Veeam and third-party checks that look for infected workloads or suspicious activity and raise events. They examine backups, the data stream and indexing data; Scan Backup with Threat Hunter, YARA or antivirus belongs here.
Read more: Veeam Help Center
In the Ultra Transcenders books
Each book explains malware detection in context, with comparison tables and the common traps.
Terms in this definition
- Scan Backup
Searches restore points that already exist for signs of malware, with Veeam Threat Hunter, an antivirus product or YARA rules doing the work. It helps identify the most recent clean point or look through what a backup contains, and no data is written back, which is where it differs from Secure Restore.
- YARA
A rule language for recognising malware by pattern. Veeam can apply such rules to restore points during Scan Backup, Secure Restore and SureBackup, flagging affected workloads as Infected.
Related terms
- guest file system indexing
Records which guest OS files each backup contains. Malware detection relies on this catalogue, and Enterprise Manager uses it for searching and restoring files.
- SuppressMalwareDetectionNotification
Putting this tag in a YARA rule's name means a match will not raise a malware detection event, though scanning still runs to the end.