Skip to content

Veeam Forensic Investigation: DFIR Triage, Database Analysis, and Artifact Hunting

HERMES

HERMES DFIR CAPABILITY SCORE & ARTIFACT DEPTH

Target: Veeam Backup & Replication Configuration DB, Service Logs & Volatile Memory
Confidence: 99%
95 / 100
CRITICAL

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 19 / 20
Threat Activity 20 / 20
Weaponization 19 / 20
Exposure 18 / 20
Prevalence 19 / 20
Impact 20 / 20
Exploit Maturity 20 / 20
Attack Chain Potential 20 / 20
โš–๏ธ Divergence & Operational Rationale

Hermes DFIR Lab rates Veeam forensic depth at 95 (CRITICAL). In compromise investigations, the Veeam server contains the definitive evidentiary record of adversary actions: timestamped session logs reveal exactly which backups were staged or wiped, SQL audit tables log administrative modifications, and DPAPI registry keys indicate whether the adversary harvested the enterprise credential store.

๐Ÿ•ธ๏ธ Connected Knowledge Graph & Provenance

Veeam Backup & ReplicationPRODUCT

Connected Nodes: 0

Upon arriving at a suspected Veeam compromise, follow this sequential triage procedure to preserve evidentiary integrity while mitigating active data wiping.

Veeam DFIR Triage Sequence:
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Phase 1: Isolation (Prevent Outbound Data Wiping) โ”‚
โ”‚ - Disconnect network interfaces or enforce host isolation โ”‚
โ”‚ - DO NOT shut down (preserve RAM and DPAPI keys) โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”‚
โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Phase 2: Live Volatile Memory Acquisition โ”‚
โ”‚ - WinPmem / LiME / DumpIt capture of full RAM โ”‚
โ”‚ - Capture network sockets: netstat -ano > netstat.txt โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”‚
โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Phase 3: Configuration Database & Key Preservation โ”‚
โ”‚ - Snapshot PostgreSQL / MSSQL database instance โ”‚
โ”‚ - Export HKLM\SOFTWARE\Veeam registry hives โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
โ”‚
โ–ผ
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Phase 4: Forensic Log Extraction โ”‚
โ”‚ - Collect %ProgramData%\Veeam\Backup\ โ”‚
โ”‚ - Export Windows Security, System, and PowerShell EventLogs โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Veeam maintains an exhaustive, structured log repository under the hidden directory %ProgramData%\Veeam\Backup\. Understanding this structure is essential for manual and automated triage.

Veeam Backup & Replication Log Hierarchy:
C:\ProgramData\Veeam\Backup\
โ”œโ”€โ”€ Svc.VeeamBackup.log <-- Core management engine activity & RPC transactions
โ”œโ”€โ”€ Svc.VeeamBroker.log <-- Console UI requests and broker API calls
โ”œโ”€โ”€ Svc.VeeamDataAnalyzer.log <-- Inline malware detection and entropy scanning logs
โ”œโ”€โ”€ VeeamThreatHunter.log <-- Threat Hunter service activities (.NET Remoting 6175)
โ”œโ”€โ”€ Svc.VeeamMount.log <-- Mount service & vPower NFS operations (TCP 6172)
โ”œโ”€โ”€ Svc.VeeamDeployment.log <-- Component package deployment and upgrade operations
โ”œโ”€โ”€ Malware_Detection_Logs\ <-- Suspicious file extensions, entropy anomalies, YARA matches
โ”œโ”€โ”€ Job_Sessions\ <-- Granular second-by-second logs per backup job run
โ””โ”€โ”€ [Job_Name]\ <-- Dedicated directory for each configured backup job
  • Svc.VeeamBackup.log: Records all administrative commands, job scheduling changes, repository status transitions, and credential lookups. Contains records of RemoveBackup or DeleteFromDisk API invocations.
  • Svc.VeeamMount.log: Must be inspected if CVE-2024-40711 is suspected. Look for unexpected client connections originating from non-backup IP addresses immediately prior to process creation events.
  • VeeamThreatHunter.log: Primary investigative artifact for CVE-2026-44963. Records inbound .NET Remoting proxy bindings and unexpected object callbacks over TCP 6175.
  • Svc.VeeamDataAnalyzer.log: Contains evidence of inline ransomware detection triggers. If a ransomware actor attempted to back up already-encrypted files, the entropy analyzer flags high-entropy blocks and known ransom extension strings (e.g., .akira, .locked).

Correlating Veeam service logs with native Windows Event Logs provides proof of adversary execution and privilege escalation.

Event Log SourceEvent IDForensic Significance in Veeam Compromise
System7045Service Creation: Detects creation of rogue persistence services spawned during post-exploitation (e.g., PsExec services or backdoor tools).
Security4624 / 4625Logon Activity: Logon Type 3 (Network) or Logon Type 10 (RDP). Identifies unauthorized lateral movement onto the backup host.
Security4720User Account Creation: Threat actors exploiting CVE-2024-40711 routinely execute net user <name> /add immediately upon RCE.
Security4732Local Group Membership: Look for the newly created user being added to the local Administrators group.
PowerShell4104Script Block Logging: Captures execution of Veeam PowerShell cmdlets (e.g., Remove-VBRBackup, Get-VBRCredentials) used to dump secrets or wipe data.
Microsoft-Windows-VSS8194 / 13Volume Shadow Copies: Correlates commands attempting to delete local Windows shadow copies (vssadmin delete shadows).

Veeam stores its entire state, infrastructure inventory, job definitions, and credential repository in a relational configuration database (PostgreSQL by default in v12+, MSSQL in legacy installations).

  • [dbo].[Credentials]: Stores the organizationโ€™s privileged credentials. The data column contains an XML blob with the username and the DPAPI-encrypted password string.
  • [dbo].[Backup.Model.BackupJobs]: Records all configured backup jobs, source VMs, and schedule parameters.
  • [dbo].[Backup.Model.JobSessions]: Contains the historical record of every executed backup, restore, or deletion session with exact start/end timestamps and initiator identities.
  • [dbo].[AuditLog] / [dbo].[AuditEvents]: Records user actions performed via the Veeam console or REST API.
-- 1. Identify Deleted Backup Chains or Manual Backup Erasures
SELECT
session_id,
job_name,
creation_time,
end_time,
result,
description
FROM "Backup.Model.JobSessions"
WHERE description ILIKE '%delete%'
OR description ILIKE '%remove%'
OR job_name ILIKE '%delete%'
ORDER BY creation_time DESC;
-- 2. Audit All Configured Credentials in the Database
SELECT
id,
user_name,
description,
modification_date,
account_type
FROM "dbo.Credentials"
ORDER BY modification_date DESC;
-- 3. Detect Recent Changes to Backup Retention Policies
SELECT
id,
name,
schedule_enabled,
last_modified,
retention_days
FROM "Backup.Model.BackupJobs"
ORDER BY last_modified DESC;

Threat actors (including FIN7 and Akira) frequently extract stored credentials from Veeam using publicly documented techniques:

DPAPI Credential Extraction Mechanism:
1. Query Database:
SELECT user_name, data FROM [dbo].[Credentials];
โ”‚
โ–ผ
2. Parse XML Blob:
<Credentials user="DOMAIN\Administrator" password="AQAAANCMnd8BFdERjHoAwE..."/>
โ”‚
โ–ผ
3. Retrieve Registry Salt (VBR v12.1+):
HKLM\SOFTWARE\Veeam\Veeam Backup and Replication\Data -> Entropy Value
โ”‚
โ–ผ
4. Invoke DPAPI Native Decryption:
[System.Security.Cryptography.ProtectedData]::Unprotect(
$EncryptedBytes,
$EntropyBytes,
[System.Security.Cryptography.DataProtectionScope]::LocalMachine
)
  • Execution of unauthorized PowerShell processes importing Veeam.Backup.Common.dll or System.Security.Cryptography.
  • PowerShell Event ID 4104 containing references to Veeam-Get-Creds, SharpVeeamDecryptor, Unprotect, or [dbo].[Credentials].
  • Anomalous read access to registry key HKLM\SOFTWARE\Veeam\Veeam Backup and Replication\Data originating from non-Veeam processes.

Prior to launching ransomware, adversaries must neutralize backup repositories and frequently exfiltrate the backup files themselves.

Adversaries use either the Veeam PowerShell module or direct disk-level commands:

  • PowerShell Snap-In Abuse:
    Terminal window
    Get-VBRBackup | Remove-VBRBackup -FromDisk -Confirm:$false
    Look for this exact command block in PowerShell Event ID 4104.
  • Low-Level Disk Wiping: Adversaries execute diskpart, vds.exe, or wbadmin to wipe volumes:
    Terminal window
    echo select disk 1 > s.txt && echo clean >> s.txt && diskpart /s s.txt
    Check Windows Event ID 4688 (Process Creation) and the USN Journal on storage volumes.

Veeam full backup files (.vbk) and incremental files (.vib) contain complete filesystem images. Adversaries frequently exfiltrate these archives to conduct off-site extortion:

  • Network Exfiltration Tooling: Inspect SRUM (System Resource Usage Monitor), Shimcache, and Amcache for recent execution of tools like rclone.exe, megasync.exe, 7z.exe, or winscp.exe.
  • Large Read Operations: Review SRUM table NetworkData for unusually large data transfers (hundreds of gigabytes) directed to external cloud IPs.

Terminal window
<#
.SYNOPSIS
Veeam Emergency DFIR Triage Collector
.DESCRIPTION
Collects critical Veeam service logs, queries local database state,
and inspects event logs for exploitation artifacts.
#>
[CmdletBinding()]
param (
[string]$DestinationPath = "C:\DFIR_Triage_Veeam"
)
Write-Host "[+] Initiating Veeam DFIR Triage..." -ForegroundColor Cyan
New-Item -ItemType Directory -Path $DestinationPath -Force | Out-Null
# 1. Collect Core Veeam Service Logs
$VeeamLogPath = "C:\ProgramData\Veeam\Backup"
if (Test-Path $VeeamLogPath) {
Write-Host "[+] Collecting core Veeam logs from $VeeamLogPath..." -ForegroundColor Green
Copy-Item -Path "$VeeamLogPath\*.log" -Destination $DestinationPath -Force
}
# 2. Extract Recent Rogue Account Creations (Event ID 4720)
Write-Host "[+] Hunting for local account creation (Event ID 4720)..." -ForegroundColor Green
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4720} -MaxEvents 50 -ErrorAction SilentlyContinue |
Select-Object TimeCreated, Id, Message |
Export-Clixml -Path "$DestinationPath\AccountCreations_4720.xml"
# 3. Hunt for PowerShell Veeam Backup Removal Commands (Event ID 4104)
Write-Host "[+] Inspecting PowerShell script blocks for backup deletion..." -ForegroundColor Green
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-PowerShell/Operational'; Id=4104} -MaxEvents 500 -ErrorAction SilentlyContinue |
Where-Object { $_.Message -match "Remove-VBRBackup" -or $_.Message -match "Unprotect" -or $_.Message -match "Credentials" } |
Select-Object TimeCreated, Message |
Export-Csv -Path "$DestinationPath\Suspicious_PowerShell_4104.csv" -NoTypeInformation
# 4. Capture Active Network Connections on Veeam Ports
Write-Host "[+] Dumping listening sockets and active connections..." -ForegroundColor Green
Get-NetTCPConnection | Where-Object { $_.LocalPort -in 6172, 6175, 9401, 9380 } |
Select-Object LocalAddress, LocalPort, RemoteAddress, RemotePort, State, OwningProcess |
Export-Csv -Path "$DestinationPath\Veeam_Sockets.csv" -NoTypeInformation
Write-Host "[+] Triage complete. Evidence archived in $DestinationPath." -ForegroundColor Cyan