Multiple Deleted Files
To detect the deletion of multiple files, the Veeam Data Analyzer Service compares guest indexing data from two restore points. The later restore point will be compared with the earliest restore point from the same 25-hour period. If there is no restore point, the scan will use the most recent restore point from the same 30-day period. If the deletion of multiple files is present only in the later restore point, a malware detection event is created.
A malware detection event will be created if the following conditions are met:
- At least 100 files with a specific extension have been deleted.
- The percentage of deleted files compared to the total amount of files with this extension is more than 50%.
Tracked extensions can be found in the TrackedFiles.xml file. The default path is C:\Program Files\Veeam\Backup and Replication\Backup\TrackedFiles.xml.
You can configure tracked file extensions in the following way:
- Thresholdpercent — the percentage of files with the specified extension that must be deleted before a malware detection event is created. The default value is 50.
- Thresholdfiles — the minimum number of files with the specified extension that must be deleted before a malware detection event is created. The default value is 100.
Note |
When a malware detection event is marked as a false positive, the file deletion detection threshold will be automatically increased by 5 percent to a maximum of 90 percent. |
Adding and Removing File Extensions
<FileMaskData> |