Commvault has integrated its Threat Scan capability with Google Threat Intelligence. The move aims to help organisations identify clean recovery points faster and cut the delay between a cyberattack and a safe restore.
The integration incorporates Google Threat Intelligence data and scanning into Commvault Threat Scan workflows. It addresses a common problem after an attack. Security teams may quickly identify indicators of compromise, but recovery teams still need to validate backup data before a restore can begin.
Google Threat Intelligence combines Mandiant frontline intelligence, VirusTotal's crowdsourced data and Google's own threat insights. Integrating it with Threat Scan lets customers analyse protected workloads for malware and pinpoint which recovery points are compromised. Threat context is provided for further investigation.
As part of the release, Commvault is adding scanning that collects file hashes inline during backup operations. The company likens file hashes to fingerprints. They give teams a fast way to check recovery points against threat intelligence indicators and identify clean files for recovery.
The inline inspection lets customers start with rapid threat intelligence validation, then selectively run deeper malware, encryption and forensic analysis when needed. Commvault says the layered approach speeds recovery decisions while maintaining confidence in restored data. The capabilities also strengthen its Synthetic Recovery feature, which detects and removes threats during recovery while keeping clean data intact.
"Businesses need confidence that the data they're restoring is clean," said Pranay Ahlawat, chief technology and AI officer at Commvault. "By combining Threat Scan and inline scanning with Google Threat Intelligence, we're helping customers validate recovery points faster and accelerate clean recovery when it matters most."
Miton Adhikari is head of Google security OEM partnerships. He said customers would be able to apply Google Threat Intelligence within recovery workflows to make faster, more informed decisions and reduce recovery uncertainty. The announcement builds on Commvault's existing collaboration with Google Cloud.
The Google Threat Intelligence integration, inline scanning and associated Threat Scan enhancements are expected to be available in the coming months.