Security Ecosystem at Veeam
Veeam’s product development and collaboration pace with security vendors is not just a differentiator, it’s a trust signal. Veeam has proven to innovate fast and integrate wide. This session highlights these integrations, iteration velocity and the breadth of the ecosystem. Veeam emphasizes its “power of three” strategy, extending beyond internal innovation to encompass robust partnerships with over 65 security vendors, including major players like Palo Alto, CrowdStrike, Splunk, and Sophos. This extensive ecosystem allows organizations to leverage their existing security investments by feeding information directly from Veeam’s data protection platform into their chosen security tools. The Veeam CyberSecure program, which includes advanced capabilities, incident response retainers, and a ransomware recovery warranty with zero claims to date, further underscores their commitment to data safety.
Veeam provides comprehensive monitoring and reporting through Veeam ONE, which tracks hypervisor, cloud workloads, and Microsoft 365 backup products. This critical data is fed into security partners’ platforms, offering insights into anomalies such as unusual data read-write rates or suspicious login attempts, enabling quicker threat notification. Veeam supports various event types, from malware detection to overall system overviews, making this information available via Syslog and JSON formats. This allows customers to filter events based on their needs and avoid alert fatigue, integrating seamlessly with any Security Information and Event Management (SIEM) tool, including free options. Notably, Veeam makes its documentation publicly accessible, reflecting its commitment to transparency and empowering users.
A key aspect of Veeam’s integration strategy is its recent collaboration with CrowdStrike, offering dashboards for data protection monitoring and security events within the CrowdStrike platform. These pre-built dashboards provide a high-level overview of security events within the Veeam environment, allowing users to drill down for detailed information. Furthermore, Veeam’s integration with Palo Alto XSOAR enables automated playbooks, such as initiating instant VM recovery or deploying security agents on compromised machines. This bidirectional communication helps orchestrate responses across data protection and security operations, enabling security analysts to build customized workflows, even without direct experience with Veeam’s application, as demonstrated by a customer who leveraged Veeam events in Splunk to drive Palo Alto XSOAR automations.
Presented by Rick Vanover, VP of Product Strategy, and Emilee Tellez, Field CTO, Strategy and Community. Recorded live at Security Field Day 13 in Santa Clara, CA on May 29, 2025. Watch the entire presentation at https://techfieldday.com/appearance/veeam-presents-at-security-field-day-13/ or visit https://techfieldday.com/event/xfd13/ or https://Veeam.com for more information.
Transcript
Hello and welcome to Security Field Day 13. I'm Rick Vanover from Veeam. And I'm Emily Tess from Veeam.
And we're gonna talk about the security ecosystem and how Veeam and our partners are really helping keep data resilient. Emily? Yes, thanks Rick.
So we talked about the Veeam power of three, so not just what we're doing from an innovation standpoint, but also what Veeam is doing in partnering with our security vendors and all of those wonderful partnerships that organizations have already invested in. So let's be able to allow them to utilize those tools and then just feed our own information into those platforms. So this is just a quick, I would say snapshot, the snapshot of the actual vendors that we're currently working with.
But we're, we're essentially with, um, working with over 65 different security vendors. Um, we had a very busy RSA this year that, needless to say, um, but some of the top ones up there that you can see, right? Palo Alto, um, torque, which is one that's brand new, CrowdStrike, Splunk, Sophos, I mean these are all really great security vendors that not only are they, um, pretty well into the organizations that they're working with, right?
So they have their incident response playbooks that have already been created. Those security analysts, they already know how they wanna leverage their different war rooms or their action items that they wanna take if they were to identify any type of malware suspicious activity happening in their environment. So why not be able to feed all the information from the data protection platform directly into that.
Now, there's another bit in here that we like to call out, which is not just what's happening from a data protection standpoint, but then also data overall monitoring. So we do talk a lot about, um, Veeam one, which is our monitoring reporting tool. Essentially be able to monitor the hypervisor, the cloud workloads, the M 365 backup product that we utilize, right?
Um, but being able to feed in any of those events directly into the security partners is, uh, really, really important. And also, uh, it shows some really great impacts for customers to be able to identify, okay, do we have, you know, large ReadWrite rates happening on a data store that's not normal. Do we have suspicious users trying to, uh, log on to different machines and they're doing multiple attempts at that?
How can we be notified of that sooner or, or quicker before, uh, we have some type of incident that could occur? So these are gonna be some of the different ecosystem providers that we play with. And then when we look at it from a stance of didn't change there, Well, Yeah, sometimes there it goes.
All right, so when we look at it from a stance of what happens both during, before and post backup or recovery, right? Having all of those, uh, capabilities, not just to be able to scan and validate those backups, but then also feeding that information in. So I'm gonna cover the different types of events that we can actually feed into different types of security platforms.
So, um, from the malware detection all the way down to maybe even some of the items that we're gonna see from an overall, uh, overview. And then we're gonna dive into, uh, some of the other pieces in here from, from Rick. Um, I have a comment on this real quick.
Well, Emily does this quick little transition. The Veeam Cyber Secure, which was that graphic that she just showed, was it's a program, it's a package. It includes the highest level of capabilities, it includes a retainer for incident response, it also includes a ransomware recovery warranty.
And a, a little zinger little data point is we've had zero claims on that warranty. You know, coupled with my previous point about the backups immutable and the encryption password, this advice works. And you know, we're really proud of that.
You know, we're really keeping customer data safe. So it looks like we're in, Gosh, it's taking a little while to Which one. Yeah, There it goes.
So customers can find out everything that we are going to report on. So we have a very nice event reference ID that's available. So not just what's happening from click by click inside of the actual data platform.
But then also when we're looking at strictly malware detection, we also, um, have a report on our beam community, which highlights all the different malware detection and the ways that we are pulling in those events and where they map inside of Mitre, but then also giving information back as to what you should do if you have comes up, right? Because the last thing we want is to funnel in and throw a whole bunch of alerts to a security analyst or to a cyber defense lead. And now all of a sudden they're sitting there with 500 plus alerts and they're like, what am I supposed to do with this information?
Right? So we do, uh, help them so that way they can actually be able to triage any of that information. And then this is also available instead of A-J-S-O-N format.
So they can go ahead and upload this into whatever security vendor they're utilizing so they can get that information. We are doing this all through SIS log. So essentially it's just Syslog van ID filtering, right?
And so, uh, that's the only portion that I wanna show in here. And then the other piece in here is that you actually, we could actually filter it for customers. So if you're using a SIM tool or a provider out there that charges per the amount of information that they're receiving, they can actually come in here and they can make those changes and those adjustments say, okay, maybe only go ahead and notify on the errors or the warnings.
We don't need to get information for everything. So that is something that we really did take to heart because as much as we love all of those beautiful logos that I showed earlier, um, a lot of different users are gonna leverage whatever they have accessible to them, right? And so if they're using utilizing free tools, we can go ahead and we can feed into that as well.
I think when I first demoed this, when it came out I was using Nagios, right? So pretty simple, really easy to set up and utilize. Well, Speaking of accessible, one other thing I'll say that's not entirely but uniquely Veeam, um, and not common in the industry, is we don't put our documentation behind a paywall that XML that I pulled up.
Yes. Fernando liked that. Right?
Thank you. You know, it's just, we're, we're pretty proud of it and we want it accessible and, you know, the tinkerers, the practitioners, we want it really accessible for. Yeah.
So I'll start off with our latest, um, integration, which is our CrowdStrike one. So this actually just recently came out. We made this announcement at BM one last month.
Um, so CrowdStrike, we look at it two different ways. Essentially being able to, um, work directly with Falcon Log Scale as well as creating a data parser so that way customers can create their own customized dashboards and be able to create their own, you know, specialized runbooks and automations and whatever else they need based off of the event IDs that Veeam has available to us, um, more available within the CrowdStrike marketplace so they can actually see that within there. Um, my Zoom is loading on my, well, And you know, these integrations, the ecosystem, they are where they need to be.
We have an app in Splunk base, we have this in the, uh, the CrowdStrike world, I don't know what it's called. App store Marketplace Yeah. In the marketplace.
So, so we're in all of these marketplaces, we, we'll keep it all up to date. Um, we're taking in feedback from all of our users that are actively utilizing these applications. Um, but then what we're also finding is users that are actually parsing and I would say frankensteining these different applications together because they're not utilizing just one tool, right?
They have Splunk, they have, um, windows Defender, they're using CrowdStrike, they're using Palo Alto X Sword to run automations and playbooks. So they're trying to figure out a way to make it easier for them to be able to respond to these different types of detections and attacks, um, while, you know, providing that information all into a single space. Quick question.
Mm-hmm. What would you say is the most common obstacle that you're seeing for people not doing that kind of, of, or for people not doing these kinds of, of integrations, if it's something that you have to push a theme to, Hey, look, we can do all this, you're not doing it. Or is it the fact that oh no, the, the, the system integrator that owns that client doesn't work with us.
Like what's your, what's your, your, uh, your take on how to get this into more people's hands or more people's implementation? I would say it's probably having the discussion with the, the actual owner of whatever platform it is that they're utilizing, right? So it's having the discussion with the backup admin or you know, the CIS admin, whoever's actually managing the Veeam data platform itself.
And then them figuring out on their security side, okay, what is it that we're utilizing? Okay, we have this app now how can I go ahead and talk to them about what the event IDs are and why is it important for them to start pushing this through? So it's having that connection.
'cause usually we speak directly to the backup admin and the IT manager, right? So it's getting into this entire realm of security, which I would say in the last two years we've all had to do, right? There's been a significant shift with ransomware and everything else that, where everybody's having to speak to security at some point in time.
So now it's just getting them into the point of why do we need to be, why should we have all this information being pointed, Fernando, it is, it's this person and that person in two different groups. And if we were having this conversation 10, 15 years ago, from a backup perspective, it would be the storage and the networking people fighting with the backup people. I don't know if you've seen the meme of, you know, several spidermans pointing to each other.
That kind of is, was what's going on. But it is, you know, especially up stack in the larger orgs, the same person that's running Veeam as that Veeam admin is not the admin of, of the security stack. And just bridging that gap and being able to be fluent in their native formats is a huge bo to make that.
And it's education. We just gotta get it out there and that's why we're here. Yeah.
Telling Them. Absolutely. So there's two dashboards available with CrowdStrike.
There's a data protection monitoring as well as a security events monitoring. So this is just gonna do a quick level highlight of all the security related events that are happening within the data protection platform, both from Veeam backup and replication, as well as that monitoring and reporting tool, which is Veeam One. So this will just give them a dashboard of being able to pull in and ingest all of that data without them having to go and look at each individual event id.
So this is already prebuilt and delivered for the customers to, to be able to utilize, and then they can actually drill down into detail for any of those, except for when it says I'm not connected to the internet, which for some reason it just keeps on kicking me off the wifi. So we'll have it reconnect here shortly. There it goes.
So we have all of those options that are available within here. Now I'm gonna switch gears because I know we're gonna be short on time and I do wanna show some of the other ways that we are seeing customers utilize this. So going back to Fernando's original point, right?
How do we get this into the hands of, of different users or, um, different people within the organization? So me personally, I worked with a actual customer that I guess participated in Tech Field Day a few weeks ago, most recently, right? So they're a current customer of ours.
I'm not gonna say the name, but they actually, um, the security analysts that I worked with there, she actually built her own customizable, um, Splunk environment. So she has her own application for how she reads imports in data, and she utilize not just the VAP for Splunk, but then she's also utilizing, um, Palo Alto xor. So essentially what she does is she actually folds in all of the Veeam events that she, they're receiving from their data detection platform.
So anything from backups, inline detection and line scanning, anything that they've done from running the AB tools. And then she has that forwarded in into s Spunk, and then Splunk becomes the ingest engine to determine what's gonna be a high severity level for them. If she has a SEV one or SEV two, it gets forwarded over into Palo Alto, XOR.
From there, she actually came in and she started building these customizable playbooks. So by default, we give customers four playbooks within Palo Alto, XOR that they could start working from. So things like starting an instant VM recovery automatically, right?
So how can we go ahead and start connecting that data, capturing that virtual machine from there, being able to run any additional items or checks that we want to in there. But what she did is she actually started having it creating war rooms for her. So not just scanning the machine, but if that machine is missing things like Windows Defender AV on it, let's go ahead and have that be automatically installed.
Let's start pulling in the right people early and often so that way we can determine and have a war room to decide, okay, what's happening within this environment? Because now we're not only just seeing it from production level, we're also seeing it inside of our data protection side as well. So this helps them to alert quicker as to a potential attack that could be happening or suspicious event.
Um, so those are just some really kind of unique factors that we're seeing against. The other cool story about this. So she's never touched Beam before in her life, so she was able to build this entire app just by funneling in all the events that we're sending into Splunk and with Palo Alto.
And she's never once actually gone into the Veeam application itself to set up any of this. Uh, so with that, I think the only last one that we have inside of here was my Splunk one, and that is if that guy is up and running, Can can we go back for just a second? Sure.
And I'm not sure if I'm taking you off script or not. No. But, um, in the crowd, I guess it was the CrowdStrike where you showed the donut charts.
Mm-hmm. Um, it says, if I'm reading that right, correctly, under your Veeam backup replication security events, it's talking about key management rotation. Are you, what are you guys doing with keys and key management?
Ah, So we integrate with different KMS vendors. Okay. So we can integrate with the whatever vendor, uh, the customer chooses.
We have a list of logos that are up there. Um, and this is essentially just highlighting that there was a key rotation happening as an event, and that got ported up into, So it's a key management systems doing that external, external, external to you, but you're just recording the event? Exactly.
Mm-hmm. Okay. But if they're not using an external KMS, we can do manual, uh, encryption key setting.
So back to my recoverable data from ransomware, there can be a single user driven password that Veeam itself has built in password loss prevention and stuff like that. Mm-hmm. But the, the enterprise thing to do is external KMS.
Yeah. Yep. Yep.
Quick question for you, uh, Romeo. Um, the VM one data sources mm-hmm. What, what sources can you utilize now That is everything that we are looking at protecting.
So the virtual machines, if that's running in VMware or Hyper V, um, so essentially it's pulling in information from there. It's also pulling in information from the backups. So whatever we've recently backed up, um, NAS or file data, uh, we also do enterprise application plugins.
So SAP, Oracle sql. So Veeam one is essentially just monitoring both from, uh, what's running in production, but then also what's happening from the backup side. So it's looking at information from two different avenues.
Okay. How does that differ from the beam backup and replication data sources? Sure.
Yeah. So this is actually just what the actual backup is itself. Okay.
So I would say BEAM one also looks directly into production itself. So if we start seeing somebody try to go in and, you know, a bunch of log on or brute force attempts happening on a machine, for example, when I actually saw this happen with an organization, they had over 500 attempts happening from 10:00 PM till 2:00 AM every single day of a bad username, uh, and password being utilized against one of their machines. And they're like, well, what is this that's happening?
So Veeam one is able to check that that's looking directly at the production machine itself. It wasn't essentially happening in the backup. Okay.
So, Yeah, I, I like to say, uh, for the audience, I guarantee you Veeam one will tell you something about your environment you didn't know, but you need to address. Mm-hmm. So how does it gather this information Collectors?
Um, it's agentless directly to Veeam, or there is a, a Veeam agent to Veeam, which is kind of funky, but, uh, to the primary data sources, namely virtual infrastructures and to an extent physical infrastructures. It's agent less network based collection and authentication, um, for another tech field day, there's actually some really cool AI stuff that we're doing to predict preemptively see some problems based on some things we see. It's a reverse style home telemetry analysis situation.
It's called Intelligent Diagnostics. But, um, there's some automated ways to fix that too, which that one does require a, a Veeam agent inside of Veeam to do that. Yeah.
So, we'll, we'll Level set. Okay. Well, thank you for watching this segment of Security Field day 13 about the security ecosystem.
I'm Rick Manover from Veeam. And I'm Emily Tess. Stay tuned for other segments where we walk through the additional security capabilities.
I.