Securing a SharePoint Server file repository requires layering controls on top of its built-in antivirus, which scans each file only once at upload or download using a single engine. Multiscanning, CDR (Content Disarm and Reconstruction), DLP (Data Loss Prevention), and continuous rescanning close the gaps that leave malware and ransomware sitting at rest.
Key Takeaways
- SharePoint Server's built-in antivirus (VSAPI or AMSI) scans each file with a single engine, only at upload or download. It never re-scans files already stored.
- A file rated clean on day one keeps that verdict indefinitely, so malware and ransomware can sit at rest undetected as signatures and detection models improve around it.
- Version history compounds the exposure: every retained copy carries the same unscanned, at-rest risk as the current file.
- The July 2025 ToolShell/Warlock attacks showed attackers dropping web-shell files that a one-engine, point-in-time scan was never built to catch.
- Closing the gap takes a layered control set. The set adds multiscanning, CDR (Content Disarm and Reconstruction), DLP (Data Loss Prevention), and continuous rescanning on top of native scanning.
- MetaDefender™ Storage Security is OPSWAT's enterprise data protection platform, applying Metascan™ Multiscanning™, Deep CDR™ Technology, and Proactive DLP™ to inspect both new uploads and files already at rest.
When on-premises SharePoint users and admins upload a file, that file is scanned with either a third-party antivirus or AMSI-compatible engines (such as Microsoft Defender). If the file passes that initial scan, it’s considered handled. Clean once, clean forever. The assumption is exactly how malware and ransomware payloads get to sit inside the repository undetected;, sometimes for years.
Microsoft says as much directly: SharePoint’s malware protection can limit damage, but doesn’t serve as a single point of defense.
For BFSI (Banking, Financial Services, and Insurance), healthcare, government, and OT (Operational Technology) or Critical Infrastructure environments, the data at risk means compliance filings, patient records, case files, and engineering documentation. All sitting in a library that keeps growing, year over year, while nothing goes back to re-examine what's already inside.
What follows comes down to three things: how SharePoint antivirus scanning actually works, what it doesn't cover, and what layered, effective SharePoint file repository security should look like.
How MetaDefender™ Storage Security Meets These Requirements
The MetaDefender™ Storage Security platform is OPSWAT's enterprise data protection platform, designed to secure files across on-premises, hybrid, and cloud-native storage using Metascan™ Multiscanning, Deep CDR™ Technology, and Proactive DLP™, scanning both new uploads and content already sitting at rest.
For SharePoint users, the platform can solve both the problem of content sitting at rest, and the limitations derived from detection bounded by a single engine. Here’s how it happens:
- Scanning with 30+ antimalware engines through the Metascan™ Multiscanning technology; a threat missed by one vendor has 29 other chances to get caught.
- The Deep CDR™ Technology eliminates blind spots in detection; Deep CDR™ Technology deconstructs and rebuilds files into a safe structure, useful for zero-day and unknown threats hidden in productivity files. The file is deconstructed regardless of whether or not a threat was recognized.
- The Proactive DLP™ technology mitigates the risks of data leaks by identifying, blocking, and redacting sensitive or confidential data in files. For BFSI, healthcare, and government environments regulated by PCI DSS, PHI, or CUI requirements, that's a compliance control sitting on top of malware protection and audit trails.
Multiple Scanning Options in MetaDefender Storage Security
A core departure from SharePoint's native model, MetaDefender Storage Security supports real-time, scheduled, and on-demand scanning of content already sitting in the repository. Real-time protection secures new uploads within seconds, while scheduled and on-demand scans ensure existing files and historical versions remain protected.
Deployment Stays where You Need It
MetaDefender Storage Security can be deployed through various models: physical Servers for direct hardware installations, Virtualization Platforms (compatible with VMware, Hyper-V, and XenServer), IaaS (Infrastructure as a Service) from major cloud providers, or through containerized deployments in Kubernetes clusters.
Frequently Asked Questions
1. Does SharePoint Server scan files for malware automatically?
Yes, but only at specific moments. SharePoint Server can scan documents on upload, download, and online editing using a single engine via VSAPI or the AMSI-based document antivirus feature. It does not automatically re-scan files already stored in libraries.
2. Can malware sit undetected in a SharePoint Server document library?
Yes. SharePoint Server’s native antivirus integrations (VSAPI or AMSI) scan a file at upload or download using a single engine’s signatures at that moment. Files are not rescanned afterward, so a file that was clean, or simply unrecognized, when the engine’s signatures were less current can remain in the library indefinitely.
3. Does SharePoint Server rescan files that are already stored?
No. Native scanning is event-based, triggered by upload or download activity. It does not run on a recurring schedule against existing content, including older file versions retained through version history.
4. How can attackers use SharePoint to distribute malware, not just store it?
Attackers can use SharePoint’s sharing and sync features - external or guest links, synced libraries, or compromised sites hosting phishing documents and malicious links - to move a file already staged in a repository out to other users and endpoints.
5. Is SharePoint Online (Microsoft 365) affected by the same gaps and by ToolShell?
No. The ToolShell exploit chain affected on-premises SharePoint Server only; SharePoint Online was not impacted. The at-rest and single-engine scanning limitations discussed here likewise apply to on-premises Server deployments.
6. What is ToolShell, and does patching fully fix it?
ToolShell is a chained exploit (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) enabling unauthenticated remote code execution on on-premises SharePoint Server. Patching closes the vulnerabilities, but because attackers stole machine keys, organizations must also rotate keys and hunt for already-dropped web shells.
7. Why do I need to rotate ASP.NET machine keys after patching?
Attackers who stole your machine keys can forge valid authentication tokens even after you patch. CISA's guidance is to rotate keys, apply the update, rotate keys again, and restart IIS with iisreset.exe so patching actually evicts the attacker.
8. Does enabling AMSI protect SharePoint from ToolShell?
The AMSI request-filtering integration (enabled by default since the September 2023 updates, ideally in Full Mode) inspects incoming requests and can block unauthenticated ToolShell exploitation. This is separate from the AMSI-based document antivirus feature that scans file content on upload and download.

