Commvault is integrating Google Threat Intelligence into its Threat Scan product, announced today. The integration pulls in Mandiant frontline intelligence, VirusTotal's crowdsourced data, and Google's own threat signals to check backup data against known indicators of compromise before recovery begins.
The practical problem: attackers often remain undetected inside systems long enough to compromise backup copies. When recovery teams activate a restore point, they risk restoring malware alongside the data. Commvault's new inline scanning, introduced alongside the integration, generates file hashes during backup operations — fingerprinting each file so it can be quickly checked against threat intelligence when a restore is needed.
The Google threat intelligence is refreshed daily. When Threat Scan flags a file, the integration surfaces additional context — which threat actor, which malware family — to help teams decide whether to investigate further or simply move to an earlier clean recovery point. This layered approach is designed to let organisations start with rapid validation and selectively trigger deeper malware and forensic analysis only where needed.
Businesses need confidence that the data they're restoring is clean. By combining Threat Scan and inline scanning with Google Threat Intelligence, we're helping customers validate recovery points faster and accelerate clean recovery when it matters most.
Pranay Ahlawat, Chief Technology and AI Officer at Commvault
Organisations are looking for ways to strengthen cyber resilience while reducing complexity during incident response and recovery. Through our collaboration with Commvault, customers will be able to apply Google Threat Intelligence within recovery workflows to make faster, more informed recovery decisions and reduce recovery uncertainty.
Miton Adhikari, Head of Google Security OEM Partnerships
The capabilities feed into Commvault's Synthetic Recovery feature, which uses AI to detect and surgically remove threats during the recovery process itself. The Google Threat Intelligence integration and inline scanning are expected to become generally available in the coming months. Commvault and Google will present a live demonstration at Black Hat on 4 August.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter