Loading...
Loading...
This article documents how to investigate which files are encrypted within a machine when the Malware Detection system flags a machine as having Encrypted data. This tool only works for malware inline detection events created by Veeam Backup & Replication 12.1.2 and newer. Previous versions of Veeam Backup & Replication are not supported.
Protected Workload Guest OS Requirement This tool only supports investigating the backup files from Windows-based machines.
Investigation Tool Files v2 (VBR v12.x and v13) What's New New in v2.1 Added support for backups from Nutanix AHV. If the script is run without any parameters, it will now automatically detect the latest malware encrypted event and generate a report. Added a column to the report for EstimatedFileEncryption. Improvements to the script to cause the paths in the .csv file to now list paths similar to those expected on the source VM, and no longer display paths like "C:\VeeamFLR\VMName\Volume2\...". A subfolder with the VM name will now be created in the output folder to store the results. The boolean parameter -SkipSmallFilesInResult was added to force the script to exclude information about files smaller than 8 KB from the output report. The script will now attempt to detect and skip disks that do not have a DiskID. Support for non-default-location installs has been improved by adding the ability to pass the installation location using the parameter -CorePath to declare the folder where Veeam.Backup.CatalogFsLib.dll is located.
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.