Start-VBREncryptionAnalysis

Short Description

Starts an analysis of an encrypted data malware event.

Product Edition: Standard, Enterprise, Enterprise Plus, Veeam Universal License

Syntax

Start-VBREncryptionAnalysis [-EventId] <Guid> -FolderPath <String> [<CommonParameters>]

Detailed Description

This cmdlet starts an analysis session for an encrypted data malware event. The cmdlet returns a VBREncryptionAnalysis object that exposes the session ID and current session state.

After the analysis session completes, Veeam Backup & Replication downloads a logs archive to the folder that you specify. The archive has the following name format: encryption-analysis-<sessionId>.zip.

Parameters

Parameters

Parameter

Description

Type

Required

Position

Accept Pipeline Input

EventId

Specifies the ID of an encrypted data malware event. The cmdlet will analyze this event.

Guid

True

0

True (ByPropertyName, ByValue)

FolderPath

Specifies a local absolute path to a folder. The cmdlet will save the logs archive of the analysis to this folder. If the folder does not exist, the cmdlet will create it.

String

True

Named

False

<CommonParameters>

This cmdlet supports Microsoft PowerShell common parameters. For more information on common parameters, see Microsoft Docs.

Output Object

VBREncryptionAnalysis

Examples

Start-VBREncryptionAnalysisExample 1. Starting Analysis by Event ID

This example shows how to start an analysis for an encrypted data malware event by its ID.

Start-VBREncryptionAnalysis -EventId "5a8c2d36-1f9e-4b3a-b1d5-7c2e9a1d0c4b" -FolderPath "C:\Reports\EncryptionAnalysis"

Run the Start-VBREncryptionAnalysis cmdlet. Specify the following settings:

  • Specify the EventId parameter value.
  • Specify the FolderPath parameter value.

Start-VBREncryptionAnalysisExample 2. Starting Analysis for Malware Detection Event

This example shows how to start an analysis for a malware detection event returned by Get-VBRMalwareDetectionEventReturns malware detection events for machines..

$event = Get-VBRMalwareDetectionEvent -ObjectName "WinSrv2022"

Start-VBREncryptionAnalysis -EventId $event[0].Id -FolderPath "C:\Reports\EncryptionAnalysis"

Perform the following steps:

  1. Run the Get-VBRMalwareDetectionEventReturns malware detection events for machines. cmdlet. Specify the ObjectName parameter value. Save the result to the $event variable.
  2. Run the Start-VBREncryptionAnalysis cmdlet. Pass the Id property of the first event in the $event array as the EventId parameter value. Specify the FolderPath parameter value.

    The Get-VBRMalwareDetectionEvent cmdlet will return an array of events. Mind the ordinal number of the event (in this example, it is the first event in the array).

Get-VBRMalwareDetectionEventReturns malware detection events for machines.

Page updated 2026-08-19

Page content applies to build 13.1.1.18