Commvault has announced a new integration with Google Threat Intelligence, bringing Google’s threat intelligence data and scanning capabilities into Commvault Threat Scan workflows. The integration helps organizations turn global threat intelligence into actionable recovery insights, enabling them to identify clean recovery points more quickly and speed recovery after cyberattacks.
When cyberattacks occur, organizations often face a critical challenge: determining which recovery points are safe to restore. While security teams may quickly identify indicators of compromise (IOCs), recovery teams still need to validate backup data before recovery can begin, delaying recovery efforts when every minute of downtime matters.
Google Threat Intelligence combines Mandiant frontline intelligence, VirusTotal’s crowdsourced intelligence, and Google threat insights gained from protecting billions of users. Integrating Commvault Threat Scan workstreams with Google Threat Intelligence helps customers analyze protected workloads for malware, while also helping organizations identify threats and pinpoint which recovery points are compromised. Commvault Threat Scan customers will also receive actionable threat context from Google Threat Intelligence for threats found in their environment to help with further research and remediation.
As part of this release, Commvault is also introducing new scanning capabilities that collect file hashes inline during backup operations. File hashes, like individual fingerprints, provide a fast and easy way to quickly check recovery points against threat intelligence indicators so teams can identify clean files to be used for recovery.
Commvault’s inline inspection capability allows customers to start with rapid threat intelligence validation and selectively perform deeper malware, encryption, and forensic analysis when additional inspection is required. This layered approach helps organizations accelerate recovery decisions while maintaining confidence in the integrity of restored data.
These new threat insights and scanning capabilities power Commvault’s Synthetic Recovery capability, which uses an AI-enabled process to automatically detect threats and surgically remove them during recovery while keeping the “good” data intact. Customers can then make the most complete recovery possible.
“Businesses need confidence that the data they’re restoring is clean,” said Pranay Ahlawat, Chief Technology and AI Officer at Commvault. “By combining Threat Scan and inline scanning with Google Threat Intelligence, we’re helping customers validate recovery points faster and accelerate clean recovery when it matters most.”
“Organizations are looking for ways to strengthen cyber resilience while reducing complexity during incident response and recovery,” said Miton Adhikari, Head of Google Security OEM Partnerships. “Through our collaboration with Commvault, customers will be able to apply Google Threat Intelligence within recovery workflows to make faster, more informed recovery decisions and reduce recovery uncertainty.”
This announcement builds upon Commvault’s ongoing collaboration with Google Cloud, including expanded cyber resilience capabilities for Google Cloud environments via Clumio, and support for Google Cloud workloads.
Availability
The Google Threat Intelligence integration, inline scanning capabilities, and associated Threat Scan enhancements are expected to be available in the coming months. To learn more about the Google Threat Intelligence integration and see a live demonstration of the integration, attend Google’s Theater Session featuring Commvault at Black Hat on Tuesday, August 4, at 6:20pm PT, on Mandalay Bay Convention Center Expo Floor or visit the website.
Related News:
Commvault Unveils IDC Resilience Operations White Paper
Commvault Outlines Resilience Strategies for the Frontier AI Era