Microsoft Defender for Cloud
Cloud and workloads

Review and remediate malware alerts for Kubernetes nodes

In brief

The article was refreshed with corrected wording, clearer Defender for Cloud plan prerequisites, an updated Azure account link, and added guidance for reviewing and remediating malware alerts.

What Defender admins need to know

Administrators can use the revised prerequisites and steps to configure and investigate Kubernetes node malware scanning.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Review and remediate malware alerts for Kubernetes nodes

Defender for Containers uses the Microsoft Defender Antivirus anti-malware engine to scansscan nodes for malicious files.

When malware is detected, Defender for Cloud generates security alerts that can be investigated and remediated in Defender for Cloud and Defender XDR. This article explains the prerequisites for malware scanning on Kubernetes nodes, how to review malware alerts in the Azure portal, and how to follow the recommended remediation steps.

Prerequisites

Before you begin, make sure that:

Review and remediate Kubernetes node malware alerts

To review and remediate malware alerts for Kubernetes nodes, follow these steps:

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Security alerts.