Skip to main content
Question

Malware Detection


hs08
Forum|alt.badge.img+1
  • Comes here often
  • 57 comments

When we enable ‘Guest file system indexing and malware detection’, this mean if the VM source infected by malware then VBR will send alert to us and keeping backup running?

If i want to test this, can i testing by simply put eicar file into the source VM?

13 comments

tarik.yenisey
Forum|alt.badge.img+5
  • Influencer
  • 138 comments
  • November 26, 2024

I tried this with Eicar. Veeam detected it when I turned on index level control. But I found which files it detected virus in sure backup and Veeam's antivirus scan


waqasali
Forum|alt.badge.img+3
  • Influencer
  • 198 comments
  • November 26, 2024

Hi ​@hs08 

 

To detect malware in Veeam environments, it’s important to implement a combination of technical tools (such as antivirus software, Veeam's built-in ransomware protection, and backup integrity checks) and best practices (such as regular scanning, monitoring, and encryption). Leveraging Veeam’s advanced features, along with security tools, can help maintain the integrity of your backup environment and provide peace of mind that your data is safe, even from evolving malware threats.

 

 

 


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1354 comments
  • November 26, 2024

Hi ​@hs08

The Guest Indexing Data Scan is not a classical anti-virus and doesn’t search explicitly for malware. It searches for suspicious files and known ransomware extensions. So if you want to test it, you can check the content of the SuspiciousFiles.xml and place such a file inside of a VM. You can find all the details in the following helpcenter article:

https://helpcenter.veeam.com/docs/backup/vsphere/malware_detection_guest_index.html?ver=120

 

The inline scan might be able to detect the EICAR string, but again that’s not a replacement for an anti-virus.

https://helpcenter.veeam.com/docs/backup/vsphere/malware_detection_data_blocks.html?ver=120


hs08
Forum|alt.badge.img+1
  • Author
  • Comes here often
  • 57 comments
  • November 28, 2024

I test only enabling the ‘enable guest file system indexing and malware detection’ the i run the backup job.

after that i create file extension which listed in suspicious file xml called test.1cbu1 then run the job again. I can see i not yet receive any alert for this suspicious file, are this is behavior of ‘enable guest file system indexing and malware detection’?


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1354 comments
  • November 28, 2024

Can you please check whether then file system scan is enabled in the global malware detection settings?

https://helpcenter.veeam.com/docs/backup/vsphere/malware_detection_guest_index_enable.html?ver=120


hs08
Forum|alt.badge.img+1
  • Author
  • Comes here often
  • 57 comments
  • November 28, 2024

I use community version and this menu is greyed out, this mean the file system scan is disabled?

 


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1354 comments
  • November 28, 2024

Unfortunately the Community Edition doesn’t include the malware/ransomware detection features. That’s why both are disabled and greyed out.


hs08
Forum|alt.badge.img+1
  • Author
  • Comes here often
  • 57 comments
  • November 29, 2024

Hi ​@regnor 

yes it’s work now after assigning license and enable the malware detection setting

 


AndrePulia
Forum|alt.badge.img+7
  • Veeam Legend, Veeam Vanguard
  • 345 comments
  • November 29, 2024

that’s a great discusison. very good to have this topic here


hs08
Forum|alt.badge.img+1
  • Author
  • Comes here often
  • 57 comments
  • December 4, 2024

Hello,

Veeam use suspicious.xml file to detect malware, are this file is update automatically incase to detect if there any ne variance if malware?


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1354 comments
  • December 4, 2024

Yes, the file is automatically update. That’s also in the helpcenter article from above:

Veeam Backup & Replication will communicate with the Veeam Update Server (vbr.butler.veeam.com) daily and download the latest version of the SuspiciousFiles.xml file. By default, this occurs once a day at 12:00 AM.


AndrePulia
Forum|alt.badge.img+7
  • Veeam Legend, Veeam Vanguard
  • 345 comments
  • December 6, 2024

Hi All, I’m trying to understand the term entrophy, does anyone know how to explaing taht? I have had the manual, but, i didn’t undestand it so far.


waqasali
Forum|alt.badge.img+3
  • Influencer
  • 198 comments
  • December 8, 2024

Hi ​@hs08 considerations & best practices avoid using EICAR or similar files in critical production environments, as they might trigger unintended alerts or actions and ensure the antivirus used for detection is correctly integrated and up to date and plan how to handle detected malware (e.g., quarantining affected files, adjusting backup strategies) and always test in a non-production or isolated environment to prevent unnecessary alerts in the production setup.

 


Comment