Veeam Expands Palo Alto Networks Cortex Integrations for Deeper Investigation and Response

Security teams rely on signals from across the environment to understand and respond to cyber threats. But critical activity within the backup environment can remain disconnected from the tools and workflows used by the SOC.

The Veeam App for Palo Alto Networks helps close that gap by bringing Veeam backup and security events, recovery context, and response actions into Cortex XSIAM and XSOAR. Security teams can enrich threat detection, accelerate investigations, and better coordinate response and recovery without leaving the workflows they already use.

 Now, Veeam is expanding the app with new capabilities that help SOC analysts and incident responders investigate protected data more effectively and incorporate Veeam insights into their security workflows.

Building on the Veeam + Cortex Integration

The Veeam App for Palo Alto Networks already connects Veeam with Cortex XSIAM and XSOAR to bring backup intelligence into security operations. The app’s existing capabilities help security teams monitor supported Veeam activity, correlate supported Veeam events with broader security signals, create incidents, and initiate predefined actions such as Quick Backup and Instant VM Recovery.

Deeper Investigation and Response with Cortex XSOAR

Now, Veeam is expanding the Cortex XSOAR integration, giving SOC analysts and incident responders more ways to investigate suspicious activity and act within existing security workflows through the following methods:

  • Scan protected data with Veeam Threat Hunter, antivirus, and YARA to investigate potential malware and suspicious files.
  • Validate protected Microsoft Entra ID users and objects to add identity context to investigations.
  • Publish disks through the Veeam Data Integration API to support deeper forensic analysis.
  • Run Security & Compliance Analyzer assessments, start configuration backups, and resolve Veeam ONE alarms as part of incident workflows.
  • Extend security workflows through the Generic API Request capability using available Veeam Backup & Replication REST API endpoints for custom investigations and workflows.

Security Visibility and Correlation with Cortex XSIAM

The existing Cortex XSIAM integration brings supported Veeam backup and security events into the SOC alongside endpoint, identity, network, and other security signals. This gives security teams centralized visibility into Veeam activity and additional context to support threat detection and investigation.

Security teams can also create Veeam-specific incidents in Cortex XSIAM and use relevant automation to support investigation and response workflows.

Bringing It All Together

Together, Cortex XSIAM and XSOAR connect Veeam security signals, investigation capabilities, and response actions across the incident lifecycle. By bringing Veeam security context and actions into the SOC, Veeam and Palo Alto Networks help security and backup teams work together from detection through recovery.

Get Started

The Veeam App for Palo Alto Networks is available to Veeam Data Platform Advanced and Premium customers through the Cortex Marketplace.

 

The post Veeam Expands Palo Alto Networks Cortex Integrations for Deeper Investigation and Response appeared first on Veeam Software Official Blog.

from Veeam Software Official Blog https://ift.tt/Y4Af3Cm

Share this content: