The Veeam Difference: Coveware by Veeam
Veeam’s product development and collaboration pace with security vendors is not just a differentiator, it’s a trust signal. Veeam has proven to innovate fast and integrate wide. This session highlights these integrations, iteration velocity and the breadth of the ecosystem. Coveware by Veeam, acquired in March 2024, significantly enhances Veeam’s in-house capabilities in ransomware incident response. Since 2018, Coveware has amassed a large database from supporting 50-100 ransomware cases monthly, allowing them to publish quarterly reports detailing threat actor techniques, tactics, and procedures (TTPs). This proactive intelligence helps organizations understand prevalent threats and implement preventative measures like patching, whitelisting, and enhanced due diligence.
Coveware provides a comprehensive incident response retainer service, including cyber extortion negotiation, cryptocurrency settlements, and decryption support, leveraging their extensive database of decryption tools and keys. They offer 24/7/365 response, typically engaging with organizations within 15 minutes, and partner with other incident response firms like CrowdStrike and Mandiant for specialized containment and eradication efforts. A key differentiator is Coveware’s patent-pending Recon Scanner, a forensic investigation tool deployed on impacted systems to collect logs and build attack timelines. This scanner highlights critical warnings and identifies malicious activity, brute-force attempts, data exfiltration, privilege escalation, and other behaviors indicative of threat actor movement within an environment.
The Recon Scanner’s output, including detailed attack timelines, helps organizations understand the progression of an incident. While its primary use is during an active incident, its ability to uncover historical malicious activity that may have bypassed other security tools makes it a powerful forensic asset. Veeam emphasizes that while they do not advocate paying ransoms, Coveware’s negotiation expertise often focuses on buying time for recovery efforts rather than facilitating payments. This allows organizations to activate their incident response plans, communicate with stakeholders, and restore operations from clean backups. The continuous focus on education and best practices, like immutable backups and encryption passwords, is crucial for organizations to build resilience and improve their posture against evolving cyber threats.
Presented by Rick Vanover, VP of Product Strategy, and Emilee Tellez, Field CTO, Strategy and Community. Recorded live at Security Field Day 13 in Santa Clara, CA on May 29, 2025. Watch the entire presentation at https://techfieldday.com/appearance/veeam-presents-at-security-field-day-13/ or visit https://techfieldday.com/event/xfd13/ or https://Veeam.com for more information.
Transcript
Welcome to Security Field Day 13. I'm Rick Vanover from Veeam. And I'm Emily tes.
Today we're gonna talk about something really differentiating from Veeam, the Veeam Difference Cove Wear by Veeam, which was just to run people up as an, uh, history lesson, uh, March of 24. This was an acquisition that Veeam did that really makes a difference for our, uh, in-house capabilities. Emily, Yes.
So, so ware by Veeam, uh, again, they've been in the business of helping organizations that have been impacted by ransomware, um, specifically helping them when it came to negotiation, but then also when we start talking about, um, different types of payments as well as how can we actually help them from being proactive so that way they don't end up in that situation. Um, so they've been around since 2018, uh, and essentially they have probably the largest database aggregate as far as, uh, the different cases that they've supported. So anywhere between 50 to a hundred cases per month.
And these are just organizations that have been impacted by ransomware. These aren't essentially, you know, these are not essentially Veeam customers. These are just people that have been on for them with retainer.
Um, so one thing that they like to do is they collect all that information when they are working with these organizations and they essentially put out a report every quarter. And in this report they're able to highlight these are the top 10 or so threat actors or ransomware groups that they have came upon. And they like to go ahead and capture the techniques, tactics and procedures that they have seen as far as responding to these ransomware cases.
So what types of techniques did these threat actors utilize? What types of, um, you know, tools are they using so that way that they are able to gain lateral movements or get more additional access to information? Um, what are some things that organizations should be aware of, right?
So that way they could start ensuring that not only are they patching their systems, maybe they're whitelisting, some of these, um, pieces within their platforms, plus also maybe even doing some additional due diligence in the backend to be more proactive. Um, so this is what they lead in, right? And so we have an incident response retainer service, but they also deal with the cyber extortion negotiation, cryptocurrency settlements, decryption support.
They have a large database of decryption tools and decryption keys. So they're usually able to help provide that to organizations that have been impacted with the actual encryption. And then on top of that, you know, a lot of the things that they do is around those tabletop experiences.
So actually walking them through very specific, um, questions or unique, I would say, scenarios in which they could possibly be impacted by. So that way they know exactly what can they do to ensure that they're not going to, um, end up on the wrong side of a incident. And then this is just a quick overview.
So 24 by 7, 365 response. They're usually within 15 minutes, um, being on a call with a user or organization or a customer. Um, they also partner with different incident response firms, right?
So if we're looking at a CrowdStrike or a Mandiant that really, you know, they specialize in containment eradication efforts, this is where cohort can help come in to help them when, when it comes to overall negotiation and being proactive, right? So they actively do partner with those different types of retainer services. So, you know, a lot of large enterprises probably have more than one.
This is gonna be a supplemental option for them to utilize. And then on top of that, one of the biggest things that I'm actually gonna showcase is gonna be the patent pending assessment technology, which they actually call recon scanners. This is something that they utilize to do forensic investigation.
So with recon, they're able to deploy that on systems that have been impacted. From there, it does a log collection. It goes ahead and actually collects all the information, anything that has happened on that server.
And that's what they utilize to actually build out this attack timeline. So they have, um, a database of just the events that have happened that you can find within the Mitre attack framework, but then they also have their own database for different ransomware groups that they've actually seen. And then they keep both of those on hand and then they create, uh, an actual attack timeline for organizations to be able to funnel through.
So we offer Recon Scanner and we're gonna wait for that to load. So we offer, uh, recon Scanner as part of the Veeam data platform. So organizations can go ahead and they can install recon.
Essentially what it's able to do is again, go through and actually collect logs. And once it collects all of that information, we're able to provide that back to, and cohort could go through and actually determine, okay, what's actually taken place or what has happened on those different types of endpoints. So you have your, your critical warnings of, you know, what's, uh, a potential event or a potential incident.
And then we have some high and some medium activity that we could look at here. If we were to dive into some of these events, so we could see that there was a malware detection event that has happened here, we can see the location of said suspicious files. We could see what type of evil, uh, file was it that has actually flagged or triggered this event.
Uh, and then from there they can go ahead and collect this information and they can run it through with their security teams to go ahead and do some analysis. Emily, Sorry. Mm-hmm.
Uh, Jack, Paula or Paradigm Technica, um, is the recon scanner and cove wear, is that focused on, uh, ransomware or does that respond? Are you looking at all cybersecurity events? Looks at all different types of events?
So brute force attempts, so it also starts looking at things like exfiltration. Mm-hmm. So, so like when do we start seeing tools that are being utilized to start moving data outside of the environment as well?
Um, so it's highlighting all of those different types of tools that'll be used, uh, for what they know as indicators of compromise And other behaviors like permission elevation. Mm-hmm. Creating new users, turning off MFA or across even environmental stuff, right?
Yeah. Those in Linux Firewall rule change, right? Shell command a process was created.
So I mean, we'll start, they'll start looking at all these different types of events. Mm-hmm. That could be, again, behaviors known for threat actors to utilize when they're moving inside of an environment.
I'll give you a recent story, um, with a organization that was actually doing a brand new install of this product. And essentially when they went to do the install, they started to see a lot of malware activity start to flag from what work had actually shown earlier. When they went to do an investigation with Cohort, they actually saw through recon an entire timeline for the last three weeks of a specific user, uh, actually going in and, uh, downloading very suspicious files.
There was some other items that are in there. And essentially they all went into a war room and that is actively being worked on as we speak, right? So it bypassed some of their EDR tools that bypassed some of their AV tools, but they were able to, to see it and capture it within recon itself.
And one thing I'll highlight while we deal with the gremlins of live demos is that this feeds into a data pipeline, right? And this is one environment's look, and then if we aggregate those from other environments, there's learnings that they, they have that can really kind of looks like something hot was on the right side of that host right there, for example. Mm-hmm.
Yeah. And so, I mean, we get to highlight it through based off of just very specific hosts, right? So, so the benefit here is this was the actual product that they developed themselves in house to help them with responding to these incidents that can occur, um, when they're helping different organizations respond to, okay, who is it that we might have to get on a phone and negotiate with?
Right? Is it a cure? Is it ransom hub, is it fog?
They wanna know that because you wanna know your enemy, right? You wanna know are they gonna respond to you know, x, y, Z amount or are these people gonna be irrational? Um, one of the things that we do in these tabletop events that we've been hosting all around the United States and also been happening worldwide, is talking about those different types of threat actors and the way that they respond to different negotiation techniques and what they usually see.
And essentially, you know, with some of these groups, a lot of them are gonna be very irrational. They are gonna go ahead and they're just gonna dump your information on the dark web. They don't care what amount of money it is that you're gonna pay.
They're never gonna delete the data. And they're actually able to find that with some of the recent FBI arrests, right? When they see some of that information or those data centers from those ransomware groups, they still found remnants of data from organizations that had paid the ransom, that had assumed that they had deleted or got rid of the data and it was still there.
So it's providing all of this information so that way customers make the best decision possible for them in order to move forward and in a really bad situation. You mentioned ransomware payments, and I noticed on the, uh, the, the, the ware slide itself, you talked about, um, uh, uh, helping negotiate payments. Do you have, do you find that there's any either moral illegal implications to that?
No, because I would say with co themselves, they're always went v ourselves. We're always gonna say, you don't pay their ransom, that's gonna be your number one. Hmm.
We don't want anybody paying any type of ransom. 'cause all you're doing is just perpetuating the cycle. In fact, CO was actually founded in 2018 because of the other vendors that were out there at the time.
That was all that they were doing was they were saying, okay, well don't pay them, pay us. Right? And then essentially you'd go and you work with this third party and they were just negotiating on your behalf, but it was always for a payment.
So what they wanted to get into is not only, um, helping customers to be better proactive so that way they're never having to perform that payment, but then also giving them all the information necessary, right? Because the last thing we want is for an organization to say, well, we paid it because we thought it was gonna, you know, help us from a brand perspective, or we did everything possible to get the customer data back. So it helped it from a legal perspective, it's never gonna help, right?
But, so essentially they're just trying to work with, or we're just trying to work with customers, make sure they're, we're more proactive with never being in that situation. Jack, let me say it another way. Um, I would say I've, I've been at Veeam 15 years.
This is by far the most impactful acquisition and new market we've gotten into the, the business leader of Ware, bill Siegel, we, he goes by CEO of Ware, by Veeam, it's a business unit. He at our Veeam on conference last year, said something to the effect, loose quote, he can tell in the, in the first 15 minutes of an initial call, how well or how poorly an organization is prepared to deal with the situation in front of them. Okay?
And, and you as security folks, if you're practitioners, you walk into things, you're shaking your head, I get that that's a real thing. Where I'm going with that is the reality is today that there's a lot of work to do. You know, I mentioned earlier we don't have an example of this and that the reality is people aren't doing what they need to do.
And we're in the business of saying, Hey, this needs to be done. We have partners that are, that are trained, but I talk to customers that are like, yeah, I don't have anything immutable. And I'm like, that's an emergency leave now.
Yeah. Go home, set it up. You know, something like that.
There's a lot of work to do and that's, that's what me, Emily, and and our team are in the business of doing. Yeah. Yeah.
And the other portion of that is also when it comes to like sanction groups, right? How do we make sure that you're not just making a decision completely siloed? Yeah.
I, I spoke to an organization two months ago that said that they always have a, I dunno if I should say this, their plan is to always pay. Yeah. And I'm like, what a way to just put your name out there for everybody to go and just attack you.
And where in the world did you determine that that was the best choice for you to move forward with? Right? So it's again, continuing to make sure that we are, uh, educating the, the, those that need to make these types of decisions.
Um, because sometimes when you're put inside of those high pressure situations, it helps to have some people that have dealt with that and that's all they deal with, to be able to be like that clear, calm voice to say, this is not gonna work out well for you. Right. But there are industry thought leaders saying, just pay it, get it over with, move on.
It's not worth your time to negotiate because, and, you know, everyone has their decision on legality or ethics or morality or job risk, whatever they want. So I always think it's an interesting question. Thanks Jack.
Mm-hmm. Because it is a contentious thing, right? No, absolutely.
I'll I'll say it this way, what an organization does to the left of the bang, 100% predicates what happens to the right of the bang. Mm-hmm. Okay?
And, and I think there's a choice, Karen, of what they do ahead of time. Yes. That might predicate that mindset.
And um, I think, you know, I've got plenty of examples of organizations that have had incredible outcomes against these threats with us, and that's a great feeling. But you know what, so I'm based in Ohio, we have a, a tech support center there. It's not all lollipops and Goldilocks.
There are some ugly things out there and there's always a reason why that happened. And actually I love talking to them about that. I want to know what broke down, what was the problem?
What, why was there a data loss scenario? And it's, you know, number one thing is, I've been talking to them about this for seven years, was immutable backups. Right?
That is the single most effective technique to drive data recovery, right? So you're right, Karen, but I'm in the middle of being on the good side of the bang. Yeah.
And I mean, we talked about negotiation in, in form of payment, but majority of the times when COVID does get involved, they don't, there isn't a payment that's issued. They're gonna help negotiate time. Time is what everybody is gonna be dealing with during this type of incident, right?
How can we get systems back up online? Do we need to go and look at new environments? Do we need to go and start doing scanning for all of our, um, backups to ensure that we're gonna be restoring those to a clean state?
Right? We're not gonna be reinfecting ourselves. Do we need to go and have a conversation with our corporate communications teams so that way they can issue a statement?
Do we need to go make sure that all of our customers are aware of what has been taking place? Right? So they're there to help negotiate for that time so that way they can get everything in the background.
If that wasn't identified early in their incident response plan while now it can be worked on. Well, they go ahead and keep the threat actor at bay and don't have to worry about them saying, what, we're gonna start releasing x, y, Z information or we're gonna start doing this. Right.
So that's gonna be the other option. And or actually that's gonna be their main focus in which cohort is usually, um, involved in all of these different types of incidents. I I love the recon scanner.
Is that a point in time or is that automated where I can set that up to, to run on cron? Um, 'cause I think that's really useful data that you, you are getting in there. It so it, it is automated.
So essentially the, uh, or the customers have access to it, they go and they can download it. They can go ahead and decide which machines they wanna go ahead and run that against. And then it's scheduled to run.
They'll have that information being pulled into cover, then they'll be able to showcase to them if it's there. Usually what this is very useful for is when you actually have an incident that takes place. Otherwise, I mean, if there's nothing happening in the environment, it's gonna be just pretty, pretty flat.
They're not gonna see any information that's happening. Sure. And how do you collect that data?
Is that agent based? It is Agent based, yeah. Okay, cool.
Yeah, it's an agent collection that happens and it's going and it's just capturing any information from the logs itself. Okay. Perfect.
Thanks Emily. And, and a hot standby scenario, how does the technology change, and do you see different differences in, in the way process works in that way when you look at something like risk recon when you're in a hot standby type of scenario, When it's in a hot standby scenario? Well, I don't think it changes the game.
Uh, an Andre, I think, um, a hot standby, as long as it's on, it's a, it's a target. Yeah. Right.
Um, and we do a lot of, um, you know, warm, warm, hot, hot, you know, DR sites and that becomes kind of an interesting attack area where you think, oh, I've got a DR site, or I've got a parallel infrastructure, but then that's impacted concurrently and the recon world that's, uh, gonna be, um, transparent and like a straight re straight line recovery conversation. We have an advantage with the backups on immutable storage and the, the high speed recovery techniques. Um, that gets specific quick, but that's a good question.
Any other questions? Look at that goes on time. Oh, I had a, just an observation.
Like some of our security stuff, I mean, we're doing it for bad actors and malicious intent, but some of it just has saved us from incompetency or ignorance, things like, so the one I'm curious about is, you know, would this detect any of the stuff you've talked about today, detect if someone turned off litigation holds or turned off backups or Turned off encryption? Well, Yeah, because Actually had that happen and Yeah. With, Well the litigation hold is common.
Mm-hmm. Yeah. Anything that is done is, is lockable, trackable.
Okay. And things. And Veeam one, I guarantee you it sees it all right.
Uh, it'll catch it at a minimum at reporting. Um, I don't know if cohort's looking that deep, but, but it would, it would, it would detect the off. And then if you think about the ecosystem integrations that event log, that definitely would be mm-hmm.
So yes, in several different ways. Yeah. Alright, well I think we'll wrap this section.
Mm-hmm. Alright, well this was the Veeam difference. I'm sorry.
So thanks for watching this session at Security Field Day 13, the Veeam Difference Co. Where by Veeam. I'm Rick Vanover.
And I'm Emily. And stay tuned for our final section about some future innovations coming from Veeam. Yep.