Commvault is integrating Google Threat Intelligence into its Threat Scan workflows. The integration is designed to help companies find clean recovery points more quickly following a cyberattack. In addition, the company is introducing inline scanning that automatically collects file hashes during backups.
Anyone looking to restore data after an attack often has to determine which backup is still clean. Security teams typically identify Indicators of Compromise (IOCs) quickly. But recovery teams must then validate that backup data before the recovery process can begin. And every minute of downtime counts.
That’s exactly what Commvault is targeting with this new partnership. Google Threat Intelligence combines Mandiant’s frontline intelligence, VirusTotal’s crowdsourced data, and the insights Google gains from protecting billions of users. That data and those scanning capabilities now flow directly into Commvault’s Threat Scan workflows.
File fingerprinting
The integration analyzes protected workloads for malware and identifies which recovery points are infected. Customers also receive context about detected threats, enabling teams to conduct further investigation. Another new feature is an inline inspection that collects file hashes during the backup process itself. These hashes act as individual fingerprints and can be rapidly checked against known threat intelligence indicators.
The approach is layered. Users start with a quick validation using threat intelligence and only conduct deeper malware, encryption, and forensic investigations when necessary. These insights also enhance Commvault’s Synthetic Recovery, which automatically detects and removes threats during recovery while keeping the good data intact.
“Businesses need confidence that the data they’re restoring is clean,” says Pranay Ahlawat, Chief Technology and AI Officer at Commvault.
According to Commvault, the Google Threat Intelligence integration, inline scanning, and related Threat Scan enhancements will become available in the coming months.