vendor family and add Avast's Business Hub managed products for Windows and Mac devices rather than mixing vendors; be aware that the Linux hosts still stay outside that console, so plan their evidence separately through syslog forwarding.
The most consequential limitation is the design of the File Server Shield: it monitors write events only, so a file that is already infected before the shield is installed is not scanned when someone merely reads or copies it, and an initial full scan with the command line tool is needed to clean existing stock. Platform coverage is narrower than older marketing pages suggest: the current technical documentation supports Debian 11 to 13, Ubuntu 22.04, 24.04 and 26.04 LTS and Red Hat Enterprise Linux 8 to 10 with the compatible AlmaLinux and Rocky builds, on x86_64, while SUSE support was dropped and there are no ARM packages. Files created through bind mounts or namespaces can bypass the fanotify notification and need the source directory added explicitly to the monitored paths. The follow-up purchase this product most often triggers is protection for Windows and Mac devices, since it covers Linux hosts only and cannot be extended to other platforms.
Yes. The vpsmirror script creates a local copy of the virus definition repository, and the hosts are pointed at that mirror through the vps.conf configuration file, using either a local HTTP server or a file path. The cloud-dependent features such as streaming updates and reputation queries are switched off separately in avast.conf.
Yes, and Avast documents the procedure for systems that were not booted with systemd. The daemons are started manually or through a process manager, the non-privileged avast user has to exist, and the definition update script must be called periodically, roughly every four hours.
That name appears in Avast's technical documentation for the licence that covers all Linux packages, meaning avast, avast-fss and avast-rest together. The licence file is placed in the /etc/avast directory, and one file can be distributed to several machines when it is valid for more than one.
Malware protection for Debian, Ubuntu and Red Hat servers, with a real-time shield for written files. Configured locally, without a console.
Avast Business Antivirus for Linux, Avast, Avast Business, linux server antivirus, file server shield, on-demand scanning, malware protection, rest api
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies