Commvault has announced its integration with Google Threat Intelligence, a platform offering comprehensive threat insights.
This partnership aims to enhance Commvault's Threat Scan workflows by incorporating advanced Google Threat Intelligence data and scanning capabilities.
This collaboration is designed to enable organisations to swiftly identify clean recovery points and expedite data recovery processes following cyberattacks.
Challenges in data recovery
In the event of a cyberattack, organisations often struggle to identify which recovery points remain uncompromised.
Although security teams may quickly detect indicators of compromise (IOCs), backup data still needs validation by recovery teams, potentially delaying efforts where every second of downtime is crucial.
Utilising Google Threat Intelligence
The integration of Commvault Threat Scan workstreams with Google Threat Intelligence is poised to support organisations in assessing protected workloads for malware. Google Threat Intelligence, which merges Mandiant's frontline insights, VirusTotal's crowdsourced intelligence, and Google's extensive threat insights, assists in identifying threats and determining compromised recovery points.
Users will receive detailed threat context, aiding further research and remediation efforts.
Enhanced scanning platforms
Commvault is introducing new capabilities to collect file hashes during the backup processCommvault is introducing new capabilities that gather file hashes during backup procedures. File hashes act as distinctive fingerprints, enabling quick comparison against threat intelligence indicators, thus assisting in pinpointing clean files for recovery.
This inline inspection capability allows for rapid validation of threat intelligence, with the option for more thorough malware, encryption, and forensic analysis if needed. This multi-layered strategy ensures quicker recovery decisions while maintaining data integrity.
These advancements complement Commvault’s Synthetic Recovery capability, which employs AI to detect and remove threats during recovery, preserving unaffected data. This ensures a complete and reliable data restoration.
Expert commentary
Pranay Ahlawat, Chief Technology and AI Officer at Commvault, remarked, "Businesses need confidence that the data they're restoring is clean. By combining Threat Scan and inline scanning with Google Threat Intelligence, we’re helping customers validate recovery points faster and accelerate clean recovery when it matters most."
Miton Adhikari, Head of Google Security OEM Partnerships, added, "Organisations are looking for ways to strengthen cyber resilience while reducing complexity during incident response and recovery. Through our collaboration with Commvault, customers will be able to apply Google Threat Intelligence within recovery workflows to make faster, more informed recovery decisions and reduce recovery uncertainty."
This development builds on Commvault’s existing partnership with Google Cloud, enhancing cyber resilience capabilities for Google Cloud environments and supporting Google Cloud workloads via Clumio.
Availability
The integration of Google Threat Intelligence, along with inline scanning features and related Threat Scan enhancements, is slated to become available in the forthcoming months.
Commvault, a pioneer in unified resilience at enterprise scale, announced a new integration with Google Threat Intelligence, Google’s comprehensive threat intelligence platform, that incorporates Google Threat Intelligence data and scanning capabilities into Commvault Threat Scan workflows.
Through this collaboration, Commvault can help customers transform global threat intelligence into actionable recovery insights, enabling organisations to identify clean recovery points faster and accelerate recovery following cyberattacks.
Recovering data challenge
When cyberattacks occur, organisations often face a critical challenge: determining which recovery points are safe to restore. While security teams may quickly identify indicators of compromise (IOCs), recovery teams still need to validate backup data before recovery can begin, delaying recovery efforts when every minute of downtime matters.
Google Threat Intelligence
Google Threat Intelligence combines Mandiant frontline intelligence, VirusTotal’s crowdsourced intelligence, and Google threat insights gained from protecting billions of users. Integrating Commvault Threat Scan workstreams with Google Threat Intelligence helps customers analyse protected workloads for malware, while also helping organisations identify threats and pinpoint which recovery points are compromised.
Commvault Threat Scan customers will also receive actionable threat context from Google Threat Intelligence for threats found in their environment to help with further research and remediation.
Introducing new scanning platforms
As part of this release, Commvault is also introducing new scanning capabilities that collect file hashes inline during backup operations. File hashes, like individual fingerprints, provide a fast and easy way to quickly check recovery points against threat intelligence indicators so teams can identify clean files to be used for recovery.
Commvault’s inline inspection capability allows customers to start with rapid threat intelligence validation and selectively perform deeper malware, encryption, and forensic analysis when additional inspection is required. This layered approach helps organisations accelerate recovery decisions while maintaining confidence in the integrity of restored data.
These new threat insights and scanning capabilities strengthen Commvault’s Synthetic Recovery capability, which uses an AI-enabled process to automatically detect threats and surgically remove them during recovery while keeping the “good” data intact. Customers can then make the most complete recovery possible.
Authority comments
“Businesses need confidence that the data they’re restoring is clean,” said Pranay Ahlawat, Chief Technology and AI Officer at Commvault. “By combining Threat Scan and inline scanning with Google Threat Intelligence, we’re helping customers validate recovery points faster and accelerate clean recovery when it matters most.”
“Organisations are looking for ways to strengthen cyber resilience while reducing complexity during incident response and recovery,” said Miton Adhikari, Head of Google Security OEM Partnerships. “Through our collaboration with Commvault, customers will be able to apply Google Threat Intelligence within recovery workflows to make faster, more informed recovery decisions and reduce recovery uncertainty.”
This announcement builds upon Commvault’s ongoing collaboration with Google Cloud, including expanded cyber resilience capabilities for Google Cloud environments via Clumio, and support for Google Cloud workloads.
Availability
The Google Threat Intelligence integration, inline scanning capabilities, and associated Threat Scan enhancements are expected to be available in the coming months.