Known Suspicious Files and Extensions
To detect suspicious files and extensions commonly used by malware, the Veeam Data Analyzer Service compares the guest indexing data of a restore point with the SuspiciousFiles.xml file. If files have extensions or names that match any in the SuspiciousFiles.xml file, a malware detection event is created.
The SuspiciousFiles.xml file is maintained and updated regularly to manage evolving threats. These updates are informed by Veeam Cyber Threat Intelligence as well as internal security research and validation processes. The Veeam Data Analyzer Service checks for updates to the SuspiciousFiles.xml file once a day.
Do not edit the SuspiciousFiles.xml file directly. Instead, you can add custom suspicious files and extensions, exclude trusted files and folders, and export or import the list. To configure these settings, see Configuring Malware Detection Using Console and Configuring Malware Detection Using Web UI.