
NetBackup Connector
Use Elastio to continuously inspect your Veritas NetBackup data for ransomware, malware, and hidden tampering. With native Veritas integration, Elastio verifies backup integrity, identifies the last known clean recovery point, and provides clear, actionable insights grounded in real behavioral scanning rather than job completion alone.
Why This Matters
Backups are often considered the last line of defense, but ransomware actors know this and frequently target backup servers, catalog data, recovery points, and shadow copies. If a backup chain is silently encrypted or tampered with, it cannot be trusted during a recovery. Job completion and immutability settings show that backups ran, but they do not confirm that the data inside is clean.
Elastio fills this gap by providing continuous, behavioral ransomware inspection for your Veritas NetBackup workloads. The integration gives you an automated control that verifies whether each backup is recoverable, clean, and safe to restore. This strengthens incident response preparedness, simplifies audit processes, and improves confidence in your disaster recovery posture.
Key Capabilities
Native Integration with Veritas NetBackup
- Works directly with the NetBackup Backup Server using authenticated API access.
- Fully supported for on-premises environments through the Elastio Worker VM or Elastio Cluster.
Behavioral Ransomware Scanning of Backups
- Scheduled or on-demand inspections of backup data.
- Detects encryption activity, malware indicators, insider-driven data manipulation, and corruption that traditional backup checks miss.
Identification of Clean Recovery Points
- Elastio determines the last known clean backup set for each asset.
- Eliminates guesswork and dramatically accelerates recovery during ransomware events.
Compliance and Risk Visibility
- Track which backup sets are validated, clean, misconfigured, or require investigation.
- Helps satisfy internal governance, cyber insurance reviews, and regulatory reporting.
Seamless Fit with Existing Veritas Workflows
- Elastio automatically scans after Veritas backup jobs are completed.
- No changes needed to backup schedules or NetBackup policies.
How It Works (High-Level Architecture)
- Veritas NetBackup executes backup jobs as usual.
- The Elastio Worker VM or cluster connects to the NetBackup Backup Server through its native APIs and identifies completed backup sets.
- Elastio mounts the relevant recovery points without rehydrating data, ensuring efficient and scalable inspection.
- Elastio runs its behavioral ransomware engine on the mounted data, detecting signs of encryption, tampering, malware, or suspicious activity.
- Results are sent to the Elastio console, your SIEM, and reporting dashboards. Backups are marked as Clean or High Risk.
- Your SOC, IR, or DR team uses the verified clean recovery point information to guide safe restorations and perform forensic analysis when needed.
Elastio also offers advanced threat hunting capabilities and access to incident response specialists for detailed investigations.
Deployment Scenarios and Use Cases
Hybrid and On-Premises Veritas Environments
Ideal for organizations running NetBackup on dedicated infrastructure. Elastio provides an ongoing view of backup health and recovery readiness.
Highly Regulated Industries
Financial services, healthcare, and government organizations benefit from auditable proof that backup data is free from ransomware and safe to restore.
Ransomware Incident Preparedness
During an attack, recovery speed determines impact. Elastio pinpoints the cleanest possible recovery point, avoiding delays caused by scanning multiple backups or restoring contaminated data.
Disaster Recovery Modernization
Elastio strengthens existing Veritas deployments with continuous assurance rather than relying solely on point-in-time checks or manual verifications.
Setup and Prerequisites
NetBackup Requirements
- A NetBackup user with the Administrator role for API operations.
- Network connectivity between the Elastio Worker VM and the NetBackup Backup Server.
Elastio Worker VM or Cluster Requirements
- Minimum VM spec: 4 vCPUs, 16 GB RAM, 100 GB storage.
- Supported hypervisors: VMware vSphere.
- Static IP configuration and access to required outbound endpoints.
Deployment Steps
- Deploy the Elastio Worker VM or cluster using the provided OVA or CloudFormation templates.
- Configure network settings, static IPs, DNS, and required ports.
- Initialize the Elastio console and cluster with Veritas as the selected vendor.
- Provide AWS credentials and NetBackup access keys during setup.
- Create scanning plans that define included assets, schedules, scan types, and retention rules.
- Monitor scan queues, performance metrics, and results through Grafana and the Elastio console.
Why Elastio vs Traditional Backup Validation
Backup job logs and immutability settings confirm that backups exist, but they do not protect against:
- Malicious encryption hidden in the dataset
- Tampered or corrupted recovery points
- Insider attacks that bypass perimeter defenses
- Stealthy malware embedded in backup files
Elastio adds a behavioral ransomware detection layer to every Veritas backup, providing verifiable proof of which recovery points are clean, safe, and ready for restoration.
This reduces downtime, eliminates guesswork, and dramatically improves recovery confidence during ransomware events.
More Elastio Integrations
Other tools Elastio connects with across your stack.

Cohesity Backup Connector
Cohesity
Automated ransomware assurance for your Cohesity backups & cloud snapshots.
View Cohesity Backup Connector
Commvault Backup Connector
Commvault
Automated ransomware assurance for your Commvault on-premise backups.
View Commvault Backup Connector
Rubrik Backup Connector
Rubrik
Automated ransomware assurance for your Rubrik on-premise backups.
View Rubrik Backup Connector
Datadog
Datadog
Send Elastio ransomware recovery and data integrity findings into Datadog to power incident response, threat hunting, and compliance reporting.
View Datadog
Splunk
Splunk
Elastio brings real-time ransomware and backup-integrity insights into Splunk, allowing analysts to correlate threats, spot compromised recovery points, and restore safely with confidence.
View Splunk
VS Code
Microsoft
Ransomware and Recovery Intelligence Directly Inside Your Editor.
View VS CodeFrequently Asked Questions
Common questions about this integration.