Analyzing Encrypted Data Events
When Veeam Backup & Replication registers an Encrypted data event, you can analyze the affected restore point in the Veeam Backup & Replication console to identify the files that may contain encrypted blocks. Encrypted data events are created by inline entropy analysis. For more information, see Inline Scan.
To analyze an Encrypted data event, do the following:
- In the History view, navigate to Malware Detection > Malware Events and select an Encrypted data event.
- Click Analyze on the ribbon. Alternatively, open the Event Details window and click Start entropy analysis.
Veeam Backup & Replication mounts the restore point, analyzes it for encrypted files, and unmounts it. When the analysis finishes, click Download logs to save the results.
The results are saved as a ZIP archive that contains one CSV file for each analyzed disk or volume. Each CSV file lists the paths of the files that may contain encrypted data, along with statistics such as the file size and the estimated encryption percentage.
Note |
|
Consider the following:
|