ウイルスチェック API の比較
Web アプリケーションのアップロードファイルをウイルスチェックする方法を選ぶときに見る 8 項目で、代表的なサービスと自前運用を並べました。セキュリティチェックシートで問われやすい「エンジン」「処理場所」「ファイルの保持」「検体の外部共有」を中心にしています。金額は各社の表示通貨のままで、円換算していません。各欄の出典は表の下にまとめ、確認日を付けています。他社の価格・仕様は変わるので、契約前に出典のページで最新の内容を確認してください。
1. 比較表
表は横にスクロールします。製品名の列は固定です。「未確認」は、公式ページで該当する記述を見つけられなかった項目です(無いことの証明ではありません)。
| 製品 | 検出エンジン | 価格(表示通貨のまま) | 商用利用の条件 | 処理場所(リージョン) | ファイルの保持・削除 | 検体の外部共有 | 呼び出し方法 | 契約・サポートの言語、請求書払い |
|---|---|---|---|---|---|---|---|---|
| VirusTotal Public API / Google Threat Intelligence |
自社エンジンを持たず、70 以上のアンチウイルス製品・URL スキャナ等の判定を集約するマルチエンジン方式t1 | Public API は無料(1 日 500 リクエスト、毎分 4 リクエスト)。有償の Google Threat Intelligence は全プラン「要問い合わせ」。公式ブログは小規模向け「VT Lite」を "From $5k" と説明t2 | Public API は商用製品・サービスへの組み込み不可、新しいファイルを寄与しない業務ワークフローでの利用も不可。現行規約でも利用目的は「非商用の個人または組織の立場」に限定され、自社製品への組み込みは GTI Integration SKU の契約が必要t3 | 通常スキャンはリージョンを選べず、所在地の明示なし。Google のデータ所在コミットメントは GTI に適用されないと規約に明記。有償の Private Scanning のみ保存先を US / EU から選択(日本なし)t4 | 通常スキャンで送ったファイルは VirusTotal のコーパスに保持され、「コミュニティが寄与したコンテンツは原則削除しない」。有償の Private Scanning は既定 1 日(1〜28 日)で削除t5 | 設計上、共有される。送ったファイルはセキュリティパートナー(アンチウイルスベンダー等)と共有・分析され、規約は「公開共有したいものだけをアップロードする」ことへの同意を求める。共有されない Private Scanning はアンチウイルス判定が付かないt6 | REST API v3。ファイルを POST すると analysis ID が返り、結果はポーリングで取得する非同期型。32 MB 超は別 URL(最大 650 MB)。公式クライアントは Go / Python / CLI、他言語はコミュニティ製。ストレージ連携は公式にないt7 | 開発者ドキュメントは英語のみ。有償版は Google Cloud の契約で、Google Cloud 利用規約には日本語版があり、請求書・銀行振込払いの規定あり(支払期日は請求書日から 30 日)。日本語サポートの有無・日本円請求は未確認。無料利用者には SLA・サポート規定が適用されないt8 |
| Cloudmersive Virus Scan API |
エンジンの提供元は非公開。公式ページは「1,700 万以上のシグネチャ」「AI 異常検知」「360 度コンテンツ検証」と説明c1 | 無料: 600 回/月(1 回/秒、3.5 MB まで、評価用)。有料: Basic $19.99/月(10,000 回/月)〜 Medium Business Advantage $999.99/月(500,000 回/月)。Enterprise は要問い合わせ。10 MB 超のファイルは有料プランのみc2 | 無料枠は「サービスを試すためのもの」で、本番利用には有料プランを案内。無料枠の商用利用を禁止する明文は未確認。API の第三者へのサブライセンスは禁止c3 | 北米(バージニア・オレゴン・ケベック)、EU(フランクフルト・ロンドン)、APAC(インド・シンガポール・シドニー)。日本リージョンの記載なし。リージョン指定は Premium / Managed Instance で相談c4 | API はステートレスで、ペイロードをメモリ上で処理し、完了後に保持しないと明記。ハッシュ・検知ログの保持期間は未確認c5 | 第三者や検体共有ネットワークへ送るか否かの明文は未確認。DPA は処理目的をサービス提供・サポートに限定c6 | REST(同期)。SDK は .NET / Java / Node.js / Python / PHP / Ruby / Go / Swift など 20 言語超。Azure Blob / S3 / GCS / SharePoint を対象にするスキャン API と Power Automate コネクタありc7 | サイト・ドキュメント・規約は英語のみ。カード払い(JCB 含む)。購入注文書(PO)を受け付ける。請求書払い・円建ての条件は未確認。準拠法はデラウェア州法c8 |
| OPSWAT MetaDefender Cloud | 他社エンジンを束ねたマルチエンジン(20 以上)。プラン別に無料 20+、Standard 10、Professional 15、Enterprise 20+。一覧には Avira・Bitdefender・ClamAV・McAfee など。無料と有料でエンジンの構成が異なるo1 | 無料(Community): 150 スキャン/日、750 MB まで。有料の Standard / Professional / Enterprise(1,000+ スキャン/日〜 30,000+/月)は契約制で金額は非公開(要問い合わせ)o2 | 無料利用は規約で「personal use」に限定。サービスの再販や、製品・サービスの開発・提供への利用は書面許可なしに禁止。自社サービスへの組み込みは有料契約が前提。登録には法人ドメインのメールが必要o3 | 7 リージョン(米国西海岸・ドイツ・カナダ・オーストラリア・日本(東京)・インド・イスラエル)。既定は呼び出し元に近いリージョンで、東京固定のエンドポイントあり。ファイルは指定リージョン外に出ない。基盤は AWSo4 | 標準(無料含む)ではファイル本体と結果を保持(プライバシーポリシーで最長 10 年)。有料の private scanning では解析後にファイル本体を恒久削除し、結果・ハッシュは残る(保持は最長 24 時間)o5 | 標準送信(無料含む)では、送ったファイルがエンジン提供ベンダーなどの「third-party malware exchange partners」と共有される。止めるには有料ライセンス限定の private scanning が必要o6 | REST API v4。ファイルを POST すると data_id が返り、結果はポーリングで取得する非同期型(コールバックヘッダあり)。無料キーは低優先度キュー。公式 SDK は Python / JavaScript / Java / .NET。S3・Blob 等の自動スキャンは別製品 MetaDefender Storage Securityo7 | 日本法人(東京)あり。opswat.com 本体・ドキュメント・規約は英語のみ。日本語サポート・請求書払い・日本円請求の可否は未確認(有料は営業経由の契約で、支払条件は Order Form に従う)o8 |
| attachmentAV Virus and Malware Scan API |
Sophos(単一エンジン)a1 | 恒久的な無料枠はなく 14 日トライアル。Medium 49 €/月(50,000 回/月)〜 XXL 499 €/月(500,000 回/月)。超過は課金せず HTTP 429 で拒否。Self-hosted(AWS Marketplace)は $0.025/vCPU 時 + $0.200/スキャン GBa2 | 有料サブスクリプションで商用利用が前提。規約で「サービスビューロー・ASP としての利用」「第三者にアクセスさせること」を禁止(ラップして再販する用途は不可)a3 | EU(既定)・米国・カナダ・インド・オーストラリアから選択し、選んだリージョンからデータが出ないと明記。日本リージョンなし。Self-hosted 版は自社の AWS アカウント内a4 | 暗号化ボリュームに一時保存し、スキャン後に削除。非同期モードの結果は 24 時間保持。スキャン単位のログに何が残るかは未確認a5 | Sophos へ検体を送るか否かの明文は未確認。SaaS のサブプロセッサ一覧に載るのは AWS のみa6 | REST。同期(バイナリ 10 MB / URL・S3 200 MB、タイムアウト 60 秒)と非同期(5 GB、コールバックまたはポーリング)。SDK は Java / Python / JavaScript。S3 の自動スキャンは別製品 bucketAVa7 | 英語のみ。メールサポート(ドイツの翌営業日までに応答)。SaaS は FastSpring 経由のカード払いで、請求書払いは未確認。Self-hosted は AWS の請求に統合a8 |
| Amazon GuardDuty Malware Protection for S3 |
AWS 自社エンジンとサードパーティ(リンク先は Bitdefender)のマルチエンジン。YARA・機械学習も併用。シグネチャは 15 分ごとに更新g1 | 東京リージョン: $0.1185/スキャン GB + $0.000282/オブジェクト。無料枠は毎月 1 GB + 1,000 オブジェクト(期限なし)。S3 の操作・タグ・EventBridge は別料金g2 | AWS Customer Agreement の通常条件。用途の制限なし(再販は禁止)g3 | 対象バケットと同じリージョンの隔離環境(インターネット非接続の VPC)。東京(ap-northeast-1)対応g4 | スキャン中のみ KMS で暗号化した環境に一時コピーし、完了後に削除。判定の Finding は 90 日保持g5 | 検体を第三者へ共有する記述なし。「同意なく顧客コンテンツを利用しない」が AWS 全体の方針。サードパーティエンジンへデータが渡るか否かは未確認g6 | S3 バケット単位の自動スキャン(非同期)。結果は EventBridge イベント / オブジェクトタグ / GuardDuty Finding。ファイルを送って判定を受け取る同期 API はない。1 オブジェクト最大 100 GBg7 | 日本語ドキュメント・日本語サポートあり。日本円での支払いを選択可。請求書払い(銀行振込)は条件を満たす場合に切り替え可g8 |
| Microsoft Defender for Storage マルウェア スキャン |
Microsoft Defender Antivirus(単一エンジン)。Defender for Endpoint と同じエンジンと定義z1 | Japan East: $0.15/スキャン GB。加えて Defender for Storage の基本料(ストレージアカウント単位)。月間のスキャン GB 上限を設定可。無料枠なし(30 日トライアルの対象外)z2 | Azure の通常契約(Microsoft Online Subscription Agreement / Microsoft Customer Agreement)。用途の制限なし(再販は禁止)z3 | ストレージアカウントと同じリージョン。Japan East / Japan West 対応z4 | メモリ上でスキャンし、直後に削除。サービス側にファイルは保存しない。結果は Blob インデックスタグに記録z5 | 限定的なケースで SHA-256 などのメタデータを Microsoft Defender for Endpoint(Microsoft 社内)と共有。Microsoft 以外への共有の記述なしz6 | ストレージアカウント単位で有効化し、アップロード時に非同期でスキャン。結果は Blob インデックスタグ / Event Grid / Log Analytics。オンデマンドは ARM の REST API。同期 API はない。1 Blob 最大 50 GBz7 | 日本語ドキュメント(機械翻訳)・日本語サポートあり(24 時間対応は重大度 A のみ)。日本円で請求。請求書(銀行振込)払いは 6 か月以上の利用実績などの条件付きz8 |
| 自前で運用する ClamAV | ClamAV(Cisco Talos がシグネチャを作成)。シグネチャ検査v1 | ソフトウェアは無料(GPLv2)。サーバー費用と運用工数は自己負担。公式の推奨 RAM は最小 3 GiB・望ましくは 4 GiBv2 | GPLv2 のもとで商用利用可v3 | 自社のサーバー(任意)。外部通信は定義ファイルの取得のみv4 | 実装次第。clamd 自体にファイルを保存する機能はないv5 | ClamAV 自体は検体を送信しない。Talos への検体提出(clamsubmit・Web フォーム)は任意v6 | clamd の TCP / Unix ソケットへ INSTREAM などのコマンドを送る(同期)。clamdscan・libclamav は公式、各言語のクライアントは第三者製。ソケットに認証なし。ストレージ連携は公式にないv7 | ドキュメントは英語のみ。サポートはコミュニティ(メーリングリスト・Discord・GitHub)のみで、Cisco は有償サポートを提供しない。契約・請求なしv8 |
| malcheck | ClamAV(シグネチャ検査)。定義は毎時、更新の有無を確認して反映m1 | 無料: 累計 100 件まで(期限・カード登録なし)。有料: 月 10,000 件まで 11,000 円/月(税込)、年契約 132,000 円/年(税込)。超過分は自動で課金せず、続く場合に上位契約を相談m2 | 商用サービスへの組み込みを前提に提供。無料枠にも用途の制限なしm2m3 | さくらインターネット(東京)。リージョン選択なし。エラー監視(Sentry)とメール送信(Mailgun)は米国のサービスだが、ファイル本体は渡らないm1 | 検査後にファイル本体を削除。ファイル名は保存しない。サイズ・ハッシュ・判定結果・URL・meta を検査履歴として 1 年保存m1 | サーバー内の ClamAV で検査が完結。VirusTotal のような検体共有ネットワークや他社の解析サービスへ送らないm1 | REST。同期(POST、最大 30 MB)、非同期(コールバック)、ポーリング。ファイルの実体または URL を指定。SDK はなく、PHP / Ruby / Python / Node.js のサンプルコードを提供。ストレージ連携なしm4 | 規約・ドキュメント・サポートは日本語。円建て。請求書払い(銀行振込)は月契約・年契約とも可。見積書・適格請求書を発行。質問票の回答例を公開m2m5 |
2. 各製品が向いているケース
| 製品 | 向いているケース |
|---|---|
| VirusTotal | 検体を公開・共有してよい前提で、70 以上のエンジンの判定を横断して見たい調査・研究用途。無料の Public API は非商用に限られ、商用サービスへの組み込みには有償の Google Threat Intelligence(Integration SKU)が必要。 |
| Cloudmersive | 無料枠で評価してからカード払いの月額プランへ移りたく、Azure Blob / S3 / SharePoint / Power Automate との連携や多言語の SDK を重視する、英語で契約・サポートを受けられるチーム。 |
| OPSWAT MetaDefender Cloud | 20 以上の他社エンジンで多重スキャンしたく、東京リージョンで処理し、有料契約の private scanning で検体共有を止めたい企業。無料キーは personal use 限定で検体がベンダーへ共有されるため、自社サービスへの組み込みには有料契約が前提。 |
| attachmentAV | Sophos エンジンで、EU や米国など処理リージョンを明示したいチーム。または AWS Marketplace 経由で自社の AWS アカウント内にスキャン API を自前ホストしたいチーム。 |
| Amazon GuardDuty Malware Protection for S3 | すでにファイルを S3 に置いており、アップロード後に非同期で判定を受け取る設計(EventBridge・タグ)にできるチーム。実装量が最も少ない。 |
| Microsoft Defender for Storage | すでにファイルを Azure Blob Storage に置いており、アップロード後の非同期スキャンで足りるチーム。東日本・西日本リージョン内で処理される。 |
| 自前で運用する ClamAV | ファイルを自社のサーバーから一切出したくなく、3〜4 GiB の RAM を持つサーバーの確保、freshclam による定義更新、EOL に合わせたエンジンの更新、ソケットの保護を自分たちで運用できるチーム。 |
| malcheck | 取引先や情シスのセキュリティチェックシートで「アップロードファイルのウイルスチェック」を求められている日本企業の開発チーム。契約・質問票への回答・請求書払いを日本語で済ませたい。判定は同期でその場でも、コールバックで非同期でも受け取れる。件数は月 1 万件程度まで。 |
malcheck が向かないケース
- 複数エンジンやサンドボックス検査が要件になっている: malcheck は ClamAV のシグネチャ検査のみです。特定ベンダーのエンジンやマルチエンジンが指定されている場合は、OPSWAT MetaDefender Cloud や GuardDuty のようなマルチエンジンの製品、またはエンジンが指定されている製品を選んでください。
- ファイルを社外へ送ること自体が禁止されている: malcheck へ送ること自体が外部送信です。自前で ClamAV を運用するか、attachmentAV の Self-hosted 版のように自社アカウント内で動く方式を選んでください。
- ファイルの置き場所が S3 や Azure Blob Storage で、他に検査したいものがない: GuardDuty Malware Protection for S3 や Defender for Storage はストレージ側で有効にするだけで動き、API を組み込む作業そのものが要りません。ストレージに置く前に判定したい、保存先が複数ある、AWS・Azure 以外で動いている、といった場合は API 型の malcheck が候補になります。
- 30 MB を超えるファイルを検査したい: malcheck の上限は 30 MB です。
3. 出典と確認日
すべて 2026 年 9 月 15 日に確認しました。ページの内容は変わることがあります。
VirusTotal(Google)
- VirusTotal「Contributors」 https://docs.virustotal.com/docs/contributors 、「How it works」 https://docs.virustotal.com/docs/how-it-works ("over 70 antivirus scanners")
- VirusTotal「Public vs Premium API」 https://docs.virustotal.com/reference/public-vs-premium-api ("500 requests per day and a rate of 4 requests per minute")、Google Cloud「Google Threat Intelligence」 https://cloud.google.com/security/products/threat-intelligence?hl=ja (料金はお問い合わせ)、VirusTotal Blog「Simpler access for a stronger VirusTotal」(2025-10-08) https://blog.virustotal.com/2025/10/simpler-access-for-stronger-virustotal.html ("From $5k for low API volumes")
- VirusTotal「Public vs Premium API」("The Public API must not be used in commercial products or services.")、「Difference between Public and Private API」 https://docs.virustotal.com/docs/difference-public-private 、Google Cloud「SecOps Service Specific Terms」第 3 条 https://cloud.google.com/terms/secops/service-terms (3(b)(ii)、3(h)(i)、3(i))
- Google Cloud「SecOps Privacy Notice」 https://cloud.google.com/terms/secops/privacy-notice 、「SecOps Service Specific Terms」("Google's data location commitments ... do not apply to Google Threat Intelligence")、VirusTotal「Upload a file (Private Scanning)」 https://docs.virustotal.com/reference/upload-file-private-scanning (storage_region: US, EU)
- Google Cloud「SecOps Service Specific Terms」(3(e)(iv))、VirusTotal「Private Scanning」 https://docs.virustotal.com/docs/private-scanning 、「Accidental upload」 https://docs.virustotal.com/docs/accidental-upload
- Google Cloud「SecOps Service Specific Terms」(3(e)(i)(iii)(v)(vi))、VirusTotal「How it works」("The contents of submitted files or pages may also be shared with premium VirusTotal customers.")、「Private Scanning」("Private analyses won't contain antivirus verdicts")
- VirusTotal「API v3 Overview」 https://docs.virustotal.com/reference/overview 、「Upload a file」 https://docs.virustotal.com/reference/files-scan 、「API scripts and client libraries」 https://docs.virustotal.com/docs/api-scripts-and-client-libraries
- Google Cloud「Google Cloud Platform Terms of Service」 https://cloud.google.com/terms (2.1 支払い、日本語版へのリンク)、「SecOps Service Specific Terms」(3(i) 無料利用者への SLA・サポートの不適用)、「Technical Support Services Guidelines (SecOps)」 https://cloud.google.com/terms/secops/tssg
Cloudmersive
- Cloudmersive「Virus Scan API」 https://cloudmersive.com/virus-api (エンジンの説明。提供元の記載はこのページ・Security ページ・FAQ のいずれにもなし)
- Cloudmersive「Pricing - Small Business」 https://cloudmersive.com/pricing-small-business 、プラン選択画面 https://portal.cloudmersive.com/selectplan 、「Pricing - Enterprise」 https://cloudmersive.com/pricing-enterprise
- Cloudmersive「FAQ」 https://cloudmersive.com/faq ("The free tier is for trying out the service")、「Terms of Service」 https://portal.cloudmersive.com/terms-of-service (2.d、4.a)
- Cloudmersive「Regions」 https://cloudmersive.com/regions 、「Security」 https://cloudmersive.com/security 、「Data Processing Addendum」 https://cloudmersive.com/data-processing-dpa (10.1)
- Cloudmersive「FAQ」 https://cloudmersive.com/faq ("Cloudmersive APIs are stateless, they do not store or retain payload data or copies after the transaction completes")、「Security」 https://cloudmersive.com/security
- Cloudmersive「Data Processing Addendum」 https://cloudmersive.com/data-processing-dpa (5.2)、「Privacy Policy」 https://cloudmersive.com/privacy-policy 、「Subprocessors」 https://cloudmersive.com/subprocessors
- Cloudmersive「Virus Scan API Reference」 https://api.cloudmersive.com/docs/virus.asp 、「Virus Scan API」 https://cloudmersive.com/virus-api (対応言語)
- Cloudmersive「FAQ」 https://cloudmersive.com/faq (支払い方法・購入注文書)、「Terms of Service」 https://portal.cloudmersive.com/terms-of-service (8.b、8.c)
OPSWAT MetaDefender Cloud
- OPSWAT「MetaDefender Cloud」 https://www.opswat.com/products/metadefender/cloud 、「Licensing」 https://metadefender.com/licensing (プラン比較表)、「List of anti-malware engines」 https://www.opswat.com/docs/mdcloud/integrations/list-of-anti-malware-engines
- OPSWAT「Licensing」 https://metadefender.com/licensing 、「Product licensing」 https://www.opswat.com/docs/mdcloud/account-management/product-licensing
- OPSWAT「Terms of Service」 https://www.opswat.com/legal/terms-of-service (Section 3.d、6)
- OPSWAT「Locations」 https://www.opswat.com/docs/mdcloud/compliance/locations 、「MetaDefender Cloud Privacy Policy」 https://www.opswat.com/docs/policies/v1.0/privacy-policy/metadefender-cloud-privacy-policy
- OPSWAT「Private scanning with MetaDefender Cloud APIs」 https://www.opswat.com/docs/mdcloud/operation/private-scanning-with-metadefender-cloud-apis 、「Confidentiality」 https://www.opswat.com/docs/mdcloud/compliance/confidentiality 、「MetaDefender Cloud Privacy Policy」(保持期間)
- OPSWAT「MetaDefender Cloud Privacy Policy」("sharing any executables you submit with third-party malware exchange partners")、「Private scanning with MetaDefender Cloud APIs」("This flag is only available to users who have a paid license")、「Malware Sample Sharing Program」 https://www.opswat.com/blog/malware-sample-sharing-program
- OPSWAT「MetaDefender Cloud API v4」 https://www.opswat.com/docs/mdcloud/metadefender-cloud-api-v4 、「API authentication mechanisms」 https://www.opswat.com/docs/mdcloud/integrations/api-authentication-mechanisms 、SDK https://github.com/OPSWAT/mcl-platform-sdk-python 、「MetaDefender Storage Security」 https://www.opswat.com/products/metadefender/metadefender-storage-security-cloud
- OPSWAT「Contact」 https://www.opswat.com/contact (日本法人)、「Support」 https://www.opswat.com/support 、「Terms of Service」(Section 14、15)
attachmentAV(widdix GmbH)
- attachmentAV「Pricing - Virus and Malware Scan API」 https://attachmentav.com/pricing/virus-malware-scan-api/ 、「Security」 https://attachmentav.com/help/virus-malware-scan-api/security.html
- attachmentAV「Pricing - Virus and Malware Scan API」 https://attachmentav.com/pricing/virus-malware-scan-api/ 、「Throttling and Quotas」 https://attachmentav.com/help/virus-malware-scan-api/developer/throttling-and-quotas.html
- attachmentAV「Terms」 https://attachmentav.com/terms/ (Restrictions (e)(f)(g)、販売者 FastSpring / AWS Marketplace)
- attachmentAV「Security」 https://attachmentav.com/help/virus-malware-scan-api/security.html (エンドポイント一覧と "data sent to an API endpoint does not leave the jurisdiction/region")、Self-hosted 版ドキュメント https://attachmentav.com/help/virus-malware-scan-api-aws/
- attachmentAV「Security」 https://attachmentav.com/help/virus-malware-scan-api/security.html 、「API Definition」 https://attachmentav.com/help/virus-malware-scan-api/developer/definition.html ("Scan results are stored for 24 hours")
- attachmentAV「Security」 https://attachmentav.com/help/virus-malware-scan-api/security.html (Sub-Processors)、Self-hosted 版「Signatures Database」 https://attachmentav.com/help/virus-malware-scan-api-aws/security/signatures-database.html
- attachmentAV「API Definition」 https://attachmentav.com/help/virus-malware-scan-api/developer/definition.html 、「SDKs」 https://attachmentav.com/help/virus-malware-scan-api/developer/sdks.html
- attachmentAV「Terms」 https://attachmentav.com/terms/ (Support SLA、販売者)、「Imprint」 https://attachmentav.com/imprint/
Amazon GuardDuty Malware Protection for S3(AWS)
- AWS「GuardDuty malware detection scan engine」 https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-malware-detection-scan-engine.html ("internally built and managed scan engine and a third-party vendor"。third-party のリンク先が Bitdefender)
- AWS「Amazon GuardDuty pricing」 https://aws.amazon.com/guardduty/pricing/ 、「Pricing for Malware Protection for S3」 https://docs.aws.amazon.com/guardduty/latest/ug/pricing-malware-protection-for-s3-guardduty.html 、AWS Price List(ap-northeast-1) https://pricing.us-east-1.amazonaws.com/offers/v1.0/aws/AmazonGuardDuty/current/ap-northeast-1/index.json
- AWS「AWS Customer Agreement」 https://aws.amazon.com/agreement/ 、「AWS Service Terms」 https://aws.amazon.com/service-terms/
- AWS「How Malware Protection for S3 works」 https://docs.aws.amazon.com/guardduty/latest/ug/how-malware-protection-for-s3-gdu-works.html 、「Amazon GuardDuty endpoints and quotas」 https://docs.aws.amazon.com/general/latest/gr/guardduty.html
- AWS「How Malware Protection for S3 works」 https://docs.aws.amazon.com/guardduty/latest/ug/how-malware-protection-for-s3-gdu-works.html ("deletes the downloaded copy of the object")、「Amazon GuardDuty endpoints and quotas」(Finding retention 90 日)
- AWS「Data Privacy FAQ」 https://aws.amazon.com/compliance/data-privacy-faq/ 、「AWS Customer Agreement」 https://aws.amazon.com/agreement/ (1.4)
- AWS「How Malware Protection for S3 works」、「Malware Protection for S3 quotas」 https://docs.aws.amazon.com/guardduty/latest/ug/malware-protection-s3-quotas-guardduty.html 、「Monitoring scan results with EventBridge」 https://docs.aws.amazon.com/guardduty/latest/ug/monitor-with-eventbridge-s3-malware-protection.html
- AWS「Amazon GuardDuty ユーザーガイド(日本語)」 https://docs.aws.amazon.com/ja_jp/guardduty/latest/ug/gdu-malware-protection-s3.html 、「AWS サポート よくある質問」 https://aws.amazon.com/jp/premiumsupport/faqs/ 、「AWS 日本語 FAQ(請求書払い)」 https://aws.amazon.com/jp/aws-jp-faq/ 、「Managing your payment methods」 https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/manage-payment-method.html
Microsoft Defender for Storage(Microsoft Defender for Cloud)
- Microsoft Learn「Malware scanning in Defender for Storage」 https://learn.microsoft.com/en-us/azure/defender-for-cloud/introduction-malware-scanning ("uses Microsoft Defender Antivirus (MDAV)")
- Azure Retail Prices API(productName "Microsoft Defender for Storage"、japaneast) https://prices.azure.com/api/retail/prices 、Microsoft Learn「On-upload malware scanning」 https://learn.microsoft.com/en-us/azure/defender-for-cloud/on-upload-malware-scanning (GB 単位課金と月間上限)、「Defender for Cloud pricing」 https://azure.microsoft.com/en-us/pricing/details/defender-for-cloud/
- Microsoft「Microsoft Online Subscription Agreement」 https://azure.microsoft.com/en-us/support/legal/subscription-agreement (1.a、1.b)
- Microsoft Learn「Malware scanning in Defender for Storage」("performed in the same Azure region as your storage account")、「Defender for Cloud regional availability」 https://learn.microsoft.com/en-us/azure/defender-for-cloud/regional-availability
- Microsoft Learn「On-upload malware scanning」 https://learn.microsoft.com/en-us/azure/defender-for-cloud/on-upload-malware-scanning ("Scanned content isn't retained and is deleted immediately after scanning")
- Microsoft Learn「Malware scanning in Defender for Storage」("file metadata such as the SHA-256 hash might be shared with Microsoft Defender for Endpoint")
- Microsoft Learn「On-upload malware scanning」、「On-demand malware scanning」 https://learn.microsoft.com/en-us/azure/defender-for-cloud/on-demand-malware-scanning 、「Malware scanning in Defender for Storage」(結果の 4 経路、50 GB 上限)
- Microsoft Learn「Defender for Storage のマルウェア スキャン(日本語)」 https://learn.microsoft.com/ja-jp/azure/defender-for-cloud/introduction-malware-scanning 、「Azure サポート FAQ(日本語)」 https://azure.microsoft.com/ja-jp/support/legal/faq 、「Pay for Azure by wire transfer」 https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/pay-by-invoice 、「Microsoft Customer Agreement FAQ」 https://learn.microsoft.com/en-us/azure/cost-management-billing/microsoft-customer-agreement/microsoft-customer-agreement-faq (日本円請求)
ClamAV(Cisco Talos)
- ClamAV https://www.clamav.net/ 、Cisco Talos「ClamAV」 https://www.talosintelligence.com/clamav ("Talos authors all detection for ClamAV")
- ClamAV Documentation https://docs.clamav.net/ (ライセンス・推奨要件)、「Docker」 https://docs.clamav.net/manual/Installing/Docker.html ("Minimum: 3 GiB, Preferred: 4 GiB")
- ClamAV「COPYING.txt」 https://github.com/Cisco-Talos/clamav/blob/main/COPYING.txt (GNU General Public License, Version 2)
- ClamAV「freshclam.conf.sample」 https://github.com/Cisco-Talos/clamav/blob/main/etc/freshclam.conf.sample (DatabaseMirror)、「clamd(8)」 https://github.com/Cisco-Talos/clamav/blob/main/docs/man/clamd.8.in
- ClamAV「clamd(8)」 https://github.com/Cisco-Talos/clamav/blob/main/docs/man/clamd.8.in (SCAN / INSTREAM のコマンド仕様。保存機能に関する記載なし)
- ClamAV「clamsubmit(1)」 https://github.com/Cisco-Talos/clamav/blob/main/docs/man/clamsubmit.1.in 、「Report a malware sample」 https://www.clamav.net/reports/malware
- ClamAV「Scanning」 https://docs.clamav.net/manual/Usage/Scanning.html 、「Community Projects」 https://docs.clamav.net/manual/Installing/Community-projects.html ("authored by third parties and not by the ClamAV Team")、「clamd(8)」("clamd does not currently protect or authenticate traffic coming over the TCP socket")
- ClamAV「FAQ - End of Life」 https://docs.clamav.net/faq/faq-eol.html ("Cisco does not offer paid technical support")、「Contact」 https://www.clamav.net/contact
malcheck(株式会社ダンミカ)
- malcheck「セキュリティ情報・データの取り扱い」 https://malcheck.com/security (エンジン、処理場所、ファイル本体の扱い、保存される情報と保持期間、再委託先、検体共有について)
- malcheck「料金・契約条件」 https://malcheck.com/#price
- malcheck「利用規約」 https://malcheck.com/term
- malcheck「API ドキュメント」 https://malcheck.com/doc.html (POST /api/scan、GET /api/scan/{id}、ファイルサイズ上限)
- malcheck「よくある質問」 https://malcheck.com/#faq (請求書払い、質問票への回答)
4. 関連ページ
- セキュリティ情報・データの取り扱い(malcheck の処理場所・保持期間・再委託先と、セキュリティチェックシートの回答例)
- 料金・契約条件
- API ドキュメント
- 問い合わせ(この表の誤りの指摘、質問票の回答依頼もこちら)