How Malware Detection Works
Malware detection is managed by the Veeam Data Analyzer Service. The service restarts once a day at 12:00 AM and starts a new malware detection session. During the session, the Veeam Data Analyzer Service performs the following operations:
- Checks for updates to the list of known suspicious files, extensions, and indicators of compromise. For more information, see File Detection.
- Sends an email notification about all malware detection events that were created within the last 24 hours. For more information, see Notifications.
- Initiates a scan session using a specific malware detection method if there is new backup data that needs to be scanned. Otherwise, the service waits for new data to appear.
If malware activity is detected, the Veeam Data Analyzer Service does the following:
- Creates a malware detection event.
- Marks the workload and the restore point where malware activity was detected for the first time as Suspicious or Infected.
|
Note |
|
Consider the following:
|