If I had to point to one main area where Antivirus for Amazon S3 can be improved, it would be the reporting and analytics side of things. The current dashboard gives you what you need for operations, but if you want rich, forensic-level reporting, such as tracking infection patterns over time, which upload sources are riskier, or trending data by bucket, you have to build that system yourself on top of the logs. I would love to see more out-of-the-box reporting capabilities without needing to pipe everything into a SIEM first. It is not a deal-breaker, but it would make the product much stronger from a security analytics perspective. Regarding needed improvements, I think about documentation, debugging, and monitoring. Documentation is generally good, but there are some edge cases, particularly across cross-account deployment configuration, where the documentation feels thin. I had to piece together information from a Stack Overflow post and a support ticket to get it right. For debugging, clearer error messaging from the scanning engine when something fails silently would be helpful. Sometimes a scan just does not trigger, and there is no obvious signal in the logs as to why. Better diagnostic tooling there would save a lot of troubleshooting.


