Commvault has announced enhanced features in its Commvault Cloud Threat Scan platform, aimed at improving threat identification and cleaning backup data to bolster organisational security. These upgrades are intended to help firms quickly pinpoint vulnerabilities in backup environments, effectively recover validated data, and reduce potential reinfection and downtime.
Research indicates that the median dwell time for breaches not reported by actors is around 24 days, providing ample opportunity for malicious code infiltration. Security teams may have access to intelligence on specific indicators of compromise (IOCs) and indicators of attack (IOAs), but applying this information to backup data pre-restoration is crucial to avoid reinfections, prolonged outages, and further business disruptions.
YARA-based analysis
To combat these threats, Commvault has introduced two scanning modes within the Threat Scan. "Hyper Threat Hunting" offers targeted searches using artifacts such as hashes and YARA rules to identify IOCs at scale.
This method uses hash-based detection for quick identification and YARA-based analysis for detailed pattern matching. "Deep Inspection" provides in-depth file-level analysis using malware signatures, machine learning, heuristic analysis, and AI-enabled encryption detection to find threats, including ransomware activities, that might bypass traditional detection methods.
Time-sensitive response
These scanning features facilitate collaboration between incident response and recovery teams
These scanning features facilitate collaboration between incident response and recovery teams, isolating compromised data and supporting informed recovery strategies.
Organisations can either schedule recurring scans or initiate searches during incidents, offering both continuous protection and quick response flexibility. "In an era where attacks adapt faster than defences, our priority is to get ahead of every threat," stated Dr. Erika Voss, Chief Security Officer at Blue Yonder, emphasising the importance of validating recovery data against current threat indicators.
Achieving data cleanliness
Commvault has integrated these enhanced detection capabilities with its Synthetic Recovery technology, which merges detection with recovery operations.
This technology allows for the surgical removal of compromised datasets, ensuring that only clean data is restored to production systems. According to Fernando Montenegro of The Futurum Group, this reflects a market trend towards integrated solutions balancing threat detection with recovery workflows.
Proprietary signal correlation
Pranay Ahlawat, highlighted the importance of joint efforts between security and IT teams
Commvault's Chief Technology and AI Officer, Pranay Ahlawat, highlighted the importance of joint efforts between security and IT teams, stating that while threat intelligence is crucial, the next steps — using proprietary signal correlation and AI-driven algorithms in recovery processes — are what provide tangible assurance of clean data restoration.
The enhanced Threat Scan features are available globally, both as a standalone product and part of Commvault's cyber resilience package, all without additional cost to existing customers.
Attendees of the RSA Conference in San Francisco will have the opportunity to observe these capabilities firsthand, participate in ransomware recovery demos, and gain insights into identity resilience and unified cyber recovery strategies.
Commvault, a pioneer in unified resilience at enterprise scale, announces expanded threat hunting capabilities within Commvault Cloud Threat Scan. The enhancements help organisations rapidly identify risks within backup environments and recover validated clean data, reducing reinfection risks and prolonged downtime.
According to recent reports, the median dwell time for a non-actor disclosed breach is 24 days,1 giving attackers ample opportunity to silently embed malicious code across systems. While security operations teams often possess intelligence tied to specific indicators of compromise (IOCs) or indicators of attack (IOAs), that intelligence must also be applied across backup data before restoration begins. Without clear visibility into backup integrity, organisations risk reintroducing threats, extending outages, and compounding business disruption.
YARA-based analysis
To address this challenge, Commvault now delivers two complementary scanning modes within Commvault Cloud Threat Scan:
- Hyper Threat Hunting enables targeted searches across backup data using threat hunting artifacts such as hashes and YARA rules to identify known indicators of compromise at scale. Hash-based hunting provides fast, index-based detection, while YARA-based analysis supports more targeted pattern matching for deeper investigation.
- Deep Inspection provides layered file-level analysis using malware signatures, machine learning, heuristic analysis, and AI-enabled encryption detection to uncover known threats, suspicious variants, and ransomware related activity that may evade exact-match indicators alone.
Time-sensitive response
Together, these detection modes allow close collaboration across incident response and recovery teams to isolate affected data and make informed recovery decisions. They can schedule recurring scans for continuous monitoring or conduct targeted searches during active incident response scenarios, providing flexibility for both ongoing protection and time-sensitive response.
“In an era where attacks adapt faster than defences, our priority is to get ahead of every threat,” said Dr. Erika Voss, Chief Security Officer at Blue Yonder. “Being able to validate recovery data against current threat indicators is one way to stay ahead of it — ensuring we have more control in an unpredictable landscape.”
Achieving data cleanliness
Commvault integrates these threat detection capabilities with its patent-pending Synthetic Recovery technology – unifying detection and recovery workflows. Once risks are identified, Commvault’s AI-enabled Synthetic Recovery offering can help surgically remove compromised datasets during recovery while restoring clean data to production systems. With Synthetic Recovery, organisations can maximise data preservation while simultaneously achieving data cleanliness.
“We’re seeing a fundamental shift in how organisations approach recovery operations. The market is demanding integrated solutions that combine threat detection with recovery workflows, and Commvault’s layered approach to verified clean recoveries represents where the industry is heading,” said Fernando Montenegro, VP and Practice Lead Cybersecurity at The Futurum Group. This announcement continues to demonstrate how Commvault is advancing the ResOps operating model. Instead of operating in silos across IT and security, ResOps connects people, processes, and technology, so organisations can manage resilience as a continuous enterprise-wide discipline.
Proprietary signal correlation
“Security and IT teams need to operate from the same playbook during an incident. Threat intelligence at scale is increasingly table stakes — what sets us apart is what happens next,” said Pranay Ahlawat, Chief Technology and AI Officer at Commvault.
“By layering our proprietary signal correlation and AI-enabled algorithms on top of targeted threat hunting, and connecting that directly to verified recovery, we give organisations something powerful: not just the ability to find threats fast, but the confidence that what they restore is clean.”
Cyber resilience bundle
Threat Scan is available globally and is sold as a standalone offering as well as part of Commvault’s cyber resilience bundle. The new threat hunting capabilities are generally available and will be provided at no additional cost to existing Threat Scan customers.
Commvault’s latest Threat Scan offerings take centre stage at this year’s RSA Conference (Booth #S-0634) from March 23-26 in San Francisco. Show attendees can grab a ringside seat for the ResOps Rumble where resilience and operations join forces to deliver unified cyber recovery, identity resilience, and data security. Register today for ransomware recovery demos and sessions, expert insights on identity resilience and clean recovery, and the ultimate prize – unified resilience for your organisation