Malware Detection

You can use built-in or 3rd party malware detection methods to scan backup data and get information about suspicious activity or infected objects. The functionality includes:

  • Detecting malware activity in guest indexing data and data stream
  • Performing Scan Backup with different scan engines — Veeam Threat Hunter, 3rd party antivirus software, or YARA
  • Performing Secure Restore with different scan engines — Veeam Threat Hunter, 3rd party antivirus software, or YARA
  • Performing proactive signature-based scans
  • Integration with 3rd party malware protection solutions through Veeam Incident API
  • Viewing malware detection events
  • Receiving daily and immediate reports about malware detection events
  • Managing the malware status of the machines marked as Suspicious or Infected
  • Marking specific restore points as Infected or Clean

For more information on licensing support for specific malware detection features, see Veeam Data Platform Feature Comparison.

Requirements and Limitations

Malware detection has the following requirements and limitations:

  • Malware detection is only supported on specific platforms and applications. For more details, see the supported scenarios of the specific malware detection method:
  • Only users with the Backup Administrator role have full access to the functionality. Users with other roles can view malware detection events and machines marked as Suspicious or Infected.
  • You can manage malware detection in both the Veeam Backup & Replication console and the Veeam Backup & Replication web UI. Currently, some operations, such as analyzing encrypted data events, are available only in the Veeam Backup & Replication console.
  • When using Cloud Connect, malware detection is managed by a tenant. A service provider cannot scan tenant data for malware or view the malware detection status.

In This Section

Page updated 2026-07-30

Page content applies to build 13.1.0.411