Self-hosted service
Cisco-Talos/clamav avatar
Cisco-Talos/clamav

ClamAV: the open source antivirus engine, and how to run it on Linux, Windows or Docker

ClamAV - Documentation is here: https://docs.clamav.net

7,288 stars929 forksCGPL-2.0

At a glance

What is it?
ClamAV is a GPLv2 antivirus engine from Cisco Talos that ships as a scanner, a daemon, a milter and a set of library bindings. Here is what the documentation covers, where the design choices bite, and what to check before you put it in a mail path.
Who is it for?
Adopt ClamAV when you need a file or mail scanning engine you can script, embed or run on your own hardware, and when you accept that signature delivery and daemon operation are your responsibility. Do not adopt it as a replacement for an endpoint agent with behavioural detection; the project describes itself as a detection engine, and the documentation does not claim host-level protection.
Can I use it commercially?
Yes, with conditions. GPL-2.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 33 days ago.
What is it written in?
Mainly C, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

DEEP OPEN-SOURCE ANALYSIS

What ClamAV actually is, and who reaches for it

ClamAV is an antivirus engine, not a desktop product. The README describes it as "an open source antivirus engine for detecting trojans, viruses, malware & other malicious threats", and the repository layout backs that up: a scanning library (libclamav), a command line scanner (clamscan), a daemon (clamd) with its own client (clamdscan), a signature updater (freshclam), a mail filter (clamav-milter), a signature tool (sigtool), and a bytecode compiler for signature authors (clambc).

The audience is correspondingly narrow and technical. If you run a mail gateway and want to reject attachments carrying known malware, a milter plus clamd is the shape you are looking for. If you accept uploads on a web service, libclamav's scan functions are the integration point, and the repository ships examples such as ex_basic_scandesc.c and ex_scan_callbacks.c to show the calling convention. If you are an analyst writing your own detections, the signature writing manual is a first-class part of the documentation rather than an appendix.

The thing ClamAV is not is an endpoint security agent. Nothing in the README or the repository structure describes behavioural monitoring, exploit mitigation, or host hardening. It matches files against signatures and heuristics. Treating it as a drop-in for a commercial endpoint suite misreads what the project claims to do.

How the engine, the daemon and the signature feed fit together

The architecture is a pipeline with three separable stages, and separating them is the point.

The first stage is signature delivery. freshclam fetches signature databases and writes them where libclamav expects to find them. The repository splits the update client into its own library, libfreshclam, so the fetching logic is reusable outside the freshclam binary. Every scanning component reads the same database files, which means update once, scan everywhere on that host.

The second stage is the engine. libclamav does the parsing and matching, including the archive and container formats it can unpack. This is where the licensing detail matters most. The README states that libclamunrar, the RAR decompressor, is not linked with libclamav at all because the UnRAR licence "is incompatible with GPLv2". Instead it is loaded at run time, and if that load fails "ClamAV will continue running without RAR support". That is a deliberate architectural concession to a licence conflict, and it means RAR scanning is a runtime capability that can silently be absent.

The third stage is the interface. clamscan runs once and exits, loading signatures each time. clamd stays resident and holds the database in memory, and clamdscan talks to it. For anything with throughput requirements, the daemon exists precisely because reloading a signature database per invocation is wasteful. clamdtop is there to watch a running daemon, and clamonacc is the on-access companion. The Rust workspace declared in Cargo.toml has a single member, libclamav_rust, so part of the engine's newer code is Rust alongside the C core.

Installing ClamAV and running a first scan

The README lists four installation routes: Docker, a package manager, a prebuilt installer from clamav.net/downloads, and building from source. It does not give the commands itself, it points at the manual at docs.clamav.net, under the Installing and Packages pages. For Docker it points at the clamav/clamav images on Docker Hub. For a first look, the prebuilt installers cover Linux (Debian and RPM packages for x86_64 and i686), macOS (a universal PKG installer for x86_64 and arm64) and Windows (MSI installers and portable ZIP packages for win32 and x64).

What the repository does document in detail is the code-level integration. The examples directory contains ex_basic_scandesc.c, which scans a file descriptor through libclamav, ex_cl_cvdunpack.c, which unpacks a signature database archive, and ex_scan_callbacks.c, which shows the callback interface. Those files, plus the build options in INSTALL.md, are the concrete material for anyone embedding the engine rather than running the binaries.

Once a package or installer is in place, the operating sequence is the same on every platform: point the updater at a signature source and let it populate the database, then scan. The manual's Docker page is the shortest path if you want the daemon and updater managed as a container rather than as host services. The upgrade FAQ at docs.clamav.net/faq/faq-upgrade.html is the page to read before moving between release lines, since 1.4.x and 1.5.x are cut separately.

Where ClamAV is the wrong tool

The clearest limitation is stated in the licence section rather than in a caveat paragraph: RAR support is conditional. Because libclamunrar is loaded at run time and is not linked into libclamav, a deployment can be running without it and continue running without it. If your threat model includes RAR archives, that is a capability you must verify on the actual host rather than assume from the fact that ClamAV is installed.

A second boundary is signature dependence. The engine matches against a database that freshclam delivers. Nothing in the README suggests a cloud verdict service or a reputation lookup; the detection surface is what is in the database plus the engine's own parsing and heuristics. A host that cannot reach its update source has a database that ages, and the documentation does not describe a fallback.

A third is the operational shape. clamscan loads signatures per invocation, which is fine for a cron job and poor for a busy file service. clamd fixes that but introduces a long-running process with a socket or TCP listener that has to be access-controlled. That is a real piece of operational work, not a configuration footnote, and it is the reason ClamAV shows up in mail gateway and upload pipeline designs rather than on user laptops.

Finally, ClamAV is not a sandbox. It identifies known malicious content; it does not contain the execution of unknown content. If the requirement is to detonate a suspicious document safely, this is not that product.

ClamAV against VirusTotal-style hash lookups and YARA-only scanning

The nearest practical alternative for many teams is not another antivirus engine but a different detection model: submitting file hashes or files to an online multi-engine service. The difference in approach is structural. ClamAV runs locally, holds its own database, and produces a verdict without sending the file anywhere, which matters when the content is confidential or the network is segmented. A submission service does the opposite: it aggregates many engines' verdicts but requires the artifact to leave your environment and typically requires an API key and a rate budget. For an air-gapped file pipeline, that difference decides the choice.

A second alternative is scanning with YARA rules alone, using the yara tool directly rather than through ClamAV. YARA gives you pattern matching you write yourself, with no signature feed and no updater to operate. What you give up is the rest of the engine: the archive and container unpacking that libclamav performs before matching, the bytecode signature support that clambc exists to compile, and the maintained database. ClamAV's own documentation treats signature writing as a supported workflow, so the two are not mutually exclusive in principle. The trade-off is who maintains the rules: with YARA alone, you do. Note that ClamAV bundles a copy of Yara under the Apache 2.0 licence, and the README observes that upstream has since moved to BSD 3-Clause while "our source is out-of-date and needs to be updated".

Maintenance, upgrades and the GPLv2 and UnRAR licence split

The repository is not archived, and the last push was on 2026-08-27. Releases are cut on parallel branches: clamav-1.5.4 and clamav-1.4.6 both landed on 2026-08-07, with clamav-1.5.3 before them on 2026-07-01. That pattern tells you the project maintains more than one release line at a time, so an upgrade is a branch decision rather than a single moving target. The README points at a dedicated FAQ page for upgrading from a previous version, and NEWS.md carries the per-release change list. Read that before jumping a minor version.

The recurring cost is signature updates. freshclam is not a one-time setup step; it is a service that has to keep running, and its failure mode is quiet. A daemon with a stale database still answers scan requests and still returns clean verdicts. Whatever you build around ClamAV needs to surface the age of the database, not just the health of the process.

On licensing, ClamAV itself is GPLv2, with COPYING.txt as the licence text. The third-party inventory in the README is worth reading before you ship a product built on the library: Yara under Apache 2.0, 7z/lzma in the public domain, libmspack under LGPL, and the UnRAR component under a non-free restricted licence that the README says prohibits reverse engineering a RAR compression algorithm from the decompression code. If you plan to redistribute ClamAV or link against libclamav, that mix is the thing to take to your own legal review. This article cannot tell you what your obligations are.

Editorial conclusion

Adopt ClamAV when you need a file or mail scanning engine you can script, embed or run on your own hardware, and when you accept that signature delivery and daemon operation are your responsibility. Do not adopt it as a replacement for an endpoint agent with behavioural detection; the project describes itself as a detection engine, and the documentation does not claim host-level protection. Before rollout, verify three things: that freshclam can reach its update source from the host or network segment, that clamd's socket or TCP port is reachable only by the processes you intend, and whether you need RAR support, because libclamunrar loads at run time under a separate licence and ClamAV keeps running without it if the load fails.

Frequently asked questions

What is ClamAV used for?

It is an antivirus engine for detecting trojans, viruses, malware and other malicious threats, according to the README. In practice that means scanning files, mail and other content against a signature database delivered by freshclam.

Is ClamAV still being supported?

The repository is not archived and the last push was on 2026-08-27. Releases are maintained on more than one branch at once: clamav-1.5.4 and clamav-1.4.6 were both published on 2026-08-07.

Who is the current owner of ClamAV?

The project is developed under the Cisco-Talos organisation on GitHub, and the README credits the ClamAV Team. The third-party code inventory notes which components are not owned by Cisco.

How do you install ClamAV on Linux?

The README lists four routes: Docker images on Docker Hub, a package manager, the installer packages on clamav.net/downloads, or building from source. The online manual has a Packages page for distribution-specific install instructions.

How do you use the ClamAV daemon?

clamd runs as a resident process holding the signature database in memory, and clamdscan sends scan requests to it over the configured socket. This avoids reloading signatures on every scan, which is what clamscan does on each invocation.

Is ClamAV a reliable antivirus?

The README positions it as an engine for detecting trojans, viruses, malware and other malicious threats, with detection driven by the signature database that freshclam delivers. It does not describe behavioural monitoring or host hardening, so reliability depends on keeping that database current.

Official sources

  1. Cisco-Talos/clamav on GitHub
  2. License: GPL-2.0
  3. Project website
  4. README
  5. Releases
For maintainers

Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/cisco-talos-clamav.svg)](https://hysenlabs.com/projects/cisco-talos-clamav)
Community notes

Community notes