Veeam
Telemetry Evidence
These values show how indexed rules identify Veeam telemetry.Kusto
Veeam_GetFinishedConfigurationBackupSessions Veeam_GetJobFinished Veeam_GetSecurityEvents VeeamMalwareEvents_CL VeeamOneTriggeredAlarms_CL VeeamSecurityComplianceAnalyzer_CL VeeamSessions_CL
Detection Rules
Kusto #
- Adding User or Group Failed source low: Detects failed attempts to add a user or user group to Veeam Backup & Replication.
- Application Group Deleted source informational: Detects when an application group is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Application Group Settings Updated source informational: Detects when application group settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Archive Repository Deleted source high: Detects when an archive repository is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Archive Repository Settings Updated source low: Detects when archive repository settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Attempt to Delete Backup Failed source high: Detects failed backup operations. This might indicate system or storage issues, or a potential sabotage of the backup infrastructure.
- Attempt to Update Security Object Failed source high: Detects failed attempts to update security objects in Veeam Backup & Replication. Security objects include users and roles, credential records, certificates, or passwords.
- Backup Proxy Deleted source informational: Detects when a backup proxy is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Backup Repository Deleted source high: Detects when a backup repository is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Backup Repository Settings Updated source low: Detects when backup repository settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
Show 103 more
- Best Practice Compliance Check Not Passed source medium: Detects when a security best practice does not pass a compliance check in Veeam Security & Compliance Analyzer.
- Cloud Gateway Deleted source informational: Detects when a cloud gateway is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Cloud Gateway Pool Deleted source informational: Detects when a cloud gateway pool is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Cloud Gateway Pool Settings Updated source informational: Detects when cloud gateway pool settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Cloud Gateway Settings Updated source informational: Detects when cloud gateway settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Cloud Replica Permanent Failover Performed by Tenant source high: Detects permanent failover of a cloud replica initiated by a tenant. This might indicate disaster recovery activity or issues with primary systems.
- Configuration Backup Failed source high: Detects failed configuration backup operations. This might indicate system or storage issues, or a potential sabotage of the backup infrastructure.
- Configuration Backup Job Failed source medium: Detects failed configuration backup operations. This might indicate system or storage issues, or a potential sabotage of the backup infrastructure.
- Configuration Backup Job Settings Updated source informational: Detects when configuration backup job settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Connection to Backup Repository Lost source high: Detects when a backup server fails to connect to a backup repository.
- Credential Record Deleted source high: Detects when a credential record is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Credential Record Updated source high: Detects when a credential record is updated in Veeam Backup & Replication.
- Detaching Backups Started source informational: Detects when a backup file is detached from a backup job.
- Encryption Password Added source informational: Detects when an encryption password is added to Veeam Backup & Replication.
- Encryption Password Changed source high: Detects when an encryption password is updated in Veeam Backup & Replication.
- Encryption Password Deleted source high: Detects when an encryption password is deleted in Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- External Repository Deleted source high: Detects when an external repository is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- External Repository Settings Updated source informational: Detects when external repository settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Failover Plan Deleted source low: Detects when a failover plan is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Failover Plan Failed source low: Detects when a failover plan fails. This might indicate disaster recovery activity or issues with primary systems.
- Failover Plan Settings Updated source informational: Detects when failover plan settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Failover Plan Started source high: Detects when a failover plan starts. This might indicate disaster recovery activity or issues with primary systems.
- Failover Plan Stopped source medium: Detects when a failover plan stops. This might indicate disaster recovery activity or issues with primary systems.
- File Server Deleted source high: Detects when a file server is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- File Server Settings Updated source informational: Detects when file server settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- File Share Deleted source high: Detects when a file share is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Four-Eyes Authorization Disabled source high: Detects when four-eyes authorization is disabled.
- Four-Eyes Authorization Request Created source high: Detects when a four-eyes authorization request is created.
- Four-Eyes Authorization Request Expired source medium: Detects when a four-eyes authorization request is expired.
- Four-Eyes Authorization Request Rejected source informational: Detects when a four-eyes authorization request is rejected.
- General Settings Updated source informational: Detects when Veeam Backup & Replication general settings are updated. This might indicate configuration changes that require review.
- Global Network Traffic Rules Deleted source low: Detects when a global network traffic rule is deleted in Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Global VM Exclusions Added source high: Detects when global VM exclusion are added in Veeam Backup & Replication.
- Global VM Exclusions Changed source high: Detects when global VM exclusions are updated in Veeam Backup & Replication.
- Global VM Exclusions Deleted source low: Detects when a VM is removed from global exclusions in Veeam Backup & Replication. This might indicate unauthorized changes.
- Host Deleted source low: Detects when a host is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Host Settings Updated source informational: Detects when host settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Hypervisor Host Deleted source informational: Detects when a hypervisor host is deleted from Veeam Backup & Replication. This might indicate unauthorized changes to the virtualization environment.
- Hypervisor Host Settings Updated source informational: Detects when hypervisor host settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Invalid Code for Multi-Factor Authentication Entered source high: Detects failed multi-factor authentication attempts. This might indicate credential stuffing or brute-force attacks.
- Job Deleted source high: Detects when a job is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Job No Longer Used as Second Destination source high: Detects when a job used as a secondary destination is removed.
- KMS Key Rotation Job Finished source informational: Detects when a KMS key rotation job is finished.
- KMS Server Deleted source high: Detects when a KMS server is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- KMS Server Settings Updated source high: Detects when KMS server settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- License Expired source high: Detects when a Veeam license is expired. This could impact backup operations and data protection.
- License Expiring source informational: Detects when a Veeam license expires shortly.
- License Grace Period Started source high: Detects when a Veeam license grace period starts. This might indicate potential licensing issues that need attention.
- License Limit Exceeded source medium: Detects when the Veeam license limit is exceeded.
- License Removed source high: Detects when the Veeam license is removed from Veeam Backup & Replication.
- License Support Expired source high: Detects when the Veeam support contract is expired. This might impact backup operations and data protection.
- License Support Expiring source low: Detects when the Veeam support contract expires shortly.
- Malware Activity Detected source high: Detects when restore points marked as suspicious. This might indicate potential compromise of backup data.
- Malware Detection Exclusions List Updated source medium: Detects when malware detection exclusions are updated. This might indicate potential compromise of backup data.
- Malware Detection Session Finished source informational: Detects when malware detection session finishes.
- Malware Detection Settings Updated source high: Detects when malware detection settings are updated.
- Multi-Factor Authentication Disabled source high: Detects when multi-factor authentication is disabled for all users.
- Multi-Factor Authentication for User Disabled source high: Detects when multi-factor authentication is disabled for a specific user.
- Multi-Factor Authentication Token Revoked source medium: Detects when a multi-factor authentication token is revoked.
- Multi-Factor Authentication User Locked source high: Detects when the allowed number of multi-factor authentication attempts is exceeded for a user.
- NDMP Server Deleted source informational: Detects when an NDMP server is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Object Marked as Clean source informational: Detects when an object is marked as clean.
- Object Storage Deleted source high: Detects when an object storage is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Object Storage Settings Updated source low: Detects when object storage settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Objects Added to Malware Detection Exclusions source high: Detects when an object is added to malware detection exclusions.
- Objects Deleted from Malware Detection Exclusions source informational: Detects when an object is deleted from malware detection exclusions.
- Objects for Job Deleted source high: Detects when objects are deleted from the job. This might indicate unauthorized removal of critical components.
- Objects for Protection Group Changed source informational: Detects when protection group objects are updated.
- Objects for Protection Group Deleted source high: Detects when objects are deleted from a protection group. This might indicate unauthorized removal of critical components.
- Preferred Networks Deleted source informational: Detects when a preferred network is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Protection Group Deleted source high: Detects when a protection group is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Protection Group Settings Updated source informational: Detects when protection group settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Recovery Token Deleted source low: Detects when a recovery token is deleted. This might indicate unauthorized removal of critical components.
- Restore Point Marked as Clean source informational: Detects when a restore point is marked as clean.
- Restore Point Marked as Infected source high: Detects when a restore point is marked as infected.
- Scale-Out Backup Repository Deleted source high: Detects when a scale-out backup repository is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Scale-Out Backup Repository Settings Updated source low: Detects when scale-out backup repository settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Service Provider Deleted source informational: Detects when a service provider is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Service Provider Updated source informational: Detects when service provider settings are updated in Veeam Backup & Replication.
- SSH Credentials Changed source high: Detects when SSH credentials are updated.
- Storage Deleted source high: Detects when storage is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Storage Settings Updated source informational: Detects when storage settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- Subtenant Deleted source high: Detects when a subtenant is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Subtenant Updated source informational: Detects when subtenant settings are updated in Veeam Backup & Replication.
- SureBackup Job Failed source high: Detects failed SureBackup job operations. This might indicate malware issues, storage problems, or potential sabotage of backup infrastructure.
- Tape Erase Job Started source high: Detects when tape erase operations start. This might indicate data destruction activity.
- Tape Library Deleted source informational: Detects when a tape library is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Tape Media Pool Deleted source informational: Detects when a tape media pool is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Tape Media Vault Deleted source informational: Detects when a tape media vault is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Tape Medium Deleted source high: Detects when a tape medium is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Tape Server Deleted source informational: Detects when a tape server is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Tenant Password Changed source high: Detects when a tenant password is updated.
- Tenant Quota Changed source informational: Detects when a tenant quota is updated.
- Tenant Quota Deleted source informational: Detects when a tenant quota is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Tenant Replica Started source informational: Detects when a tenant replica starts.
- Tenant Replica Stopped source high: Detects when a tenant replica stops.
- Tenant State Changed source informational: Detects when tenant state is updated.
- User or Group Added source high: Detects when a user or user group is added to Veeam Backup & Replication.
- User or Group Deleted source high: Detects when a user or user group is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Virtual Lab Deleted source low: Detects when a virtual lab is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- Virtual Lab Settings Updated source low: Detects when virtual lab settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
- WAN Accelerator Deleted source informational: Detects when a WAN accelerator is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
- WAN Accelerator Settings Updated source informational: Detects when WAN accelerator settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
Other Index Content
This content is indexed for research but excluded from the detection-rule headline.Kusto #