I would like to provide feedback on the documentation related to Virtual Machine Threat Analysis.
The current documentation explains Threat Analysis behavior mainly from a Linux perspective

, but it does not clearly mention OS compatibility requirements between the Threat Scan Server and the guest OS of the VM being scanned.
Based on validation in multiple environments, the following behavior is observed:
-
Linux Threat Scan Server → supports Linux VM threat analysis
-
Linux Threat Scan Server → does not support Windows VM threat analysis
-
Windows VM threat analysis works correctly only when a Windows Threat Scan Server is used
This indicates a design requirement, not a troubleshooting issue:
-
Windows VMs must be scanned using a Windows Threat Scan Server
-
Linux Threat Scan Server is intended for Linux VMs only
This requirement is currently not clearly documented, which may lead to incorrect design assumptions during deployment.

