Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloud storage malware protection works best as a controlled workflow, not a single scanner: identify every upload path, scan new objects before downstream use, establish coverage of existing data, quarantine suspicious or unknown files, monitor every scan outcome, and preserve recoverable versions and backups. A completed scan lowers risk but is not proof that a file is safe in every context.

Start by mapping the trust boundary

List every way an object can enter each bucket, container, file share, or blob account:

  • Browser and mobile uploads
  • Application programming interfaces and synchronization clients
  • Shared folders and collaboration tools
  • Partner transfers and third-party integrations
  • ETL, analytics, and other data-pipeline jobs
  • Administrator and service-account actions

Prioritize files that cross from an untrusted person or system into a process that will open, transform, distribute, index, or execute them. Microsoft lists user-upload web applications, content distribution, third-party integrations, collaboration, and data pipelines as common scenarios for on-upload protection (Microsoft’s on-upload scanning guidance).

Record the owning team, expected file types and sizes, region, sensitivity, downstream consumers, and the decision that makes an object usable. This inventory determines where scanning must be mandatory and where a delayed or unknown result must stop processing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
  • Hardware encrypted drive
  • Simple to use pin access. RPM-5400
  • Administrator password feature
  • Bus powered
  • Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm

Scan every new object before it reaches a workflow

Azure Blob Storage with Defender for Storage

Defender for Storage on-upload scanning responds to blob-created and blob-renamed events and produces a scan result asynchronously. The scan can take different amounts of time depending on file size and type, service load, and storage read latency. Microsoft also warns that uploads above a documented per-account throughput rate can queue; if the excess is sustained, some blobs may not be scanned (on-upload scanning documentation, updated September 22, 2026).

Do not let an application assume that “uploaded” means “approved.” Put untrusted objects in an intake location with restricted read permissions, or enforce equivalent authorization in the application. A consumer should proceed only after the expected result is received. If the result is delayed, skipped, or failed, route the object to an unknown state rather than treating the delay as a clean verdict.

Amazon S3 with GuardDuty Malware Protection

GuardDuty Malware Protection for S3 starts scans for newly uploaded objects. Its documented workflow can attach scan-result object tags and send notifications through EventBridge; CloudWatch metrics are available for monitoring (GuardDuty Malware Protection for S3; capabilities and supported cases; scan monitoring).

GuardDuty’s S3 protection is separate from the decision logic in your application. Also note that without a GuardDuty detector, this S3 protection feature does not create GuardDuty findings even when an object may be malicious. Connect the result notification to the system that controls access and downstream processing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use an explicit release gate

Define a state machine for each object, such as quarantined, scanning, approved for processing, malicious, skipped, and failed. Give downstream services permission to read only approved objects, or copy approved content into a separate processing location. This prevents a race in which a parser, thumbnailer, indexer, or data pipeline opens a file while its asynchronous scan is still pending.

Rank #2
Apricorn 500GB Aegis Padlock USB 3.0 256-bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-500)
  • Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
  • Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
  • Software Free Design - With no admin rights needed
  • Sealed from Physical Attacks by Tough Epoxy Coating
  • Brute Force Self Destruct Feature

Can cloud storage scan files that were already uploaded?

Yes, but enabling on-upload protection does not prove that legacy objects were scanned. Establish an initial baseline and repeat targeted checks when risk or policy requires.

Azure on-demand scans

Azure supports on-demand scans of a storage account or selected existing blobs, files, containers, shares, and path prefixes. Use an account-wide scan for an initial baseline, then use narrower scans for investigations, newly identified high-risk prefixes, retries, or alert response (Microsoft’s on-demand malware scanning documentation).

AWS on-demand scans and rescans

GuardDuty Malware Protection for S3 supports on-demand scans of existing objects and rescans. Define which prefixes, buckets, or object classes require recurring coverage instead of assuming that a one-time migration scan remains sufficient (AWS capabilities documentation).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a schedule from risk

  • Scan all existing data when protection is first enabled or after a trust-boundary change.
  • Rescan data that was skipped, failed, delayed beyond your service-level objective, or involved in an incident.
  • Use scheduled or event-triggered targeted scans for high-value shared folders, partner prefixes, and data that will be reprocessed.
  • Keep an inventory of objects with no current result and make that state visible to owners.

Make every scan outcome actionable

Outcome Required handling
Detection or malicious Block downstream access, isolate the object, notify a named incident owner, preserve evidence when required, and investigate related identities, uploads, and objects.
Completed without a detection Allow the workflow only according to your release policy. The result lowers risk; it is not a universal guarantee of safety.
Skipped, unsupported, or password-protected Keep the object unavailable to automated consumers until an approved alternative inspection or manual decision is complete.
Failed or timed out Retry within a bounded policy, alert the owner, and retain the object in the unknown state if inspection still cannot be completed.
Still pending Enforce the intake restriction and measure the delay against your service-level objective.

Azure exposes results through blob index tags, Defender alerts, Event Grid, and Log Analytics. Index tags are useful for filtering, but Microsoft warns that users with sufficient permissions can change them; do not use a tag as your only security control (Defender for Storage malware-scanning introduction). Keep an authoritative event or log record and restrict who can alter storage metadata.

AWS supports result tags, EventBridge notifications, and CloudWatch metrics. Build automation with safeguards, durable logs, and a recovery path for false positives. A quarantine move or deny rule should not destroy the original evidence before your retention and incident-response requirements are satisfied. Azure documents Event Grid and Logic Apps patterns and built-in soft deletion; AWS documents notification and tagging capabilities (Azure introduction; Azure on-upload scanning; AWS S3 capabilities).

Rank #3
Sale
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

Does cloud malware scanning catch encrypted or password-protected files?

Client-side encrypted Azure blobs

Defender for Storage cannot inspect the contents of blobs encrypted client-side. If malware inspection is required, scan before client-side encryption or use a supported server-side encryption design in which the provider can perform the inspection (Microsoft’s malware-scanning introduction). Treat excluded encrypted objects as unknown, not clean.

AWS inspection and protected content

AWS describes S3 scanning as reading and decrypting the object in a same-Region isolated environment, with temporary KMS-encrypted storage during the scan (How Malware Protection for S3 works). AWS also documents password-protected content and quota or unsupported-feature cases that can cause a scan to be skipped (AWS capabilities). Require the uploader or data owner to provide an approved inspection path, or keep the file out of automated processing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Limitations: a scan is not proof of safety

Cloud-storage scanning generally sees object content and storage metadata, not the full endpoint context available when a file is opened on a managed device. Microsoft notes that this can mean a higher likelihood of missed detections than endpoint scanning (Defender for Storage malware-scanning introduction).

Use endpoint protection, sandboxing, application allow-lists, and safe file handling for systems that later open or execute content. Do not describe “clean,” “completed,” or “not detected” as proof that a document is safe in every application, account, or execution environment.

How do I protect cloud backups from ransomware?

Restrict destructive authority

  • Apply least privilege to users, workload identities, bucket and container policies, and deletion permissions.
  • Separate upload, read, policy-change, and delete roles where practical.
  • Review public exposure, cross-account access, and changes to retention or encryption policies.
  • Require multifactor authentication for sensitive administrative and destructive actions.

Keep recoverable versions

Enable versioning where supported and verify that recovery operators can restore an earlier object without granting everyday writers delete authority. AWS Security Hub describes S3 versioning as protection against accidental or malicious overwrite or deletion. Its Object Lock feature provides WORM retention that can prevent deletion or overwrite; Object Lock must be enabled when a new bucket is created, and AWS requires versioning before objects can be locked (AWS Security Hub S3 guidance).

Rank #4
Sale
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
  • Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

S3 MFA Delete can protect destructive operations, but it has configuration constraints, including a requirement for versioning and API or command-line configuration. Validate the exact account and operational model before relying on it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Maintain independent, tested backups

Keep backups in a separately controlled location, retain multiple recovery points, and test restoration on a schedule. Include logging, alerts, delete protection, object lock or equivalent immutability, and a documented recovery owner. CISA’s #StopRansomware Guide recommends reviewing cloud shared responsibility and combining backups with access and storage protections; scanning alone does not mitigate ransomware.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Monitor latency, coverage, and cost

  • Measure time from object creation to scan completion and to release or quarantine.
  • Alert on malicious, skipped, failed, delayed, and over-quota outcomes—not only positive detections.
  • Reconcile upload inventories with scan-result logs to find objects that never produced an event.
  • Track who changed tags, policies, retention, or quarantine decisions.
  • Set provider caps or budgets and alert before they stop or defer protection.

Azure states that on-upload scanning is billed per gigabyte, supports a monthly cap, and defaults to a 10 TB monthly limit when no cap is defined; scanning may stop after the configured limit is reached. Microsoft also documents up to 50 GB per minute per storage account for on-upload scanning. These are provider limits, not independent performance benchmarks, and should be rechecked before deployment because service behavior and pricing can change (Azure on-upload scanning).

When comparing native and third-party services, evaluate supported storage types and Regions, new-object versus retrospective coverage, content-size and archive limits, encryption and password handling, result latency and failure behavior, quarantine integrations, data access and retention, operational ownership, and per-gigabyte, object, or request charges. Choose an external service only when it closes a documented coverage or workflow gap.

A practical rollout checklist

  1. Document every ingress route and assign an owner for each storage location.
  2. Define which result states permit downstream access and which states require quarantine.
  3. Enable provider-native on-upload scanning where it supports the required service, Region, and object types.
  4. Place a restricted intake boundary in front of consumers that cannot tolerate pending or unknown files.
  5. Run an initial on-demand scan of existing content and record any skipped or failed objects.
  6. Connect detections and non-success outcomes to alerts, event processing, and a named responder.
  7. Test false-positive recovery, evidence retention, retry behavior, and restoration of quarantined content.
  8. Enforce least privilege, MFA, versioning or immutable retention, independent backups, and restoration tests.
  9. Review latency, scan coverage, throughput, quotas, and costs regularly, and update the design when provider limits change.

Choosing between Azure and AWS workflows

Capability Azure Defender for Storage Amazon GuardDuty Malware Protection for S3
New-object scanning Blob-created and blob-renamed events; asynchronous results (Azure documentation) Scans newly uploaded S3 objects (AWS documentation)
Existing-object coverage On-demand account, container, share, prefix, or selected-object scans (Azure on-demand documentation) On-demand scans and rescans of existing objects (AWS capabilities)
Result integrations Blob tags, Defender alerts, Event Grid, and Log Analytics Object tags, EventBridge notifications, and CloudWatch metrics (AWS monitoring)
Important caveat Client-side encrypted blobs cannot be inspected; tags are not tamper-resistant Password-protected and quota or unsupported-feature cases may be skipped; a GuardDuty detector is needed for GuardDuty findings

The right choice is the one that can enforce your release gate, report every non-success state, and fit your identity, retention, recovery, and regional requirements—not simply the one that produces a “clean” label.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
Hardware encrypted drive; Simple to use pin access. RPM-5400; Administrator password feature
$332.95
Bestseller No. 2
Apricorn 500GB Aegis Padlock USB 3.0 256-bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-500)
Apricorn 500GB Aegis Padlock USB 3.0 256-bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-500)
Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm; Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
$197.22
SaleBestseller No. 3
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$131.00
SaleBestseller No. 4
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$129.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.