Malware Detection for Unstructured Data
You can detect malware in unstructured data backups. Malware detection identifies suspicious or infected content in these backups before you recover them.
Veeam Backup & Replication detects malware in unstructured data using the following methods:
- Index-based detection analyzes the backup to detect suspicious files and extensions, indicators of compromise, and mass file deletions. For more information, see Guest Indexing Data Scan.
- Veeam Threat Hunter and YARA scans inspect the backup content for known malware and specific data. You can use Veeam Threat Hunter or your own antivirus software. For more information, see Scan Backup.
Veeam Backup & Replication publishes the backup as a file share and scans the published share on the mount server.
Requirements and Limitations
Veeam Backup & Replication has the following requirements and limitations for malware detection in unstructured data:
- Malware detection is available for file share and object storage backups.
- The backup must not be a long-term (GFS) backup.
- The backup must be created in Veeam Backup & Replication 13.1 or later.
- The backup must be consistent.
- The backup must not be encrypted.
- After you upgrade to Veeam Backup & Replication 13.1, only restore points created by new backup runs are scanned. Existing restore points are not scanned retroactively.
- Malware detection for unstructured data is available with the Advanced edition of Veeam Universal License.
Configuring and Running the Scan
To scan the content of a file share or object storage backup, run a Scan Backup session with antivirus software or a YARA rule, in the same way as for other backups. Run the session under the Backups node in the Veeam Backup & Replication console. In the Veeam Backup & Replication web UI, you can run a Scan Backup session only for backups already marked as Suspicious or Infected. For more information, see Scanning Backups Using Console and Scanning Backups Using Web UI.
|
Important |
|
Add the Veeam Threat Hunter installation folder to the exclusion list of the antivirus software installed on the mount server. Otherwise, the scan fails. |
In the Veeam Backup & Replication web UI, the Malware Detection view shows each scanned file share or object storage backup as Suspicious or Infected. You can also mark a backup as clean there.
|
Note |
You can mark an unstructured data backup as clean only in the Veeam Backup & Replication web UI. In the Veeam Backup & Replication console, you can view the malware status and run Scan Backup, but you cannot currently mark a backup as clean. |
