Skip to content

[filesys/miniFilter/avscan]: app maybe bypass scans via file mapping and subsequent memory writes. #1371

Description

@pengyanhsha

Which is the area where the sample lives?

/filesys/miniFilter/avscan

Describe the issue

The application performs file memory mapping, closes the opened file handle, and conducts write operations on the mapped memory area.Since the IRP_MJ_WRITE event is triggered after IRP_MJ_CLEANUP,scanning can be bypassed and relevant content may not be detected.Why not scan upon receiving the IRP_MJ_CLOSE notification also?

Activity

  1. v-junyli commented on Apr 27, 2026

    @v-junyli
    Contributor

    @microsoft/filter-manager Christian Allred (@cgallred)

  2. jacewq commented on Aug 15, 2026

    @jacewq

    It seems that implementing a scan upon receiving the IRP_MJ_CLOSE notification could help ensure that any relevant data written to the memory-mapped area is still subjected to scanning. Have you considered how the potential overhead of this additional scan might impact performance, especially in high-frequency file operations?

  3. emmettmorin commented on Aug 25, 2026

    @emmettmorin

    Because the file handle is closed before the writes to the mapped memory the IRP_MJ_WRITE comes after IRP_MJ_CLEANUP and gets bypassed. We could track memory mapping in the create path and only scan on close for those files to limit the overhead when many handles close at once.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions