Skip to content

Latest commit



84 lines (63 loc) · 3.91 KB

File metadata and controls

84 lines (63 loc) · 3.91 KB


ClamAV Logo

ClamAV .NETStandard 2.1 client

Build status NuGet version

Bugs Code Smells Coverage Duplicated Lines (%) Quality Gate Status Security Rating Vulnerabilities

Usage example

Create Uri in form "tcp://clamav-server:3310" and pass it to ClamAV.Net client

private static async Task Main()
	const string connectionString = "tcp://";
	const string eicarAvTest = @"X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*";

	//Create a client
	IClamAvClient clamAvClient = ClamAvClient.Create(new Uri(connectionString));

	//Send PING command to ClamAV
	await clamAvClient.PingAsync().ConfigureAwait(false);

	//Get ClamAV engine and virus database version
	VersionResult result = await clamAvClient.GetVersionAsync().ConfigureAwait(false);

		$"ClamAV version - {result.ProgramVersion} , virus database version {result.VirusDbVersion}");

	await using (MemoryStream memoryStream = new MemoryStream(Encoding.UTF8.GetBytes(eicarAvTest)))
		//Send a stream to ClamAV scan
		ScanResult res = await clamAvClient.ScanDataAsync(memoryStream).ConfigureAwait(false);

		Console.WriteLine($"Scan result : Infected - {res.Infected} , Virus name {res.VirusName}");


ClamAV version - ClamAV 0.102.1 , virus database version 25779
Scan result : Infected - True , Virus name Win.Test.EICAR_HDB-1

Use .NET Core Logger

ClamAV.Net client has optional parameter for Microsoft.Extensions.Logging.ILoggerFactory.

ILoggerFactory loggerFactory = LoggerFactory.Create(builder =>
                builder.AddConsole(opt => opt.Format = ConsoleLoggerFormat.Systemd)

//Create a client
IClamAvClient clamAvClient = ClamAvClient.Create(new Uri("tcp://"), loggerFactory);

Output systemd style

<7>ClamAV.Net.Socket.TcpSocketClient[0] Connecting to Server= , parameters (ReadBufferSize=1024)
<7>ClamAV.Net.Socket.TcpSocketClient[0] Start writing command 'INSTREAM' to the network stream
<7>ClamAV.Net.Socket.TcpSocketClient[0] End writing command 'INSTREAM' to the network stream
<7>ClamAV.Net.Socket.TcpSocketClient[0] Start reading command 'INSTREAM' response
<7>ClamAV.Net.Socket.TcpSocketClient[0] End reading command 'INSTREAM' response. Total 34 bytes
<7>ClamAV.Net.Socket.TcpSocketClient[0] Socket disposed
<6>ClamAV.Net.Samples.Console.Program[0] Scan result : Infected - True , Virus name Win.Test.EICAR_HDB-1

Run ClamAV docker

    docker run -d -p 3310:3310 mkodockx/docker-clamav:alpine