The Linux antivirus check currently relies on package-inventory tables (deb_packages, rpm_packages, etc. via osquery), which have no equivalent for pacman-based distributions (Arch Linux, Manjaro, EndeavourOS, Omarchy, and others). As a result, any antivirus solution installed via pacman — including ClamAV, which is on your supported list — can never be detected, regardless of whether it's correctly installed and running.
We verified this on an Omarchy (Arch-based) device: ClamAV was installed, running, and actively detecting malware (confirmed via EICAR test), and the underlying osquery processes table showed clamd/freshclam running correctly — but no pacman_packages table exists for the compliance check to query against, so the device was flagged as having no antivirus.
Please authenticate to join the conversation.
Open
Feature Request
Secfix agent
About 8 hours ago

BryanK
Get notified by email when there are changes.
Open
Feature Request
Secfix agent
About 8 hours ago

BryanK
Get notified by email when there are changes.