Skip to main content
Veeam Oxford Style Debate #4

Veeam Oxford Style Debate – Episode 4 -Who Should Detect Malware?

  • October 5, 2026
  • 4 comments
  • 76 views
Madi.Cristil
Forum|alt.badge.img+9

Happy Monday Community! 

Your favorite contest ,  Veeam Oxford Style Debate is back! 

October is Cybersecurity Awareness Month, so I thought we should use the occasion to start a debate around something we’re hearing more and more about: malware detection in the backup environment.

 

Debate Statement: 

“Using Veeam for malware detection (Inline Entropy and YARA scanning) is a distraction from dedicated EDR tools.”  ( thank you ​@Viperian for this one 😉)

 

What I am looking for this round

 Real-world experience with Veeam’s malware detection capabilities
 Where you see Inline Entropy and YARA scanning adding value — or falling short
 How you see these capabilities working alongside EDR
 And most importantly, why you agree or disagree with the statement

I’m not looking for a simple “EDR is better” or “Veeam can do it too.” Bring your examples, technical arguments, and different perspectives.

 

New Here? 

 

  • Pick a side: FOR or AGAINST
  • Keep it concise.
  • Challenge someone else's argument.
  • Back your opinion with real-world experience.

 FOR or AGAINST? Let the debate begin!

4 comments

Madi.Cristil
Forum|alt.badge.img+9
  • Author
  • Principal Community Manager
  • October 5, 2026

I am challenging ​@eblack 


eblack
Forum|alt.badge.img+4
  • Influencer
  • October 5, 2026

I am challenging ​@eblack 

I’ll have to give this one full thought before I answer! :)


eblack
Forum|alt.badge.img+4
  • Influencer
  • October 5, 2026

I’m taking against on this one.

Most of my view comes from the recovery work we do at Recovery Point. EDR is important and I’d never argue otherwise. It gives you visibility into what’s happening on the endpoint and in the live environment, which is where it belongs. But once you’re recovering from a cyber event, the problem changes shape. You’re not just trying to figure out what happened anymore. You’re also trying to figure out what you can trust enough to put back into prod.

That’s where Veeam’s malware detection has value for us. We use the entropy analysis and YARA capabilities, and we’ve built out our own custom YARA rules around it. Those have been excellent because they let us look for things that matter in the kind of recovery work we’re doing instead of relying only on a generic detection set.

We also use Predatar alongside Veeam for scanning and validation, so we’re not looking at recovery through just one tool or one detection method.

I think that’s where the “distraction from EDR” argument stops for me personally. Nobody on our side is trying to make Veeam into an EDR platform. What we’re trying to avoid is getting into a serious ransomware recovery and then depending on one layer to tell us whether the data we’re about to restore is good.

As we all know, a successful backup job doesn’t mean you have a clean recovery point. Those are two different things, and anyone who’s spent enough time in DR has seen why that distinction matters during a ransomware recovery.

So from my side, I want EDR doing its job in production. I also want Veeam looking at what’s happening in the backup data, our own YARA rules available when we need to dig into something, and Predatar giving us another way to scan and validate before something goes back into service.

 

 

I challenge ​@kciolek


Jean.peres.bkp
Forum|alt.badge.img+9

AGAINST

I disagree with the statement that using Veeam for malware detection is a distraction from dedicated EDR tools.

EDR solutions are designed to detect, investigate, and respond to threats in real time. They monitor processes, memory, user activity, network connections, and other behavioral indicators to stop attacks as they happen. Their primary objective is prevention and containment.

Veeam’s malware detection capabilities, including Inline Entropy Analysis and YARA Scanning, address a different challenge: understanding the integrity of backup data and identifying potentially compromised restore points. They do not replace EDR, but they provide valuable visibility into an area that traditional security tools often overlook, the backup repository itself.

 

“How did the attack happen?”

“What is our last known clean recovery point?”

This is where Veeam adds significant value. Inline Entropy Analysis can detect unusual changes in data patterns that may indicate encryption activity, while YARA scanning can help identify known malware signatures within backup data.

Together, these capabilities help organizations make faster and more informed recovery decisions.

 

Now, I'll pass the microphone to ​@Dynamic 🎙