ClamAV

ClamAV

ClamAV is Cisco Talos’ free, open-source antivirus engine. It scans files, uploads and email on Linux, Windows and macOS from the command line or through the clamd daemon, with signature updates via freshclam. It is a server scanner, not a desktop suite.

OSWindows, Linux, macOS
Size14,5 MB
Version7.5.10
🡣2078
FreeLatest version: 1.5.4Actively developed

ClamAV is a free, open-source antivirus engine for sysadmins who need to scan files, uploads and email on servers: Linux mail gateways, file shares, web servers and CI pipelines, and on-demand scans on Windows and macOS. It is command-line and daemon based, maintained by Cisco Talos, and updated with new signatures several times a day.

If you came here looking for Immunet: Cisco switched the Immunet service off on 1 January 2024, and the Immunet client no longer protects anything. ClamAV, the engine Immunet could use for local scanning, is the Cisco antivirus project that is still actively maintained and free. It is not a like-for-like desktop replacement, though, as the limitations below explain.

ClamAV at a glance

ItemDetails
Latest version1.5.4 (7 August 2026); long-term support branch 1.4.6 LTS released the same day
LicenceFree and open source, GPL-2.0
PlatformsLinux (x86_64, aarch64), Windows (x64, x86, ARM64), macOS (universal package), FreeBSD and other Unix systems
DeveloperCisco Talos
Official websiteclamav.net (documentation: docs.clamav.net)
Best forMail gateway scanning, file-server and upload scanning, scheduled server scans

What it does

  • Scans files, directories and streams with clamscan (standalone) or clamdscan against the clamd daemon, which keeps signatures loaded in memory for fast repeated scans.
  • Unpacks and inspects archives (ZIP, RAR, 7z, tar and others), Office documents, PDFs, e-mail files and Windows, Linux and macOS executables.
  • Updates signatures automatically with freshclam; 1.5 added external signature files for database verification and FIPS-style hash limits.
  • Exposes clamd over a local Unix socket or TCP (port 3310 by default), so mail filters, file-upload handlers and scripts can send data for scanning.
  • On Linux, scans files on access with clamonacc (fanotify), with an optional blocking “prevention” mode.
  • Integrates with Postfix and Sendmail through clamav-milter, and with mail filters such as Amavis and Rspamd.
  • Can load custom signatures and YARA rules alongside the official databases.

How sysadmins use it

Nightly scan of a Linux web or file server

  1. Install the scanner and updater (Debian/Ubuntu): sudo apt install clamav clamav-freshclam. The freshclam service starts updating signatures on its own.
  2. Create a quarantine directory: sudo mkdir -p /var/quarantine && sudo chmod 700 /var/quarantine
  3. Add a cron job in /etc/cron.d/clamscan:
30 2 * * * root clamscan -r -i --move=/var/quarantine --log=/var/log/clamav/nightly.log /srv/www /home
  1. Review the log each morning; prefer --move to --remove so a false positive can be restored.

Scan mail on a Postfix gateway

  1. Install the daemon: sudo apt install clamav-daemon. On Debian and Ubuntu, clamd listens on /var/run/clamav/clamd.ctl.
  2. Point your content filter (Amavis, Rspamd or clamav-milter) at that socket.
  3. Send the EICAR test string in a message to confirm the filter rejects or tags it.

On-demand scan on Windows

  1. Install the MSI (or unpack the portable ZIP), then open an elevated PowerShell in the install folder (by default C:Program FilesClamAV).
  2. Create the updater config and delete the line that says Example:
copy .conf_examplesfreshclam.conf.sample .freshclam.conf
notepad .freshclam.conf
.freshclam.exe
.clamscan.exe -r -i D:SharesUploads
  1. Schedule freshclam.exe and the scan with Task Scheduler if you need regular runs.

Scan uploads from an application

  1. Run clamd on the app server or a dedicated scanning host.
  2. Stream each uploaded file to clamd (Unix socket locally, or TCPSocket 3310 restricted by firewall) and reject the upload if the reply contains FOUND.
  3. Test the path with clamdscan --stream suspicious.pdf.

Install and first run

Debian/Ubuntu: sudo apt install clamav clamav-daemon clamav-freshclam. If you run freshclam by hand while the service is active it fails with a lock error; stop clamav-freshclam first or just let the service do the work.

RHEL, AlmaLinux, Rocky: enable EPEL, then sudo dnf install clamav clamd clamav-update. Run sudo freshclam, edit /etc/clamd.d/scan.conf and start the daemon with sudo systemctl enable --now clamd@scan.

macOS: brew install clamav or the official universal .pkg; in both cases copy the sample configs and remove the Example line before running freshclam.

Windows: official MSI and portable ZIP builds for x64, x86 and ARM64; set up freshclam.conf as shown above. There is no GUI and no real-time protection on Windows.

Gotchas:

  • clamd keeps the whole signature set in RAM; plan for well over 1 GB on current databases, and more briefly during database reloads.
  • Use only freshclam or Cisco’s cvdupdate tool to fetch signatures. Downloading too often or with scripts gets you rate-limited (HTTP 429), and versions 0.105 and older are blocked from updates entirely.
  • Many hosts behind one NAT should share a local mirror (cvdupdate) instead of each hitting the CDN.
  • clamonacc needs root, a running clamd and a kernel with fanotify; blocking mode slows busy directories noticeably.

Limitations

  • No on-access scanning on Windows or macOS and no graphical interface; it is not a desktop antivirus suite.
  • Detection of current Windows desktop threats is weaker than commercial endpoint products; do not use it as a replacement for Microsoft Defender or an EDR on workstations.
  • Scanning large archives and file shares is CPU- and I/O-heavy; tune scan limits in clamd.conf.
  • Third-party signature feeds raise detection but also false positives.
  • Non-LTS branches get signature access only for a limited period after newer releases; the 1.4 LTS branch is supported until August 2027.

ClamAV vs alternatives

On Windows workstations and servers, Microsoft Defender is built in and gives real-time protection that ClamAV does not; use ClamAV there only for scripted or second-opinion scans. On Linux mail and file servers ClamAV is the usual free choice, and many mail stacks bundle it; for example Mailu can enable ClamAV as its antivirus. ClamWin is a separate third-party Windows GUI project, not made by Cisco. For spotting infected hosts by their network traffic rather than their files, pair ClamAV with a network detector such as Maltrail.

FAQ

Is ClamAV free?

Yes. ClamAV is free and open source under GPL-2.0, including for commercial use, and the official signature updates are free.

Is there ClamAV for Windows with a GUI?

The official Windows build is command-line only (MSI or portable ZIP). Third-party front ends such as ClamWin exist but are separate projects with their own release schedules.

How do I update the ClamAV virus database?

Run freshclam (or let the freshclam service run it). On Windows, create freshclam.conf from the sample first and remove the Example line.

How do I scan the whole computer with ClamAV?

On Linux: sudo clamscan -r -i --exclude-dir="^/(proc|sys|dev)" /. On Windows: clamscan.exe -r -i C: from the install folder. Expect a full scan to take a long time.

ClamAV vs Windows Defender: which is better?

On Windows, Defender: it has real-time protection and stronger detection of desktop threats. ClamAV is the better fit for Linux servers and mail filtering.

Is there ClamAV for Mac?

Yes. There is an official universal macOS package and a Homebrew formula, both command-line only.

What replaced Immunet antivirus?

Cisco ended Immunet on 1 January 2024 without a consumer successor; businesses are pointed to Cisco Secure Endpoint. For free server-side scanning, ClamAV is Cisco’s maintained open-source engine.

Last checked against official sources: 30 September 2026 (developer website: clamav.net). Versions and licence terms change — confirm on the developer's site before deploying in production.

Other articles

Submit your application