Skip to main content
Veeam Oxford Style Debate #4

Veeam Oxford Style Debate – Episode 4 -Who Should Detect Malware?

  • October 5, 2026
  • 3 comments
  • 37 views
Madi.Cristil
Forum|alt.badge.img+9

Happy Monday Community! 

Your favorite contest ,  Veeam Oxford Style Debate is back! 

October is Cybersecurity Awareness Month, so I thought we should use the occasion to start a debate around something we’re hearing more and more about: malware detection in the backup environment.

 

Debate Statement: 

“Using Veeam for malware detection (Inline Entropy and YARA scanning) is a distraction from dedicated EDR tools.”  ( thank you ​@Viperian for this one 😉)

 

What I am looking for this round

 Real-world experience with Veeam’s malware detection capabilities
 Where you see Inline Entropy and YARA scanning adding value — or falling short
 How you see these capabilities working alongside EDR
 And most importantly, why you agree or disagree with the statement

I’m not looking for a simple “EDR is better” or “Veeam can do it too.” Bring your examples, technical arguments, and different perspectives.

 

New Here? 

 

  • Pick a side: FOR or AGAINST
  • Keep it concise.
  • Challenge someone else's argument.
  • Back your opinion with real-world experience.

 FOR or AGAINST? Let the debate begin!

3 comments

Madi.Cristil
Forum|alt.badge.img+9
  • Author
  • Principal Community Manager
  • October 5, 2026

I am challenging ​@eblack 


eblack
Forum|alt.badge.img+4
  • Influencer
  • October 5, 2026

I am challenging ​@eblack 

I’ll have to give this one full thought before I answer! :)


eblack
Forum|alt.badge.img+4
  • Influencer
  • October 5, 2026

I’m taking against on this one.

Most of my view comes from the recovery work we do at Recovery Point. EDR is important and I’d never argue otherwise. It gives you visibility into what’s happening on the endpoint and in the live environment, which is where it belongs. But once you’re recovering from a cyber event, the problem changes shape. You’re not just trying to figure out what happened anymore. You’re also trying to figure out what you can trust enough to put back into prod.

That’s where Veeam’s malware detection has value for us. We use the entropy analysis and YARA capabilities, and we’ve built out our own custom YARA rules around it. Those have been excellent because they let us look for things that matter in the kind of recovery work we’re doing instead of relying only on a generic detection set.

We also use Predatar alongside Veeam for scanning and validation, so we’re not looking at recovery through just one tool or one detection method.

I think that’s where the “distraction from EDR” argument stops for me personally. Nobody on our side is trying to make Veeam into an EDR platform. What we’re trying to avoid is getting into a serious ransomware recovery and then depending on one layer to tell us whether the data we’re about to restore is good.

As we all know, a successful backup job doesn’t mean you have a clean recovery point. Those are two different things, and anyone who’s spent enough time in DR has seen why that distinction matters during a ransomware recovery.

So from my side, I want EDR doing its job in production. I also want Veeam looking at what’s happening in the backup data, our own YARA rules available when we need to dig into something, and Predatar giving us another way to scan and validate before something goes back into service.

 

 

I challenge ​@kciolek