Commvault has integrated its Threat Scan capabilities with Google Threat Intelligence to enhance data recovery processes following cyberattacks.
This new collaboration aims to offer organizations faster identification of clean recovery points by utilizing Google’s comprehensive threat intelligence platform within Commvault's Threat Scan workflows.
The integration is expected to help businesses convert global threat insights into actionable recovery data, assisting in quicker restoration after cyber incidents.
Data Recovery Challenges
Following a cyberattack, organizations often struggle to pinpoint safe data recovery points. While indicators of compromise (IOCs) can be quickly identified by security teams, the actual task of validating backup data still requires time.
This delay in recovery can be costly, as every minute of downtime impacts operations.
Google's Role in Threat Intelligence
The integration with Google Threat Intelligence, which fuses Mandiant frontline intelligence and VirusTotal’s crowdsourced insights, enables Commvault customers to analyze workloads for potential malware threats.
It also provides detailed threat context to assist organizations in identifying compromised recovery points. This collaboration provides a comprehensive view, helping teams to conduct further research and remediation.
Introducing New Scanning Capabilities
Commvault’s new inline scanning capabilities capture file hashes during the backup processCommvault has introduced new inline scanning functions that capture file hashes during backup processes. This allows for a rapid comparison against threat intelligence indicators, aiding teams in quickly pinpointing usable clean files for recovery. The system supports rapid threat validation and deeper analysis, such as malware inspection, when necessary.
This latest update enhances Commvault’s Synthetic Recovery capability, which utilizes AI to detect and excise threats while preserving intact data. As a result, customers can experience more thorough data recovery.
Expert Insights
Pranay Ahlawat, Commvault's Chief Technology and AI Officer, states, “Businesses need confidence that the data they’re restoring is clean. By combining Threat Scan and inline scanning with Google Threat Intelligence, we’re helping customers validate recovery points faster and accelerate clean recovery when it matters most.”
Miton Adhikari, Head of Google Security OEM Partnerships, remarks, “Organizations are looking for ways to strengthen cyber resilience while reducing complexity during incident response and recovery. Through our collaboration with Commvault, customers will be able to apply Google Threat Intelligence within recovery workflows to make faster, more informed recovery decisions and reduce recovery uncertainty.”
Upcoming Availability
The Google Threat Intelligence integration, along with the new scanning capabilities and Threat Scan enhancements, is anticipated to become available in the coming months. This announcement comes as part of Commvault’s ongoing partnership with Google Cloud and continues to expand cyber resilience capabilities for Google Cloud environments.
Commvault, a pioneer in unified resilience at enterprise scale, announced a new integration with Google Threat Intelligence, Google’s comprehensive threat intelligence platform, that incorporates Google Threat Intelligence data and scanning capabilities into Commvault Threat Scan workflows.
Through this collaboration, Commvault can help customers transform global threat intelligence into actionable recovery insights, enabling organizations to identify clean recovery points faster and accelerate recovery following cyberattacks.
Recovering data challenge
When cyberattacks occur, organizations often face a critical challenge: determining which recovery points are safe to restore. While security teams may quickly identify indicators of compromise (IOCs), recovery teams still need to validate backup data before recovery can begin, delaying recovery efforts when every minute of downtime matters.
Google Threat Intelligence
Google Threat Intelligence combines Mandiant frontline intelligence, VirusTotal’s crowdsourced intelligence, and Google threat insights gained from protecting billions of users. Integrating Commvault Threat Scan workstreams with Google Threat Intelligence helps customers analyze protected workloads for malware, while also helping organizations identify threats and pinpoint which recovery points are compromised.
Commvault Threat Scan customers will also receive actionable threat context from Google Threat Intelligence for threats found in their environment to help with further research and remediation.
Introducing new scanning platforms
As part of this release, Commvault is also introducing new scanning capabilities that collect file hashes inline during backup operations. File hashes, like individual fingerprints, provide a fast and easy way to quickly check recovery points against threat intelligence indicators so teams can identify clean files to be used for recovery.
Commvault’s inline inspection capability allows customers to start with rapid threat intelligence validation and selectively perform deeper malware, encryption, and forensic analysis when additional inspection is required. This layered approach helps organizations accelerate recovery decisions while maintaining confidence in the integrity of restored data.
These new threat insights and scanning capabilities strengthen Commvault’s Synthetic Recovery capability, which uses an AI-enabled process to automatically detect threats and surgically remove them during recovery while keeping the “good” data intact. Customers can then make the most complete recovery possible.
Authority comments
“Businesses need confidence that the data they’re restoring is clean,” said Pranay Ahlawat, Chief Technology and AI Officer at Commvault. “By combining Threat Scan and inline scanning with Google Threat Intelligence, we’re helping customers validate recovery points faster and accelerate clean recovery when it matters most.”
“Organizations are looking for ways to strengthen cyber resilience while reducing complexity during incident response and recovery,” said Miton Adhikari, Head of Google Security OEM Partnerships. “Through our collaboration with Commvault, customers will be able to apply Google Threat Intelligence within recovery workflows to make faster, more informed recovery decisions and reduce recovery uncertainty.”
This announcement builds upon Commvault’s ongoing collaboration with Google Cloud, including expanded cyber resilience capabilities for Google Cloud environments via Clumio, and support for Google Cloud workloads.
Availability
The Google Threat Intelligence integration, inline scanning capabilities, and associated Threat Scan enhancements are expected to be available in the coming months.