Overview
The Veeam Apps for Palo Alto Networks bring backup intelligence into Cortex XSIAM and Cortex XSOAR. Backup and security events, recovery context, and response actions all arrive in the SOC, so security teams can enrich threat detection, investigate faster, and coordinate response and recovery without leaving the workflows they already use. Available to Veeam Data Platform Advanced and Premium customers.
Security teams rarely have visibility into what is happening inside the backup environment. Malware detections, suspicious restore activity, configuration changes, and compliance gaps sit in tools owned by backup administrators, so they never reach the SOC — and analysts lose time chasing that context in the middle of an incident.
The Veeam App for Palo Alto Networks Cortex XSOAR helps close that gap. It uses the Veeam Backup & Replication and Veeam ONE REST API to create incidents for malware detections, suspicious activity, and the health of your backup infrastructure. Analysts can triage incidents from the built-in Veeam Incident Dashboard and initiate predefined actions through built-in playbooks, without opening a backup console or handing the ticket to a backup administrator.
The content pack includes:
- What the app ingests as incidents:
- Malware detections, including Indicators of Compromise found in protected data (new in v2)
- Recon threat states identified in the backup environment (new in v2)
- Security & Compliance Analyzer violations (new in v2)
- SureBackup Content Scan findings (new in v2)
- Backup repository anomalies and capacity issues
- Configuration backup state
- Alarms triggered in Veeam ONE
- What analysts get in Cortex XSOAR:
- The Veeam Incident Dashboard for a view of incidents and API activity handled by the app
- Custom incident types and fields, with classifiers and incoming mappers already mapped
- Restore point information and backup context, retrieved without leaving the incident
- Four-eyes authorization events, to investigate risky administrative actions (new in v2)
- Microsoft Entra ID validation — confirm protected users exist in the latest backup, and compare backed-up objects against production to spot changes (new in v2)
- What analysts can trigger from a playbook or incident:
- Instant VM Recovery for VMware vSphere, manually or automatically
- Instant VM Recovery for Hyper-V (new in v2)
- Quick Backup, to preserve recovery options mid-investigation
- Antivirus and YARA scans against backup data (new in v2)
- A Security & Compliance Analyzer assessment (new in v2)
- Disk publishing via the Data Integration API for forensic analysis (new in v2)
- Configuration backup
- Resolution of Veeam ONE alarms
- Any of the above as a one-click action from the incident view (new in v2)
Generic access to supported Veeam Backup & Replication REST API endpoints to extend the existing VBR integration with custom investigations and workflows (new in v2).
Documentation
Screenshots






