File System Activity Analysis

During file system activity analysis, Veeam Backup & Replication examines indexing data created during backup. The following malware activity can be detected:

Note

For machines, Veeam Backup & Replication scans guest file system indexing data. For file shares and object storage, Veeam Backup & Replication scans the index created by the backup job. The detection process is the same for both.

Supported Scenarios

Consider the following:

  • You can scan indexing data for the following workloads:
  • VMware VMs including VMware Cloud Director VMs
  • Hyper-V VMs
  • Nutanix AHV VMs
  • Proxmox VE VMs
  • Machines with Veeam Agent for Microsoft Windows
  • Machines with Veeam Agent for Linux
  • Machines with Veeam Agent for Unix
  • Microsoft Azure VMs backed up by Veeam Backup for Microsoft Azure
  • File shares and object storage. Such backups must meet the following conditions:
  • The backup is created in Veeam Backup & Replication 13.1 or later.
  • The backup is not a long-term (GFS) backup.
  • The backup is consistent.
  • The backup is not encrypted.
  • Detection of "sleeping" malware is not supported by this method.

In This Section

Page updated 2026-08-13

Page content applies to build 13.1.1.18