Skip to main content

Deploying and using a Yara rule with Veeam


leduardoserrano
Forum|alt.badge.img+6

Hi! In the recent Veeam Backup & Replication v12.1, Veeam brings many new features and capabilities related to data security and integrations with cybersec tools. One of them is the capability to scan backup files with Yara rules.

This is a great feature due to the native flexibility of Yara rules and its wide use in the community.

In this demonstration, we will see how to create a simple Yara rule, associate a malicious file with a VM, and obtain uncompromised recovery points through a scan operation. Everything is effortless and intuitive. I hope it is helpful for the community!

 

 

7 comments

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8512 comments
  • January 18, 2024

Thanks for sharing this as I am interested in YARA stuff and getting more details.


NZ_BenThomas
Forum|alt.badge.img+3
  • Veeam Vanguard
  • 89 comments
  • January 18, 2024

Thanks for the share :) It’s great to see more people trying this out, and I think it’s definitely going to be one of those Veeam features we look back on and think damn how did we do without it??


wolff.mateus
Forum|alt.badge.img+11
  • Veeam Vanguard
  • 542 comments
  • January 18, 2024

Very nice post @leduardoserrano!


Moustafa_Hindawi
Forum|alt.badge.img+6

Thank you @leduardoserrano  for sharing


leduardoserrano
Forum|alt.badge.img+6
  • Author
  • On the path to Greatness
  • 353 comments
  • January 24, 2024
Moustafa_Hindawi wrote:

Thank you @leduardoserrano  for sharing

🙏🏻


Scott
Forum|alt.badge.img+9
  • Veeam Legend
  • 1003 comments
  • January 29, 2024

Great post. I think this feature is only going to become more and more useful and excited to see where it goes. 


leduardoserrano
Forum|alt.badge.img+6
  • Author
  • On the path to Greatness
  • 353 comments
  • January 29, 2024
Scott wrote:

Great post. I think this feature is only going to become more and more useful and excited to see where it goes. 

I agree, @Scott !!! 👏