Summary is AI-generated, newsdesk-reviewed
  • Commvault enhances Cloud Threat Scan with Hyper Threat Hunting and Deep Inspection capabilities.
  • New capabilities rapidly detect risks and ensure clean data recovery, preventing reinfection.
  • Commvault integrates threat detection with Synthetic Recovery to maximize data cleanliness and resilience.

Commvault has announced enhancements to its Cloud Threat Scan capabilities, aiming to bolster threat hunting functions for better identification and recovery processes. These improvements are designed to aid enterprises in quickly pinpointing risks within backup systems, ensuring the restoration of unaffected data and minimizing potential reinfection and extended downtimes.

Recent statistics highlight a critical issue: the average timeframe for discovering a breach not initially identified by attackers is 24 days. This window allows adversaries to discreetly plant harmful code across networks. While many security teams have access to intelligence on specific compromise indicators, applying this knowledge to backup data before commencing restoration is crucial. Absent clear insights into backup integrity, organizations risk reintroducing threats, prolonging outages, and exacerbating business disruptions.

Enhanced Threat Detection Modes

To counter these challenges, Commvault introduces dual scanning functionalities within its Cloud Threat Scan tool:

  • Hyper Threat Hunting: This mode provides extensive searches across backup data utilizing threat hunting tools like hashes and YARA rules, enabling large-scale detection of known compromise indicators. Fast, index-driven hash-based hunting allows rapid detection, while YARA-based analysis facilitates more nuanced pattern matching for intricate investigations.
  • Deep Inspection: Offering a detailed file-level assessment, this mode employs malware signatures, machine learning, heuristic analysis, and AI for encryption detection, efficiently uncovering known threats, potential variants, and ransomware activities that may bypass straightforward indicator matches.

Response and Recovery Coordination

This system supports scheduled scans for ongoing surveillance in active response situations

These detection mechanisms foster enhanced cooperation between incident response and recovery units, allowing for precise data isolation and informed restoration determinations. This system supports scheduled scans for ongoing surveillance or focused searches in active response situations, delivering adaptability for continuous protection and urgent responses.

Dr. Erika Voss, Chief Security Officer at Blue Yonder, emphasized the importance of proactive threat measures: “In an era where attacks adapt faster than defenses, our priority is to get ahead of every threat. Being able to validate recovery data against current threat indicators is one way to stay ahead of it — ensuring we have more control in an unpredictable landscape.”

Integrated Detection and Recovery

Commvault has integrated these detection capabilities with its innovative Synthetic Recovery technology, merging detection with recovery tasks. Upon threat identification, the AI-fueled Synthetic Recovery tool aids in excising compromised datasets during recovery, while ensuring clean data is reinstated to active systems. This approach maximizes data retention while maintaining data integrity.

According to Fernando Montenegro, VP and Practice Lead Cybersecurity at The Futurum Group, “We’re seeing a fundamental shift in how organizations approach recovery operations. The market is demanding integrated solutions that combine threat detection with recovery workflows.” This reflects Commvault’s progression toward the ResOps model, bridging gaps across IT and security sectors.

Proprietary Signal Correlation

Pranay Ahlawat, Chief Technology and AI Officer at Commvault, points out the importance of unified operations: “Security and IT teams need to operate from the same playbook during an incident. Threat intelligence at scale is increasingly table stakes — what sets us apart is what happens next. By layering our proprietary signal correlation and AI-enabled algorithms on top of targeted threat hunting, and connecting that directly to verified recovery, we give organizations something powerful: not just the ability to find threats fast, but the confidence that what they restore is clean.”

Availability and Demonstrations

The advanced capabilities of Threat Scan are globally available, offered as an independent product or as part of Commvault’s cyber resilience suite. Current Threat Scan users will receive these new features at no added expense. Commvault’s offerings will be showcased at the upcoming RSA Conference in San Francisco, where participants can experience live demos and sessions on ransomware recovery and clean recovery methods.

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...

rf IDEAS Supports Gallagher Badge In Apple Wallet
rf IDEAS Supports Gallagher Badge In Apple Wallet

rf IDEAS, a global manufacturer of RFID credential readers, announces that its WAVE ID® readers support Gallagher Employee Badge in Apple Wallet, expanding the range of credent...