- About Veeam Backup & Replication REST API
- Overview
- How To
- Changelog
- Global Changes
- New Features
- Users and Roles
- Malware Detection
- High Availability Cluster
- Bare Metal Recovery and Volume Restore
- Backup Move and Copy
- Unstructured Data
- Microsoft Entra ID
- Deduplication Appliance Repositories
- Veeam Data Cloud Vault Archive
- Instant Recovery to Microsoft Azure
- Instant Recovery to Another Platform
- Quick Backup
- Proxmox VE and Nutanix AHV
- General Options
- Inventory Browser
- Agent Management
- Backup Browser
- Application Items Restore
- Deprecated Requests
- Minor Non-Breaking Changes
- Breaking Changes
- Login
- Service
- Services
- Credentials
- getGet All Credentials
- postAdd Credentials Record
- getGet Credentials Record
- putEdit Credentials Record
- delRemove Credentials Record
- postChange Password
- postChange Linux Private Key
- postChange Linux Root Password
- getGet All Cloud Credentials
- postAdd Cloud Credentials Record
- postGet Microsoft Entra ID Verification Code
- postRegister Microsoft Entra ID Application
- postGet Google Authentication Information
- getGet Cloud Credentials Record
- putEdit Cloud Credentials Record
- delRemove Cloud Credentials Record
- postChange Secret Key
- postChange Google Service Account
- postChange Certificate
- getGet All Helper Appliances
- postAdd or Edit Helper Appliance
- getGet Helper Appliance
- delRemove Helper Appliance
- Encryption
- getGet All Encryption Passwords
- postAdd Encryption Password
- getGet Encryption Password
- putEdit Encryption Password Hint
- delRemove Encryption Password
- postChange Encryption Password
- postVerify Encryption Password
- getGet All KMS Servers
- postAdd KMS Server
- getGet KMS Server
- putEdit KMS Server
- delRemove KMS Server
- postChange KMS Server Certificate
- License
- postInstall License
- getGet Installed License
- postRemove License
- postCreate License Usage Report
- postRenew Installed License
- getGet Consumption of Socket Licenses
- postRevoke Socket License
- getGet Instance Licenses Consumption
- postAssign Instance License
- postRevoke Instance License
- postRemove Instance License
- getGet Capacity License Consumption
- postRevoke Capacity License from Unstructured Data Workload
- postUpdate License
- postEnable or Disable License Auto Update
- postEnable or Disable Instance Consumption for Unlicensed Agents
- Connection
- Cloud Browser
- Inventory Browser
- getGet All VMware vSphere Servers
- getGet VMware vSphere Server Objects
- postRescan Inventory Objects
- postGet All Servers
- postGet Inventory Objects
- postGet Inventory Object Details
- postGet All Protection Groups
- postGet All Physical Inventory
- postGet Inventory Objects for Specific Protection Group
- getGet All Unstructured Data Servers
- postAdd Unstructured Data Servers
- getGet Unstructured Data Server Defaults
- getGet Unstructured Data Server
- putEdit Unstructured Data Server
- delRemove Unstructured Data Server
- postStart Browsing Unstructured Data Server
- postBrowse Unstructured Data Server
- postStop Browsing Unstructured Data Server
- getGet All Unstructured Data Server Inventory Browse Sessions
- getGet Unstructured Data Server Inventory Browse Session
- getGet All Microsoft Entra ID Tenants
- postAdd Microsoft Entra ID Tenant
- getGet Microsoft Entra ID Tenant
- putEdit Microsoft Entra ID Tenant
- delRemove Microsoft Entra ID Tenant
- getGet Active Directory Objects from Domain
- getGet Available Disk Slots for Platform
- Traffic Rules
- General Options
- getGet General Options
- putEdit General Options
- getGet Email Settings
- putEdit Email Settings
- postSend Test Email
- postCheck SMTP Server Certificate
- getGet Host Authentication Settings
- putEdit Host Authentication Settings
- postExport Trusted Hosts List to a File
- postImport Trusted Hosts List from a File
- getGet Notification Settings
- putEdit Notification Settings
- getGet Event Forwarding Settings
- putEdit Event Forwarding Settings
- getGet Storage Latency Settings
- putEdit Storage Latency Settings
- postAdd Latency Settings for Specific Datastore
- getGet Latency Settings for Specific Datastore
- putEdit Latency Settings for Specific Datastore
- delRemove Latency Settings for Specific Datastore
- getGet VSA Event Forwarding Settings
- putEdit VSA Event Forwarding Settings
- getGet Daemon Settings for VSA Event Forwarding
- putEdit Daemon Settings for VSA Event Forwarding
- getGet Node Exporter Settings
- putUpdate Node Exporter Settings
- postSet Node Exporter Basic Authentication
- Users and Roles
- getGet All Users and Groups
- postAdd User or Group
- getGet User or Group
- delRemove User or Group
- getGet Roles Assigned to User or Group
- putEdit Roles Assigned to User or Group
- postChange Service Account Mode
- postReset MFA for Specific User
- getGet All Roles
- postCreate Custom Role
- getGet Role
- putEdit Custom Role
- delDelete Custom Role
- getGet Role Permissions
- getGet Custom Role Details
- postClone Custom Role
- getGet MFA Settings
- putEdit MFA Settings
- getGet All Restore Options
- ACL
- Global Exclusions
- Security
- postStart Security & Compliance Analyzer
- getGet Security & Compliance Analyzer Last Run
- getGet Security & Compliance Analyzer Schedule
- putModify Security & Compliance Analyzer Schedule
- postReset All Security & Compliance Analyzer Statuses
- getGet Security & Compliance Analyzer Results
- postSuppress Security & Compliance Analyzer Best Practice Status
- postReset Security & Compliance Analyzer Status
- getGet All Authorization Events
- getGet Authorization Event
- Malware Detection
- getGet All Malware Events
- postCreate Malware Event
- getGet Malware Event
- getGet All Malware Detection Settings
- putEdit Malware Detection Settings
- getGet Malware Suspicious File Masks Settings
- putEdit Malware Suspicious File Masks Settings
- getGet Malware Allowed Trusted Extensions
- getGet Malware File Detection Indicators of Compromise
- postEnable Monitoring of Indicators of Compromise
- postDisable Monitoring of Indicators of Compromise
- getGet Logs for SureBackup Scan Task Session
- postMark Backup Objects as Clean
- getGet All Malware Detection Objects
- getGet Malware Detection Object
- getGet All Malware Detection Exclusions
- postCreate or Update Malware Detection Exclusions
- postDelete Malware Detection Exclusions
- getGet YARA Rules
- postScan Backups with Antivirus or YARA Rules
- postStart Malware Encryption Analysis
- getDownload Malware Encryption Analysis Logs
- Configuration Backup
- Deployment
- Managed Servers
- getGet All Servers
- postAdd Server
- postGet vCenter Servers Attached to Cloud Director Server
- postGet Microsoft Hyper-V Servers Managed by Microsoft Hyper-V Cluster or SCVMM Server
- getGet Server
- putEdit Server
- delRemove Server
- postChange to Single-Use Credentials
- getGet Volumes for Microsoft Hyper-V Standalone Server
- putEdit Volumes on Microsoft Hyper-V Standalone Server
- postRescan All Managed Servers
- postRescan Managed Server
- getDefault Set of Optional Managed Server Components
- postUpdate Managed Server Components
- Repositories
- getGet All Repositories
- postAdd Repository
- postRescan Repositories
- getGet All Repository States
- getGet Repository
- putEdit Repository
- delRemove Repository
- getGet Repository Access Permissions
- putEdit Repository Access Permissions
- getGet All Scale-Out Backup Repositories
- postAdd Scale-Out Backup Repository
- getGet Scale-Out Backup Repository
- putEdit Scale-Out Backup Repository
- delRemove Scale-Out Backup Repository
- postEnable Sealed Mode
- postDisable Sealed Mode
- postEnable Maintenance Mode
- postDisable Maintenance Mode
- Mount Servers
- Proxies
- WAN Accelerators
- Helper Appliance Templates
- High Availability (HA) Cluster
- Jobs
- getGet All Jobs
- postCreate Job
- getGet All Job States
- getGet Job
- putEdit Job
- delDelete Job
- postStart Job
- postStop Job
- postRetry Job
- postDisable Job
- postEnable Job
- postApply Backup Policy Configuration
- postClear Backup Cache
- postClone Job
- postStart Quick Backup for VMware vSphere or VMware Cloud Director VM
- postStart Quick Backup for Hyper-V VM
- postStart Quick Backup for Agent-Managed Machine
- Backups
- getGet All Backups
- getGet Backup
- delDelete Backup
- postView Backup Details
- getGet Backup Objects
- delDelete Backup Object
- postDownload Backup Metadata
- getGet All Backup Files
- getGet Backup File
- postMark Backup File as Clean
- postMark Backup File as Infected
- postRun Health Check and Repair
- postCopy Backups to Another Repository
- postCopy Machine Backups to Another Repository or Folder
- postMove Backup to Another Repository
- postMove Backup Objects to Another Job
- getGet Move/Copy Backup Sessions Awaiting Action
- postManage a Move/Copy Backup Session Awaiting Action
- Backup Objects
- Restore Points
- Restore
- postRestore Entire File Share
- postRestore Entire Object Storage Bucket or Container
- getGet All Mount Points for Instant File Share Recovery
- postStart Instant File Share Recovery
- getGet Mount Point for Instant File Share Recovery
- postStop File Share Publishing
- postStart File Share Migration
- postStart File Share Switchover
- getGet File Share Switchover Settings
- putUpdate File Share Switchover Settings
- postStart File Restore from Unstructured Data Backup
- postUnmount Unstructured Data FLR Volumes
- postProlong a Retrieval Operation from Cold Object Storage
- getGet Cold Object Storage Retrieval Operations
- getGet All Mount Points for Instant Recovery to VMware vSphere
- postStart Instant Recovery to VMware vSphere
- getGet Mount Point for Instant Recovery to VMware vSphere
- postStop Publishing Machine to VMware vSphere
- postStart Migrating Machine to VMware vSphere
- getGet All Mount Points for Instant Recovery to Microsoft Hyper-V
- postStart Instant Recovery to Microsoft Hyper-V
- getGet Mount Point for Instant Recovery to Microsoft Hyper-V
- postStop Publishing Machine to Microsoft Hyper-V
- postStart Migrating Machine to Microsoft Hyper-V
- getGet All Mount Points for Instant Recovery to Microsoft Azure
- postStart Instant Recovery to Microsoft Azure
- getGet Mount Point for Instant Recovery to Microsoft Azure
- getGet All Mount Sessions for Instant Recovery to Microsoft Azure
- postStop Publishing Machine to Microsoft Azure
- postStart Migrating Machine to Microsoft Azure
- getGet Settings for Switchover to Microsoft Azure
- putUpdate Settings for Switchover to Microsoft Azure
- postStart Switchover to Microsoft Azure
- postRestore Entire VMware vSphere VM
- postRestore Entire VMware Cloud Director VM
- postRestore Entire Microsoft Hyper-V VM
- getGet All FCD Mount Points
- postStart Instant FCD Recovery
- getGet FCD Mount Point
- postStop FCD Publishing
- postStart FCD Migration
- postStart File Restore
- postUnmount File System
- postGet User Code for Delegated Restore of Microsoft Entra ID Items
- postGet Credentials for Delegated Restore of Microsoft Entra ID Items
- getGet Redirect URI for Delegated Restore of Microsoft Entra ID Items
- postPerform Authorization Code Exchange for Delegated Restore of Microsoft Entra ID Items
- postMount Microsoft Entra ID Tenant
- postStart Microsoft Entra ID Tenant Restore from Copy
- postUnmount Microsoft Entra ID Tenant
- postStart Microsoft Entra ID Audit Log Restore
- postUnmount Microsoft Entra ID Audit Logs
- postStarts Volume Restore for Agent or Recovery Appliance
- Application Items Restore
- DiskManagement
- postInitialize Disk Management
- postMap Backup Layout to Host Layout Automatically
- putKeep Disk Management Session Alive
- getGet Current Restore Layout of Host
- postApply Backup Layout
- postApply Disk Layout
- postErase Disk
- postRemove Partition
- postResize Partition
- postGet Partition Resize Options
- postRestore Partition
- putUnlock BitLocker-Protected Volume
- putCreate Disk Management Checkpoint
- putRevert to Disk Management Checkpoint
- Recovery Media
- Data Integration API
- Backup Browser
- postValidate Target Machine Credentials
- postValidate FLR Restore Item Target Path
- getGet All File Restore Mount Points
- getGet File Restore Mount Point
- getGet Restored Files Audit
- postBrowse File System
- postCompare Attributes
- postCompare Files and Folders
- postSearch for Files and Folders
- postBrowse Search Results
- postRestore Files and Folders to Original Location
- postRestore Files and Folders to Another Location
- postPrepare Files and Folders for Download
- postDownload Files and Folders
- getDownload Files and Folders
- getGet All Unstructured Data Mount Points
- getGet Unstructured Data Mount Point
- postBrowse Unstructured Data File System
- postGet Restore Points of Unstructured Data File System Item
- postSearch for Files and Folders in Unstructured Data Mount Point
- postBrowse Search Results in Unstructured Data Mount Point
- postCopy Files and Folders to Specific Folder
- postRestore Files and Folders from Unstructured Data Backup
- postPrepare Files and Folders for Download from Unstructured Data Backup
- getDownload Files and Folders
- postCompare Attributes of Unstructured Data Backup with Source
- postCompare Files and Folders of Unstructured Data Backup with Source
- getGet Mount Points of All Microsoft Entra ID Tenants
- getGet Mount Point of Microsoft Entra ID Tenant
- postGet Restore Points of Microsoft Entra ID Tenant
- getGet Protection Scope of Microsoft Entra ID Tenant
- postGet Microsoft Entra ID Items
- postGet Microsoft Entra ID Item
- postGet Restore Points of Microsoft Entra ID Item
- postValidate Microsoft Entra ID Items
- postCheck Microsoft Entra ID Items in Production
- postGenerate Microsoft Entra ID User Passwords
- postRestore Microsoft Entra ID Items
- postRestore Microsoft Entra ID Item Properties
- postCompare Microsoft Entra ID Item Properties
- postStart Comparing Microsoft Entra ID Item Properties
- getGet Comparison Results for Microsoft Entra ID Items
- postStart Comparing Microsoft Entra ID Conditional Access Policy
- getGet Comparison Results for Microsoft Entra ID Conditional Access Policy
- postStart Exporting Microsoft Entra ID Items to JSON
- getGet JSON Export Results for Microsoft Entra ID Items
- postExport Microsoft Entra ID Tenant Objects To JSON
- postExport Microsoft Entra ID Items
- postUpload Microsoft Entra ID Users
- postUpload Microsoft Entra ID Groups
- postUpload Microsoft Entra ID Administrative Units
- postUpload Microsoft Entra ID Roles
- postUpload Microsoft Entra ID Applications
- postUpload Microsoft Entra ID Conditional Access Policies
- postUpload Microsoft Entra ID Device Configurations
- postUpload Microsoft Entra ID Organization Contacts
- postUpload Microsoft Entra ID Devices
- getGet All Restore Sessions of Microsoft Entra ID Tenant
- getGet Restore Session of Microsoft Entra ID Tenant
- getGet Restore Session Logs of Microsoft Entra ID Tenant
- postStop Restore Session of Microsoft Entra ID Tenant
- postReveal Microsoft Entra ID BitLocker Recovery Key
- Tasks
- Replicas
- Replica Restore Points
- Failover
- Failback
- Sessions
- Agents
- getGet All Recovery Tokens
- postCreate Recovery Token
- getGet Recovery Token
- putEdit Recovery Token
- delDelete Recovery Token
- getGet All Protected Linux Computers
- getGet Protected Linux Computer
- getGet All Discovered Entities
- getGet All Agent States
- getGet Agent State
- getGet Agent Backups
- postAttach Backups to Agent
- postDetach Backups from Agent
- getGet Protection Groups
- postAdd Protection Group
- getGet Protection Group
- putEdit Protection Group
- delRemove Protection Group
- postRescan Protection Group
- postEnable Protection Group
- postDisable Protection Group
- postDownload Protection Group Packages
- getGet Discovered Entities
- postRescan Discovered Entities
- postReboot Discovered Entities
- postInstall Agent on Discovered Entities
- postUninstall Agent from Discovered Entities
- postUpgrade Agent on Discovered Entities
- postInstall CBT Driver on Discovered Entities
- postUninstall CBT Driver from Discovered Entities
- postUninstall All Components from Discovered Entities
- postAdd Discovered Entities to Trusted Hosts List
- postPrepare Agent Hosts for Remote Bare Metal Recovery
- postRecreate Embedded Recovery Media on Agent Hosts
- getGet Discovered Entity
- delRemove Discovered Entity
- postCreate Recovery Media Task for Discovered Entity
- getCreate Recovery Media for Discovered Entity
- getGet Linux Agent Packages
- getGet Unix Agent Packages
- getGet Agents Recovery Appliances
- getGet Agents Recovery Appliance
- postReboots Agents Recovery Appliances
- postReboots Agents Recovery Appliance
- Active Directory Domains
- Automation
- postImport Jobs
- postExport Jobs
- postImport Credentials
- postExport Credentials
- postImport Cloud Credentials
- postExport Cloud Credentials
- postImport Proxies
- postExport Proxies
- postImport Servers
- postExport Servers
- postImport Repositories
- postExport Repositories
- postImport Encryption Passwords
- postExport Encryption Passwords
- getGet All Automation Sessions
- getGet Automation Session
- getGet Automation Session Logs
- postStop Automation Session
- Log export
The Malware Detection section defines operations for managing malware events, configuring malware detection settings (suspicious file masks, trusted file extensions and indicators of compromise), managing the malware detection state and exclusions of backup objects, scanning backups with antivirus software or YARA rules, and analyzing backups for signs of encryption.
Get All Malware Events
The HTTP GET request to the /api/v1/malwareDetection/events endpoint gets an array of all malware events created on the backup server.
Available to: Backup Administrator, Security Administrator, Backup Operator, Restore Operator, Backup Viewer, Incident API Operator. Also available to custom roles that have backup or restore permissions.
query Parameters
| skip | integer <int32> Number of events to skip. |
| limit | integer <int32> Default: 200 Maximum number of events to return. |
| orderColumn | string (ESuspiciousActivityEventsFiltersOrderColumn) Sorts events by one of the event parameters. |
| orderAsc | boolean If |
| typeFilter | Array of strings (ESuspiciousActivityType) Filters events by event type. |
| detectedAfterTimeUtcFilter | string <date-time> Returns events detected after the specified time, in UTC. |
| detectedBeforeTimeUtcFilter | string <date-time> Returns events detected before the specified time, in UTC. |
| createdAfterTimeUtcFilter | string <date-time> Returns events created after the specified time, in UTC. |
| createdBeforeTimeUtcFilter | string <date-time> Returns events created before the specified time, in UTC. |
| backupObjectIdFilter | string <uuid> Filters events by backup object ID. |
| stateFilter | Array of strings (ESuspiciousActivityState) Filters events by state. |
| sourceFilter | Array of strings (ESuspiciousActivitySourceType) Filters events by source type. |
| severityFilter | Array of strings (ESuspiciousActivitySeverity) Filters events by severity. |
| createdByFilter | string Filters events by the |
| engineFilter | string Filters events by the |
| machineNameFilter | string Filters events by the |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "data": [
- {
- "id": "8f3c1a20-9b6e-4d11-bb52-1c2d3e4f5a60",
- "type": "EncryptedData",
- "creationTimeUtc": "2026-05-20T10:30:00Z",
- "detectionTimeUtc": "2026-05-20T10:28:00Z",
- "machine": {
- "displayName": "enterprise01",
- "uuid": "564d2b1a-3c4d-5e6f-7a8b-9c0d1e2f3a4b",
- "backupObjectId": "a1b2c3d4-e5f6-4789-9abc-def012345678",
- "restorePointId": "b2c3d4e5-f6a7-4890-8bcd-ef0123456789"
}, - "state": "Created",
- "details": "Potential malware activity detected",
- "source": "InternalVeeamDetector",
- "severity": "Infected",
- "createdBy": "TECH\\Administrator",
- "engine": "Veeam Threat Hunter"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 100
}
}Create Malware Event
The HTTP POST request to the /api/v1/malwareDetection/events endpoint creates a new malware event.
Available to: Backup Administrator, Incident API Operator.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| detectionTimeUtc required | string <date-time> Detection date and time, in UTC. |
required | object (SuspiciousActivityMachineSpec) Machine that you want to mark with the malware event. Specify at least 2 parameters. Note that Veeam Backup & Replication can identify a machine by its FQDN, IPv4 address and IPv6 address only if the machine has been powered on during the backup. If you back up a powered-off machine, Veeam Backup & Replication will not get the machine IP addresses and domain name and will not be able to identify the machine. |
| details required | string Event description. |
| engine required | string Detection engine. |
| severity | string (ECreatingSuspiciousActivitySeverity) Default: "Infected" Malware status enum for creating suspicious activity operation. |
Malware event has been created.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "detectionTimeUtc": "2026-05-20T10:28:00Z",
- "machine": {
- "fqdn": "enterprise01.tech.local",
- "ipv4": "172.24.29.163",
- "uuid": "564d2b1a-3c4d-5e6f-7a8b-9c0d1e2f3a4b",
- "backupObjectId": "a1b2c3d4-e5f6-4789-9abc-def012345678",
- "restorePointId": "b2c3d4e5-f6a7-4890-8bcd-ef0123456789"
}, - "details": "Encrypted data detected on the protected machine.",
- "engine": "Veeam Threat Hunter",
- "severity": "Infected"
}- 201
- 400
- 401
- 403
- 500
{- "data": [
- {
- "id": "8f3c1a20-9b6e-4d11-bb52-1c2d3e4f5a60",
- "type": "EncryptedData",
- "creationTimeUtc": "2026-05-20T10:30:00Z",
- "detectionTimeUtc": "2026-05-20T10:28:00Z",
- "machine": {
- "displayName": "enterprise01",
- "uuid": "564d2b1a-3c4d-5e6f-7a8b-9c0d1e2f3a4b",
- "backupObjectId": "a1b2c3d4-e5f6-4789-9abc-def012345678",
- "restorePointId": "b2c3d4e5-f6a7-4890-8bcd-ef0123456789"
}, - "state": "Created",
- "details": "Potential malware activity detected",
- "source": "InternalVeeamDetector",
- "severity": "Infected",
- "createdBy": "TECH\\Administrator",
- "engine": "Veeam Threat Hunter"
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 100
}
}Get Malware Event
The HTTP GET request to the /api/v1/malwareDetection/events/{id} endpoint gets a malware event that has the specified id.
Available to: Backup Administrator, Security Administrator, Backup Operator, Restore Operator, Backup Viewer, Incident API Operator. Also available to custom roles that have backup or restore permissions.
path Parameters
| id required | string <uuid> Event ID. To get the ID, run the Get All Malware Events request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "id": "8f3c1a20-9b6e-4d11-bb52-1c2d3e4f5a60",
- "type": "EncryptedData",
- "creationTimeUtc": "2026-05-20T10:30:00Z",
- "detectionTimeUtc": "2026-05-20T10:28:00Z",
- "machine": {
- "displayName": "enterprise01",
- "uuid": "564d2b1a-3c4d-5e6f-7a8b-9c0d1e2f3a4b",
- "backupObjectId": "a1b2c3d4-e5f6-4789-9abc-def012345678",
- "restorePointId": "b2c3d4e5-f6a7-4890-8bcd-ef0123456789"
}, - "state": "Created",
- "details": "Potential malware activity detected",
- "source": "InternalVeeamDetector",
- "severity": "Infected",
- "createdBy": "TECH\\Administrator",
- "engine": "Veeam Threat Hunter"
}Get All Malware Detection Settings
The HTTP GET request to the /api/v1/malwareDetection/settings/general endpoint gets all malware detection settings.
Available to: Backup Administrator, Security Administrator, Backup Operator, Restore Operator, Backup Viewer. Also available to custom roles that have backup or restore permissions.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "encryptionDetectionSettings": {
- "inlineMalwareScanEnabled": true,
- "sensitivity": "Normal"
}, - "fileDetectionSettings": {
- "guestIndexScanEnabled": true,
- "detectIndicatorsOfCompromise": true,
- "autoUpdateMalwareDefinitions": true
}, - "notificationSettings": {
- "sendSNMPNotifications": false,
- "sendEmailToRecipients": true,
- "recipients": "soc@tech.local",
- "notificationType": "UseCustomNotificationSettings",
- "notifyOnSuccess": false,
- "notifyOnWarning": true,
- "notifyOnError": true
}, - "incidentAPISettings": {
- "quickBackupOnExternalEventEnabled": true
}, - "signatureDetectionSettings": {
- "detectionEngine": "VeeamThreatHunter",
- "archivesScanEnabled": true,
- "autoSignatureBasedScanEnabled": true,
- "autoResolveEventAfterCleanScan": true
}
}Edit Malware Detection Settings
The HTTP PUT request to the /api/v1/malwareDetection/settings/general endpoint edits malware detection settings.
Available to: Backup Administrator.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
object (MalwareEncryptionDetectionSettingsModel) Malware encryption detection settings. | |
object (MalwareFileDetectionSettingsModel) Malware file detection settings. | |
object (MalwareDetectionEmailNotificationSettingsModel) Malware detection email notification settings. | |
object (MalwareDetectionIncidentAPISettingsModel) Malware detection incident API settings. | |
object (MalwareSignatureDetectionSettingsModel) Malware signature detection settings. |
Malware detection settings have been updated.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "encryptionDetectionSettings": {
- "inlineMalwareScanEnabled": true,
- "sensitivity": "Normal"
}, - "fileDetectionSettings": {
- "guestIndexScanEnabled": true,
- "detectIndicatorsOfCompromise": true,
- "autoUpdateMalwareDefinitions": true
}, - "notificationSettings": {
- "sendSNMPNotifications": false,
- "sendEmailToRecipients": true,
- "recipients": "soc@tech.local",
- "notificationType": "UseCustomNotificationSettings",
- "notifyOnSuccess": false,
- "notifyOnWarning": true,
- "notifyOnError": true
}, - "incidentAPISettings": {
- "quickBackupOnExternalEventEnabled": true
}, - "signatureDetectionSettings": {
- "detectionEngine": "VeeamThreatHunter",
- "archivesScanEnabled": true,
- "autoSignatureBasedScanEnabled": true,
- "autoResolveEventAfterCleanScan": true
}
}- 200
- 400
- 401
- 403
- 404
- 500
{- "encryptionDetectionSettings": {
- "inlineMalwareScanEnabled": true,
- "sensitivity": "Normal"
}, - "fileDetectionSettings": {
- "guestIndexScanEnabled": true,
- "detectIndicatorsOfCompromise": true,
- "autoUpdateMalwareDefinitions": true
}, - "notificationSettings": {
- "sendSNMPNotifications": false,
- "sendEmailToRecipients": true,
- "recipients": "soc@tech.local",
- "notificationType": "UseCustomNotificationSettings",
- "notifyOnSuccess": false,
- "notifyOnWarning": true,
- "notifyOnError": true
}, - "incidentAPISettings": {
- "quickBackupOnExternalEventEnabled": true
}, - "signatureDetectionSettings": {
- "detectionEngine": "VeeamThreatHunter",
- "archivesScanEnabled": true,
- "autoSignatureBasedScanEnabled": true,
- "autoResolveEventAfterCleanScan": true
}
}Get Malware Suspicious File Masks Settings
The HTTP GET request to the /api/v1/malwareDetection/settings/fileDetection/suspiciousFileMasks endpoint gets malware suspicious file masks settings.
Available to: Backup Administrator, Security Administrator, Backup Operator, Restore Operator, Backup Viewer. Also available to custom roles that have backup or restore permissions.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "suspiciousObjects": [
- "*.locked",
- "*.crypted"
], - "trustedExtensions": [
- "*.docx",
- "*.pdf"
], - "trustedPaths": [
- "C:\\Program Files\\Veeam"
]
}Edit Malware Suspicious File Masks Settings
The HTTP PUT request to the /api/v1/malwareDetection/settings/fileDetection/suspiciousFileMasks endpoint edits malware suspicious file masks settings.
Available to: Backup Administrator.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| suspiciousObjects | Array of strings Array of suspicious file masks. |
| trustedExtensions | Array of strings Array of trusted file extensions. |
| trustedPaths | Array of strings Array of trusted file paths. |
Malware suspicious file masks settings have been updated.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "suspiciousObjects": [
- "*.locked",
- "*.crypted"
], - "trustedExtensions": [
- "*.docx",
- "*.pdf"
], - "trustedPaths": [
- "C:\\Program Files\\Veeam"
]
}- 200
- 400
- 401
- 403
- 404
- 500
{- "suspiciousObjects": [
- "*.locked",
- "*.crypted"
], - "trustedExtensions": [
- "*.docx",
- "*.pdf"
], - "trustedPaths": [
- "C:\\Program Files\\Veeam"
]
}Get Malware Allowed Trusted Extensions
The HTTP GET request to the /api/v1/malwareDetection/settings/fileDetection/allowedTrustedExtensions endpoint gets malware allowed trusted extensions.
Available to: Backup Administrator, Security Administrator, Backup Operator, Restore Operator, Backup Viewer, Incident API Operator. Also available to custom roles that have backup or restore permissions.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "allowedExtensions": [
- "docx",
- "pdf",
- "xlsx"
]
}Get Malware File Detection Indicators of Compromise
The HTTP GET request to the /api/v1/malwareDetection/settings/fileDetection/indicatorsOfCompromise endpoint gets the list of indicators of compromise.
Available to: Backup Administrator, Security Administrator, Backup Operator, Restore Operator, Backup Viewer. Also available to custom roles that have backup or restore permissions.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "data": [
- {
- "name": "Mimikatz",
- "description": "Credential dumping tool detected.",
- "status": "Active",
- "attackTactic": "Credential Access"
}, - {
- "name": "PsExec",
- "description": "Remote execution utility detected.",
- "status": "Disabled",
- "attackTactic": "Lateral Movement"
}
]
}Enable Monitoring of Indicators of Compromise
The HTTP POST request to the /api/v1/malwareDetection/settings/fileDetection/indicatorsOfCompromise/enable endpoint enables monitoring of indicators of compromise.
Available to: Backup Administrator.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| indicatorsOfCompromise required | Array of strings unique Array of objects containing details on indicators of compromise. |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "indicatorsOfCompromise": [
- "Mimikatz",
- "PsExec"
]
}- 200
- 401
- 403
- 404
- 500
{- "data": [
- {
- "name": "Mimikatz",
- "description": "Credential dumping tool detected.",
- "status": "Active",
- "attackTactic": "Credential Access"
}, - {
- "name": "PsExec",
- "description": "Remote execution utility detected.",
- "status": "Disabled",
- "attackTactic": "Lateral Movement"
}
]
}Disable Monitoring of Indicators of Compromise
The HTTP POST request to the /api/v1/malwareDetection/settings/fileDetection/indicatorsOfCompromise/disable endpoint disables monitoring of indicators of compromise.
Available to: Backup Administrator.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| indicatorsOfCompromise required | Array of strings unique Array of objects containing details on indicators of compromise. |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "indicatorsOfCompromise": [
- "Mimikatz",
- "PsExec"
]
}- 200
- 401
- 403
- 404
- 500
{- "data": [
- {
- "name": "Mimikatz",
- "description": "Credential dumping tool detected.",
- "status": "Active",
- "attackTactic": "Credential Access"
}, - {
- "name": "PsExec",
- "description": "Remote execution utility detected.",
- "status": "Disabled",
- "attackTactic": "Lateral Movement"
}
]
}Get Logs for SureBackup Scan Task Session
The HTTP GET request to the /api/v1/malwareDetection/scanSessionLog/{id} endpoint gets an array of all log lines for the SureBackup task session with the specified id.
Available to: Backup Administrator, Backup Operator, Restore Operator, Backup Viewer. Also available to custom roles that have backup or restore permissions.
path Parameters
| id required | string <uuid> Task session ID. To get the ID, run the Get All Task Sessions request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "lines": [
- "Starting malware detection scan session.",
- "Scan completed. No threats found."
]
}Mark Backup Objects as Clean
The HTTP POST request to the /api/v1/malwareDetection/backupObjects/markAsClean endpoint marks as clean backup objects that were flagged as suspicious or infected. Use this request if you cleaned the machine of malware or the malware detection event was a false positive.
Available to: Backup Administrator, Incident API Operator.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| objectIds required | Array of strings <uuid> Array of backup object IDs to be marked as clean. |
| reason | string Reason why the backup objects are marked as clean. |
| markRestorePointsAsClean | boolean If |
| excludeFromDetection | boolean If |
| noteForExclusion | string Note for exclusion from detection. |
OK
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "objectIds": [
- "0405a174-dc1a-473a-a2cf-b5b1c8b1b620",
- "3fa85f64-5717-4562-b3fc-2c963f66afa6"
], - "reason": "False positive",
- "markRestorePointsAsClean": true,
- "excludeFromDetection": true,
- "noteForExclusion": "False positive"
}- 200
- 400
- 401
- 403
- 500
{ }Get All Malware Detection Objects
The HTTP GET request to the /api/v1/malwareDetection/backupObjects endpoint gets an array of all malware detection objects created on the backup server.
Available to: Backup Administrator, Security Administrator, Backup Operator, Restore Operator, Backup Viewer. Also available to custom roles that have backup or restore permissions.
query Parameters
| skip | integer <int32> Number of malware detection objects to skip. |
| limit | integer <int32> Default: 200 Maximum number of malware detection objects to return. |
| orderColumn | string (EMalwareDetectionObjectsFiltersOrderColumn) Sorts malware detection objects by one of the object parameters. |
| orderAsc | boolean If |
| detectedAfterTimeUtcFilter | string <date-time> Returns malware detection objects detected after the specified time, in UTC. |
| detectedBeforeTimeUtcFilter | string <date-time> Returns malware detection objects detected before the specified time, in UTC. |
| backupObjectIdFilter | string <uuid> Filters malware detection objects by backup object ID. |
| backupObjectNameFilter | string Filters malware detection objects by backup object name. |
| platformFilter | string Filters malware detection objects by platform. |
| severityFilter | Array of strings (ESuspiciousActivitySeverity) Filters malware detection objects by severity. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "data": [
- {
- "objectId": "c3d4e5f6-a7b8-4901-9cde-f01234567890",
- "objectName": "linuxsrv014",
- "detectedTime": "2026-05-20T10:30:00Z",
- "severity": "Infected",
- "platform": "VMware",
- "objectHostName": "enterprise01.tech.local",
- "sourceTypes": [
- "EncryptedData"
]
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 100
}
}Get Malware Detection Object
The HTTP GET request to the /api/v1/malwareDetection/backupObjects/{id} endpoint gets a malware detection object that has the specified id.
Available to: Backup Administrator, Security Administrator, Backup Operator, Restore Operator, Backup Viewer. Also available to custom roles that have backup or restore permissions.
path Parameters
| id required | string <uuid> Object ID. To get the ID, run the Get All Malware Detection Objects request. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "objectId": "c3d4e5f6-a7b8-4901-9cde-f01234567890",
- "objectName": "linuxsrv014",
- "detectedTime": "2026-05-20T10:30:00Z",
- "severity": "Infected",
- "platform": "VMware",
- "objectHostName": "enterprise01.tech.local",
- "sourceTypes": [
- "EncryptedData"
]
}Get All Malware Detection Exclusions
The HTTP GET request to the /api/v1/malwareDetection/backupObjects/exclusions endpoint gets an array of malware detection exclusions.
Available to: Backup Administrator, Security Administrator, Backup Operator, Restore Operator, Backup Viewer. Also available to custom roles that have backup or restore permissions.
query Parameters
| skip | integer <int32> Number of exclusions to skip. |
| limit | integer <int32> Default: 200 Maximum number of exclusions to return. |
| orderColumn | string (EMalwareObjectExclusionsFiltersOrderColumn) Sorts exclusions by one of the exclusion parameters. |
| orderAsc | boolean If |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 500
{- "data": [
- {
- "id": "d4e5f6a7-b8c9-4012-9def-012345678901",
- "name": "linuxsrv014",
- "platform": "VMware",
- "platformId": "e5f6a7b8-c9d0-4123-8ef0-123456789012",
- "note": "Trusted lab machine.",
- "paths": [
- "/var/log"
], - "activities": [
- "EncryptedData"
], - "autoScanDisabled": true,
- "excludeEntireObject": false
}
], - "pagination": {
- "total": 2,
- "count": 2,
- "skip": 0,
- "limit": 100
}
}Create or Update Malware Detection Exclusions
The HTTP POST request to the /api/v1/malwareDetection/backupObjects/exclusions endpoint creates new malware detection exclusions and updates existing ones.
Available to: Backup Administrator.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/json
required | Array of objects (MalwareDetectionCommonSpec) Array of malware detection exclusions to import. |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "data": [
- {
- "type": "ObjectId",
- "id": "d4e5f6a7-b8c9-4012-9def-012345678901",
- "note": "Trusted lab machine.",
- "paths": [
- "/var/log"
], - "activities": [
- "EncryptedData"
], - "autoScanDisabled": true,
- "excludeEntireObject": false
}, - {
- "type": "InventoryObject",
- "note": "Trusted production machine.",
- "paths": [
- "/etc"
], - "activities": [
- "RenamedFiles"
], - "autoScanDisabled": false,
- "excludeEntireObject": true,
- "inventoryObject": {
- "platform": "VSphere",
- "hostName": "vcenter01.tech.local",
- "name": "linuxsrv014",
- "type": "VirtualMachine",
- "objectId": "vm-49862",
- "urn": "vc:vcenter01.tech.local;vm:vm-49862",
- "size": "124.4 GB"
}
}
]
}- 200
- 401
- 403
- 500
{- "data": [
- {
- "id": "d4e5f6a7-b8c9-4012-9def-012345678901",
- "name": "linuxsrv014",
- "platform": "VMware",
- "platformId": "e5f6a7b8-c9d0-4123-8ef0-123456789012",
- "note": "Trusted lab machine.",
- "paths": [
- "/var/log"
], - "activities": [
- "EncryptedData"
], - "autoScanDisabled": true,
- "excludeEntireObject": false
}
]
}Delete Malware Detection Exclusions
The HTTP POST request to the /api/v1/malwareDetection/backupObjects/exclusions/delete endpoint deletes malware detection exclusions specified in the request body by their IDs.
Available to: Backup Administrator.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/json
Removed.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
[- "5b8c2a14-7d3e-4f90-a1b2-c3d4e5f60718",
- "6c9d3b25-8e4f-40a1-b2c3-d4e5f6071829"
]- 401
- 403
- 500
{- "errorCode": "AccessDenied",
- "message": "Unauthorized. Get bearer JWT token at /api/login"
}Get YARA Rules
The HTTP GET request to the /api/v1/malwareDetection/yaraRules endpoint gets YARA rules located in the Veeam Backup & Replication installation folder. The default path is %ProgramFiles%\Veeam\Backup and Replication\Backup\YaraRules for Microsoft Windows-based backup servers and /var/lib/veeam/yara_rules for Linux-based backup servers.
Available to: Backup Administrator, Restore Operator, Incident API Operator. Also available to custom roles that have restore permissions.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 200
- 401
- 403
- 404
- 500
{- "data": [
- {
- "fileName": "FindFileByHash.yara"
}, - {
- "fileName": "FindFileByParameters.yara"
}, - {
- "fileName": "FindString.yara"
}
], - "pagination": {
- "total": 3,
- "count": 3,
- "skip": 0,
- "limit": 3
}
}Scan Backups with Antivirus or YARA Rules
The HTTP POST request to the /api/v1/malwareDetection/scanBackup endpoint scans backups with antivirus or YARA rules.
Available to: Backup Administrator.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| type required | string (EMalwareBackupScanSpecType) Malware backup scan specification type. | ||||||||||
| scanMode required | string (EMalwareBackupScanMode) Backup scan mode.
| ||||||||||
required | object (MalwareBackupScanSpecEngine) Type of backup scan engine. | ||||||||||
required | Array of objects (BackupObjectPair) Array of objects containing the backup IDs and backup object IDs. | ||||||||||
| restorePointId | string <uuid> ID of the restore point to scan. Required when | ||||||||||
object (MalwareBackupScanRange) Backup scan range. If you do not specify this parameter, Veeam Backup & Replication will scan all available restore points. | |||||||||||
| continueScan | boolean If |
A SureBackup session has been created to scan the backup. To check the progress, track the session state.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "type": "Backup",
- "backupObjectPair": [
- {
- "backupId": "ffcedddf-577d-4033-aab8-9c6f46c82b8d",
- "backupObjectId": "67785a3a-dd33-4f33-9869-111ece902f9b"
}
], - "scanMode": "AllInInterval",
- "scanEngine": {
- "useAntivirusEngine": false,
- "useYaraRule": true,
- "yaraRule": {
- "fileName": "FindFileByHash.yara"
}
}
}- 201
- 400
- 401
- 403
- 500
{- "sessionType": "SureBackup",
- "state": "Stopped",
- "id": "a330c612-07b2-4c3a-adbf-0007f904bbfd",
- "name": "Scan Backup",
- "jobId": "34b77de9-d5e2-4752-aff8-929bc428e80f",
- "creationTime": "2024-11-11T12:34:46.027793",
- "endTime": "2024-11-11T12:45:22.123456",
- "progressPercent": 100,
- "result": {
- "result": "Success",
- "message": "Success",
- "isCanceled": false
}, - "resourceId": "a330c612-07b2-4c3a-adbf-0007f904bbfd",
- "usn": 0
}Start Malware Encryption Analysis
The HTTP POST request to the /api/v1/malwareDetection/analyzeEncryption endpoint starts a malware encryption analysis job based on a suspicious activity event. The request returns a session model that tracks the analysis job progress.
Available to: Backup Administrator.
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
Request Body schema: application/jsonrequired
| eventId required | string <uuid> ID of the suspicious activity event to analyze. To get the ID, run the Get All Malware Events request. |
Accepted. The encryption analysis job has been started.
Bad request. This error is related to POST/PUT requests. The request body is malformed, incomplete or otherwise invalid.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- Payload
- curl
- Python
- JavaScript
- C#
- Go
{- "eventId": "8f3c1a20-9b6e-4d11-bb52-1c2d3e4f5a60"
}- 202
- 400
- 401
- 403
- 404
- 500
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "jobId": "9d222c6d-893e-4e79-8201-3c9ca16a0f39",
- "sessionType": "Infrastructure",
- "creationTime": "2019-08-24T14:15:22Z",
- "endTime": "2019-08-24T14:15:22Z",
- "state": "Stopped",
- "progressPercent": 0,
- "result": {
- "result": "None",
- "message": "string",
- "isCanceled": true
}, - "resourceId": "026d60bb-63a8-407e-bf67-01dcfc6022e6",
- "resourceReference": "string",
- "parentSessionId": "b1d7834e-fe2f-4cad-b0e5-ff5c5615f344",
- "usn": 0,
- "platformName": "VMware",
- "platformId": "32a6e381-64f4-4911-86b6-3bf681b64d23",
- "initiatedBy": "string",
- "relatedSessionId": "f3a08375-4fc2-4154-a968-538c1da6dd56",
- "algorithm": "Full",
- "progress": {
- "duration": "string",
- "processingRate": "string",
- "bottleneck": "NotDefined",
- "processedSize": 0,
- "readSize": 0,
- "transferredSize": 0,
- "progressPercent": 0
}, - "originalSessionId": "1db29c85-df48-4dff-a498-05491cf54d6f",
- "retryInfo": {
- "isRecheckRetry": true,
- "retryNumber": 0
}
}Download Malware Encryption Analysis Logs
The HTTP GET request to the /api/v1/malwareDetection/analyzeEncryption/{sessionId}/logs endpoint downloads the log file from a completed malware encryption analysis session.
Available to: Backup Administrator.
path Parameters
| sessionId required | string <uuid> Session ID of the completed encryption analysis job. To get the session ID, run the Start Malware Encryption Analysis request or check the Get Session endpoint. |
header Parameters
| x-api-version required | string Default: 1.3-rev2 Version and revision of the client REST API. Must be in the following format: |
OK. The log file is returned.
Unauthorized. The authorization header has been expected but not found (or found but is expired).
Forbidden. The user sending the request does not have adequate privileges to access one or more objects specified in the request.
Not found. No object was found with the path parameter specified in the request.
Internal server error. The request has been received but could not be completed because of an internal error at the server side.
- curl
- Python
- JavaScript
- C#
- Go
- 401
- 403
- 404
- 500
{- "errorCode": "AccessDenied",
- "message": "Unauthorized. Get bearer JWT token at /api/login"
}