Indicators of Compromise

Indicators of compromise are non-malware programs. However, their unexpected presence on a system can indicate a security risk. Indicators of compromise are specified in the SuspiciousFiles.xml file. They are selected from and categorized using the MITRE ATT&CK Matrix.

To detect indicators of compromise, the Veeam Data Analyzer Service compares guest indexing data from two restore points with the SuspiciousFiles.xml file. The later restore point is compared with the earliest restore point from the same 25-hour period. If there is no restore point, the scan uses the most recent restore point from the same 30-day period. If an indicator of compromise is present only in the later restore point, a malware detection event is created.

Note

The indicators of compromise list cannot be customized. To receive new indicators of compromise, enable automatic updates of malware definitions. For more information, see File Detection.

You can exclude specific indicators of compromise from monitoring. To do this, see File Detection and Configuring Malware Detection Using Web UI.

Page updated 2026-07-17

Page content applies to build 13.1.0.411