Perform an In-Session Scan

Run MetaDefender Drive In-Session

  1. While your device OS is running, insert your OPSWAT MetaDefender Drive into the device's USB Type-A port.

  2. Navigate to the root folder inside the MetaDefender Drive partition and locate the MetaDefender Drive In-Sesion Scan.exe file


  1. When click it, In-Session will initialize with a splashing screen


  2. Then the application starts into Overview with option to run Posture Check which is a combination check where Deep Compliance will be triggered first and then Malware scan after


  1. Deep Compliance checks for any issue in Anti-Malware, Encryption and Operation System


  2. Any compliant issues will be reported in Deep Compliance tab, and can be expanded to provide more details


  3. The issue will also be reflected in Device Information tab as well, along with other details about the device being checked


View collected information of the scanned devices from Central Management

If MetaDefender Drive is enrolled and managed by Central Management, after reports are synced, from Central Management, navigate to Solution → Portable Malware Scanning → Dashboard → Scanned Host. Click a scanned host, the collected information will be shown under System Information.


  1. After Compliance Check is done, you can also chose to Proceed with Malware Scan


  2. Click Malware Scan tab, you will see all of scan modes available for MetaDefender Drive In-Session

Engines for In-Session

Engines for In-Session scan will not be updated when In-Session is running. Engines must be updated in advanced by

  • Engines update in MetaDefender Drive Toolkit, following the instructions here

  • Engines update in MetaDefender Drive when booting it up, following the instructions here

  1. Wait until all of the embedded engines display the Ready status. Click the (i) icon to see the embedded engines provided with the version. Those engines are only available after Drive has been updated either by Drive Toolkit or by Update from Drive's UI.


Settings for In-Session

The Malware Scan that follows up after Compliance Check is pre-defined in Settings,along with options for Deep Compliance and Malware Scan included for Posture Check.


Memory Scan

To scan all the libraries loaded into the memory:

  1. Click the Memory Scan tab, then click Start


  1. Once the scan is completed, the results of scanning all the libraries loaded into the memory will be displayed.


Full Scan

To run a full system scan:

  1. Click the Full Scan tab, then click Start


  1. After scan completes, the full scan report will show:


Custom Scan

To select specific partitions, folders, or files to scan:

  1. Click the Custom Scan tab, select the paths you want to include in the custom scan, then click Start.


  1. When a Scan is in progress, you can click View Scan Path.


    It will open a popup to view what directories are under scan session


  2. Once the scan is completed, the detailed results of the selected paths will be displayed, as in the following screenshot displaying scan results of C: and D: partitions on Windows 10


Device Final Verdict

The device will be marked Unsafe when Deep Compliance or Malware check report any issue