Malware Detection
Entropy event investigation — Previously, investigating entropy-based malware detection events required switching to external tools, limiting visibility and slowing down response workflows. With this release, entropy detection events include built-in investigation context, allowing administrators to identify the specific files that triggered elevated entropy levels during block level scans. This capability improves visibility into suspicious activity, enabling faster and more accurate investigation directly within the backup environment.
Improved index analytics for failover cluster backup — File deletion tracking is now performed per volume instead of per backup job to significantly reduce false-positive malware events for clustered workloads.
Per-machine exclusions — With this release, administrators can define exclusions at the individual workload level. This capability allows precise tuning of malware detection, reducing false positives for specific systems while maintaining full protection across the rest of the environment.
Full Web UI coverage — With this release, the full malware detection control plane is available in the Web UI, including event management, granular exclusions, and end-to-end investigation workflows. This capability allows administrators to review detections, tune policies, and take action from a single interface, improving efficiency and simplifying security operations.
Performance improvements — With this release, we’ve decreased the amount of RAM consumed during guest index analysis up to 90% in some particular scenarios.