Install bucketAV powered by ClamAV in just 15 minutes and detect malware like viruses, worms, and trojans in your S3 buckets. Choose when to scan and keep full data control within your AWS account.
Real-time, scheduled, on-demand, on-access, and API virus scanning;
Open-source antivirus engine (ClamAV);
Maximum file size of 2 GB;
Real-time notifications and periodic reports about your bucket's status;
Automated mitigation: bucketAV automatically tags, deletes, or quarantines infected files;
It supports multiple AWS accounts and multiple S3 buckets
Key Benefits
Highest security standards: scan your data immediately or when suits you best and stay informed with instant notifications to detect even the latest viruses;
Data sovereignty: you can keep full control over your data because they never leave your AWS account;
Scalable: automatically scan as many files as needed ensuring cost efficiency even for spiky workloads;
Cost efficient: bucketAV runs on EC2 spot instances, which provide compute capacity at reduced costs compared to on-demand instances;
Simple: there is no need for additional UI or access management;
Fast: bucketAV will scan uploaded files within seconds to immediately detect malware;
Up-to-date Malware Database: bucketAV continuously updates malware signatures to protect you against the latest threats;
Streamlined process: bucketAV automatically tags, deletes, quarantines, and moves your data and notifies you about infected files
Want to know more about bucketAV or want to try it for free?
Contact us at hello@bucketav.com, we will be more than happy to help you!
Keeping your data safe and ensuring compliance has never been so easy and will take you just 15 minutes.
This product optionally collects your e-mail address for sending operational alerts. Your e-mail address is stored and processed using Amazon SNS in your AWS Account and is not shared with bucketAV.
Highlights
**Just 15 minutes to install** with a clear step-by-step setup guide and efficient support;
**Runs on ClamAV**: Open-source antivirus engine ideal for small companies or businesses that are searching for baseline security to meet Compliance requirements. Maximum 2GB file size and standard support included.
**Automated and ready-to-deploy solution**: it immediately runs on your own cloud infrastructure for Real-time, Scheduled, On-demand, On-access, and API virus scanning
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 14 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
bucketAV powered by ClamAV - Antivirus for Amazon S3
You pay by the hour for each running EC2 instance that scans your files. The many dimensions here are simply the supported instance types across families like t3, t3a, m4, m5, m5a, m6a, m6i, m7a, m7i, c5, c5a, c6a, c6i, c7a, and c7i, in sizes from medium to 48xlarge. Larger instances raise throughput but cost more per hour. You only pay while instances run. Uninstalling stops the charge. You control cost by choosing the instance type and the number of instances. Standard AWS charges for storage, queues, and API calls apply separately.
Top-of-mind questions for buyers
What resource does one hourly instance charge cover, and how is running time counted?
Each dimension is a specific EC2 instance type that scans your files. You pay the hourly fee only while that instance runs. The auto-scaling default launches one m6i.large instance. Charges stop when instances stop. Uninstalling the software ends the software charge entirely.
Besides the hourly instance fee, what other charges apply that are not shown in the pricing table?
You also pay standard AWS charges for EBS, SNS, SQS, and CloudWatch. AWS bills every S3 API call, such as GetObject and PutObjectTagging, plus a monthly fee for each object tag. These charges appear separately from the hourly software fee shown here.
How can I lower or raise cost by changing the instance choice?
You can reduce cost in small or development environments by switching to a t3 or t3a instance type. To raise scanning throughput, choose a larger instance type or increase the maximum number of instances. Each running instance adds its hourly fee to your bill.
bucketav.com
Helpful?
Vendor refund policy
There is no refund policy, but you can try bucketAV for free to see if it meets all your needs.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Version release notes
Deprecating DeleteInfectedFiles parameter use Delete infected files add-on instead
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Open-source ClamAV antivirus engine for detecting viruses, worms, trojans, and latest malware threats
Scanning Modes
Real-time, scheduled, on-demand, on-access, and API-based virus scanning capabilities
Automated Threat Response
Automatic tagging, deletion, or quarantine of infected files with immediate notifications via email, Slack, Microsoft Teams, AWS Security Hub, Systems Manager OpsCenter, or Amazon SNS
File Processing Capacity
Support for scanning files up to 2 GB in size across multiple AWS accounts and S3 buckets
Malware Database Updates
Continuous updates to malware signatures to protect against latest and emerging threats
Multi-Storage Platform Support
Malware scanning across Amazon S3, Amazon EBS, Amazon EFS, and Amazon FSx for object, block, and file storage environments.
Multiple Scanning Engines
Support for Sophos, CSS Premium, and CSS Secure engines that can be used individually or simultaneously to optimize detection accuracy and performance.
Flexible Scanning Models
Event-based scanning on upload, retroactive scanning on-demand or scheduled, and API-based scanning before write operations for migrations and application workflows.
In-Tenant Deployment Architecture
Installation and operation within customer AWS accounts with data remaining in the specified region, supporting private VPC endpoints and linked account management.
Automated Response and Remediation
Automated quarantine, tagging, and deletion of detected malware with integration to downstream workflows, alerts, and enforcement policies through object tagging.
Multi-Engine Malware Detection
Utilizes 30+ anti-malware engines for malware detection and threat identification.
Real-Time File Scanning
Conducts real-time scanning of files prior to upload to S3 buckets, triggered by S3 events.
Deep Content Disarm and Reconstruction
Implements Deep CDR technology to disarm active embedded threats and reconstruct sanitized file versions to prevent zero-day attacks and advanced evasive malware.
Scheduled and On-Demand Scanning
Supports flexible scanning modes including real-time, scheduled weekly or monthly scans, and on-demand file inspections.
Sensitive Data Detection and Redaction
Automatically detects compliance violations and sensitive data within files, with capability to redact or report identified sensitive information.
Added automated malware scanning has strengthened document security and reduces manual checks
Reviewed on Jul 06, 2026
Review from a verified AWS customer
What is our primary use case?
BucketAV grants us an additional security layer in case any of our userbase uploads malware.
How has it helped my organization?
BucketAV has provided an additional layer of protection for our S3-based document storage by automatically scanning uploaded files for malware before they are processed by downstream applications.
It has helped strengthen our security posture without requiring significant operational overhead. Deployment through CloudFormation was straightforward, and once configured, the service has been reliable.
I also appreciate that it integrates well with AWS services and follows an event-driven architecture.
What is most valuable?
Real-time scanning of newly uploaded S3 objects provides immediate protection against malicious files. It also requires low operational maintenance once deployed.
What needs improvement?
There is a need for better dashboards showing scan progress, throughput, and estimated completion time.
More detailed cost visibility is required to understand the impact of scheduled scans.
Native alerting integrations for Microsoft Teams and additional notification options would be beneficial.
For how long have I used the solution?
I have used it for 1 year.
Which solution did I use previously and why did I switch?
BucketAV was our first malware scanning solution for Amazon S3.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable for the security benefits it provides.
Just be mindful of AWS infrastructure and operational costs, especially when scanning large S3 buckets.
Which other solutions did I evaluate?
The team responsible for the original product evaluation has since left the organization.
What other advice do I have?
I've found BucketAV to be a dependable addition to our AWS security controls.
The support team has also been responsive whenever we've had questions.
With improved observability and enhanced support for large enterprise workloads, it would be an excellent solution for organizations of all sizes.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
reviewer2866284
Secure file scanning has supported privacy compliance while pricing still needs improvement
Reviewed on Jun 30, 2026
Review from a verified AWS customer
What is our primary use case?
We use BucketAV for scanning S3 objects for potential malware and viruses.
How has it helped my organization?
BucketAV has helped our organization by assisting with privacy compliance when handling highly sensitive data.
What is most valuable?
The ease of set-up and configuration are valuable. The ability to scan S3 objects on upload and quarantine files if appropriate is very useful since it allows us to have a compliant architecture. In addition, the support from the BucketAV team has been quick and reliable. I trust that we can rely on this product for future maintenance.
What needs improvement?
The pricing is a little high. We still need to evaluate if pricing is acceptable once we start scanning more objects.
For how long have I used the solution?
I have been using the solution for 3 weeks.
Which solution did I use previously and why did I switch?
We did not use a different product before BucketAV.
What's my experience with pricing, setup cost, and licensing?
The pricing is competitive, but I wish it was a little cheaper.
Which other solutions did I evaluate?
We evaluated Cloud Storage Security.
What other advice do I have?
I don't have additional comments.
Elad
Excellent S3 scan solution
Reviewed on Nov 19, 2024
Review from a verified AWS customer
We have been using the product for more than a year for buckets scanning. It gives us great value, very easy to install, upgrade and operate. It also has a very good dashboard and quick and efficient support.
Computer & Network Security
virus scan review
Reviewed on Oct 31, 2024
Review provided by G2
What do you like best about the product?
VirusScan for Amazon S3 is the best scanning application that can be used to submit files with code for scanning.
What do you dislike about the product?
Nothing much as it uses clamAv for scanning, but seems to do the job.
What problems is the product solving and how is that benefiting you?
Super easy to setup and integrates well with other services. We use it with SQSto notify our application of a hit to keep everything up to date.
Ken | Truss
Great product
Reviewed on Apr 22, 2024
Review from a verified AWS customer
Scalable, flexible solution for running anti-virus scans at scale. We ran about 1M scans in the last few weeks, no issues.
Some highlights - this truly is single-click-to-deploy. Whereas many marketplace solutions often require extensive outside configuration, this one is extremely easy to set up and doesn't hang or cause other issues - great documentation - flexibility to create whatever sort of queue-based, notification-based workflows you might want or need to support (ex. send to slack, send to webhook via SNS, etc) - continues to be updated regularly