Veeam

Telemetry Evidence

These values show how indexed rules identify Veeam telemetry.

Kusto

  • Queried source table Veeam_GetFinishedConfigurationBackupSessions (1 rule)
  • Queried source table Veeam_GetJobFinished (1 rule)
  • Queried source table Veeam_GetSecurityEvents (109 rules)
  • Queried source table VeeamMalwareEvents_CL (1 rule)
  • Queried source table VeeamOneTriggeredAlarms_CL (18 rules)
  • Queried source table VeeamSecurityComplianceAnalyzer_CL (1 rule)
  • Queried source table VeeamSessions_CL (1 rule)

Detection Rules

Kusto #

  • Adding User or Group Failed source low: Detects failed attempts to add a user or user group to Veeam Backup & Replication.
  • Application Group Deleted source informational: Detects when an application group is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
  • Application Group Settings Updated source informational: Detects when application group settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
  • Archive Repository Deleted source high: Detects when an archive repository is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
  • Archive Repository Settings Updated source low: Detects when archive repository settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
  • Attempt to Delete Backup Failed source high: Detects failed backup operations. This might indicate system or storage issues, or a potential sabotage of the backup infrastructure.
  • Attempt to Update Security Object Failed source high: Detects failed attempts to update security objects in Veeam Backup & Replication. Security objects include users and roles, credential records, certificates, or passwords.
  • Backup Proxy Deleted source informational: Detects when a backup proxy is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
  • Backup Repository Deleted source high: Detects when a backup repository is deleted from Veeam Backup & Replication. This might indicate unauthorized removal of critical components.
  • Backup Repository Settings Updated source low: Detects when backup repository settings are updated in Veeam Backup & Replication. This might indicate configuration changes that require review.
Show 103 more

Other Index Content

This content is indexed for research but excluded from the detection-rule headline.

Kusto #