Review and remediate malware alerts for Kubernetes nodes
In brief
The article was refreshed with corrected wording, clearer Defender for Cloud plan prerequisites, an updated Azure account link, and added guidance for reviewing and remediating malware alerts.
What Defender admins need to know
Administrators can use the revised prerequisites and steps to configure and investigate Kubernetes node malware scanning.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Review and remediate malware alerts for Kubernetes nodes
Defender for Containers uses the Microsoft Defender Antivirus anti-malware engine to scansscan nodes for malicious files.
When malware is detected, Defender for Cloud generates security alerts that can be investigated and remediated in Defender for Cloud and Defender XDR. This article explains the prerequisites for malware scanning on Kubernetes nodes, how to review malware alerts in the Azure portal, and how to follow the recommended remediation steps.
Prerequisites
Before you begin, make sure that:
You have an Azure subscription. If you don’t have an Azure subscription,
create acreate a free Azure account before you begin.Microsoft Defender for Cloud is enabled on your subscriptionMicrosoft Defender for Cloud is enabled on your subscription with one of the followingplans:plans. If it isn't enabled, see Connect your Azure subscription.- Defender for Containers
- Defender for Servers P2
Review and remediate Kubernetes node malware alerts
To review and remediate malware alerts for Kubernetes nodes, follow these steps:
Sign in to the Azure portal.
Go to Microsoft Defender for Cloud > Security alerts.
@@ -1,25 +1,25 @@ --- title: Review and remediate malware alerts for Kubernetes nodes description: Learn how to review and remediate malware alerts for Kubernetes nodes in Defender for Containers.-ms.date: 04/09/2026+ms.date: 07/03/2026 ms.topic: how-to-ms.custom: sfi-image-nochange+ms.custom: sfi-image-nochange, msecd-doc-authoring-1013 ai-usage: ai-assisted --- # Review and remediate malware alerts for Kubernetes nodes -Defender for Containers uses the Microsoft Defender Antivirus anti-malware engine to scans nodes for malicious files.+Defender for Containers uses the Microsoft Defender Antivirus anti-malware engine to scan nodes for malicious files. -When malware is detected, Defender for Cloud generates security alerts that can be investigated and remediated in Defender for Cloud and Defender XDR.+When malware is detected, Defender for Cloud generates security alerts that can be investigated and remediated in Defender for Cloud and Defender XDR. This article explains the prerequisites for malware scanning on Kubernetes nodes, how to review malware alerts in the Azure portal, and how to follow the recommended remediation steps. ## Prerequisites Before you begin, make sure that: -- You have an Azure subscription. If you don’t have an Azure subscription, create a [free account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) before you begin.+- You have an Azure subscription. If you don’t have an Azure subscription, [create a free Azure account](https://azure.microsoft.com/pricing/purchase-options/azure-account?cid=msft_learn) before you begin. -- [Microsoft Defender for Cloud is enabled on your subscription](connect-azure-subscription.md) with one of the following plans:+- Microsoft Defender for Cloud is enabled on your subscription with one of the following plans. If it isn't enabled, see [Connect your Azure subscription](connect-azure-subscription.md). - Defender for Containers - Defender for Servers P2 @@ -27,6 +27,8 @@ Before you begin, make sure that: ## Review and remediate Kubernetes node malware alerts +To review and remediate malware alerts for Kubernetes nodes, follow these steps:+ 1. Sign in to the [Azure portal](https://portal.azure.com). 1. Go to **Microsoft Defender for Cloud** > **Security alerts**. 