Threat Scan enhances security by providing visibility into abnormal activity across protected resources.
-
Resources: View overviews of each individual resource and run Threat Scan on them.
-
Anomalies: Identify anomalies in files and backup jobs that may indicate ransomware, data corruption, or unauthorized file activity. The system uses historical baselines, statistical thresholds, and file metadata validation to detect unusual behavior.
-
Threats: Scan for malware and encryption threats within backup data. Multiple detection engines and models analyze backup content to identify threats with high accuracy.
-
Partner signals: Third-party indicator of attack (IOA) detection from integrated security tools. These are shown on the Threat Scan dashboard to correlate suspected attack activity with protected workloads and help prioritize investigation and recovery actions. Threat Scan supports integration with the following third-party tools:
-
CrowdStrike Falcon Insight XDR
-
Darktrace
-
Netskope Cloud Threat Exchange (CTE)
-