Transcript
Hello, Rick, and hello, community. Yeah, I'm doing well, but how about yourself? You've been on vacation for a week. You look a bit tanned, so I'm looking forward to hear all about that. Yeah, I take good vacations, and I take a lot of vacations, so that's good. I just went to coastal Maryland in the U.S., so down by the Chesapeake and then the Atlantic Ocean. It's a really interesting part of the U.S. It was really nice to get out, and I'll sneak in a picture when we go through our featured content, but yeah, vacations are good. As normal, the community carried on, and we had the recap last week. I appreciate you doing that, so yeah. Yeah, indeed. I mean, we did only a post, but now we have a lot to cover. It was pretty difficult to pick up some articles. I almost wanted to break the rules because I found some good ones, but then I was like, let's just skip it to the standard level. Maybe next time. Who knows? Well, you never know, and on top of that, we have some super big news in the special department department, so I think it's time to jump in. You ready? Yeah, let's do it. All right, and well, we are breaking the rule because I'm going to start with a special picture. This was from my vacation. I do the camper van, like RV camping. That's my car and the camper there. We had a night here on this farm. What a view. It was so nice and so quiet, and then this was just behind the picture here was a brewery, and they had a food truck, a pizza food truck, so it was a wonderful night. It looks pretty peaceful if you ask me. Yeah, indeed. It looks really beautiful, such a beautiful place to spend the night, right? Glad that you enjoyed it. Yeah, this was on the way to the ocean, so this was one of the nights on the way to the ocean. This was in Cumberland, Maryland in the US, so Maryland's a big state. Anyways, good stuff. Back to serious business. All right, first up with our content is Ken talking about a lab hands-on test with the Veeam backup and replication 13.1 beta. I like this. Yeah, me too, and I think this is actually the first one article that I've seen at the Community Hub talking about V13.1, so I think there's going to be many more, but happy to have Ken open the door for us. This is a really good article with a lot of print screens, and yeah, I'm very curious to see what other people are going to test and how they're going to test it and how they're going to share their perspectives, but yeah, with V13.1 getting closer to GA, the community, I'm telling you, is not going to waste time. So yeah, Ken, basically what he did, he got his hands dirty in the lab. He installed the beta, and he just shows us how it behaves in the real world. So in this article, what he's doing, he's just focusing on the basics. If it installs smoothly, how can I connect this with my infrastructure? Are the backups, are those working? And do the restores work as well? And then it seems like from what I've read throughout the article, that the impressions are positive, and the installation was pretty straightforward, and the interface, he says it's pretty familiar. The core backup recovery workflows perform exactly how you'd like them to do. I also like that he included a checklist at the end, so really good stuff in there. And I'm sure everyone is excited about this release, V13.1, so this article is worth checking it out. And Ken is also inviting us, if you already did your beta, if you already installed it, if you already got some experience with it, to also share it and tell your opinion. And I think I'm inviting you as well, together with Rick, to do the same. So we're really looking forward for what's coming next to the many articles, and also Ken says that in the next one, he's going to share more findings with us. Yes. So this is a really good post that does basically a walkthrough of just these, installation, configuration, and some testing. It's not really digging into the net new stuff. And I think that's important because there's new capabilities. We announced some of those at VeeamON in New York and London, and we have tricks up our sleeve for Sydney at the end of the month. But this is a really good way to understand how the beta applies, and this is really good stuff. So thank you, Ken. And for those of you who are like, well, how do I get the beta? You can reach out to your Veeam sales contact, and they can give you that because it is self-supported, meaning your account team supports you on it, right? So that's one of the mechanisms we put to help scale it. So good stuff, but we're getting very, very close to the GA, so this is a good way to warm up to it. So thank you, Ken. Totally. All right. Next up, Andreas Buhlmann has a topic with incredibly nice looking visuals, may or may not have AI helping, talking about MFA. And what caught your eye on this one, Maddy? Well, I think, first of all, it's like an unusual post, first of all. It's not your usual post that you're going to find at the community hub, but I think it's very interesting. And we've all been there. You know, you're creating a password and you think this is a strong password. You're adding an uppercase letter, a number, you know, maybe an exclamation mark, and then think, yep, nobody's getting into this account now, right? So we've all been there, I'm sure. And Andreas actually starts there with this story, exactly this story. And I like it because it's something, you know, we can all relate this from our day to day life and work. And, you know, he's talking about from the evolution of passwords to today's MFAs, he's explaining not just what MFA is, but, you know, why we've ended up relying on it. So he talks about time list, push notifications, TOTP codes, even why your authenticator app can generate a code without an internet connection. And then he also brings it back to Veeam, of course. And he explains where MFA makes perfect sense, you know, like protecting the interactive user accounts and where it actually, you know, you might not necessarily have to use it. Or it's actually recommended not to use it, you know, such as the service accounts that need to run unattended. And, you know, that's an important distinction that he's making in there, because that gets sometimes overlooked, as he says. And he says, OK, you know, MFA isn't always convenient. And I know it from my own experience, but that small inconvenience sometimes is what's going to stop a compromised password from becoming a much bigger problem. So if you've ever enabled MFA, because someone told you it was a best practice, but never really understood what was happening behind the scenes, I think this is one article that you should read. And even he ends in an unexpected way, if you look at it with a fun fact, who invented the QR code? So I think overall, it's easy to read pretty interesting facts. So I really enjoyed reading it. Thank you, Andreas, for sharing. Oh, the QR code. Masahiro Hara and his team, 1994, TensorFlow Wave. That's cool. Yeah, I think QR code is a cool technology. I used to do a lot of work in symbology. And yeah, this makes sense. Finder, alignment, timing, and then the data is kind of interleaved. And I like how it's actually much more advanced, because you can have a lot more detail. So like this symbology has that number only. It has a little bit of resiliency in case there's a tear or rip, as long as it doesn't take an entire line out. But there's a whole bunch of error correction logic that's built into QR code, which is actually pretty cool. So what I'm getting at is you can have a QR code, and you can cover up 20% of it, 40% of it, depending on how the error correction is built, and it'll actually still read, which is a nice thing. But this one actually caught my eye the most, Maddy. I want to talk about this one on multiple devices. So especially for Veeam stuff. So I use myself here. Let's see if I can pivot a little bit. This kind of works. I use Offly, which is an app that does the one-time passwords. But here's the thing. What if I lost my phone? So I know you know this, Maddy, but a lot of people may not know this, but I carry a separate phone that is my Veeam identity. So personal, Veeam. And I also have Offly going on there. So all the same things. And I've used that app to move that over so that I have some resiliency. Now, I do carry both phones with me, so I'm not really doing 3-2-1 one-time password rule. Wait, I do have it on my iPad at home. But to this point, you know, Andreas is talking about more devices, more risk. I have some resiliency across it, but just something to think about. Because if you lost your phone, you had to redo all those. And I mean, I have some on my personal finance accounts. I have my Veeam stuff. When I say Veeam stuff, I'm talking about Veeam software appliance and Veeam infrastructure appliances, right? So something to think about. If you have OTP going on, you might want to have it with multiple devices, but consider the risk of that. Yeah, for sure. Yeah, totally. I think with this article, Mateusz reminds us of something important. The recovery doesn't always go according to plan in most situations, probably. So you mentioned it already. Basically, his goal seems to be like an easy restoration of a physical Ubuntu server into a VMware environment using the Veeam agent backup. But yeah, the ideal recovery path wasn't an option in here, because instead of instant recovery, Mateusz had to pivot, export the disks as VMDKs, manually build a virtual machine, and then he discovered that he was still not able to boot it. So, you know, Mateusz gives us an interesting perspective here. And rather than assuming the backup had failed, he takes a step back, and he looks at the original server configuration, and then he starts eliminating possibilities one by one. I think that was his only option at that point, really. And he found out that ABIOS versus EFI were mismatching. So as I learned going over the article, this can be one of those small details that, you know, can be overlooked, especially when you are working under some pressure and you are doing like maintenance. And, you know, it can, but this can make a perfectly healthy backup appear unusable. So you have to be very careful, you have to check it, double check it. And, yeah, see where the problem comes. I'm pretty sure that was not fun at all for Mateusz, but let us know in the comments, Mateusz. It seems like a very tedious job in there. And, you know, we say that a lot, but I think repeating it is not a bad practice. Recovery isn't just about having a good backup. It's definitely understanding the whole environment you're actually recovering it into. So sometimes, or in many cases, you know, the issue isn't necessarily your backup, but it's everything around it. So it's really important to kind of understand how that environment works. So I also, at the end, really enjoyed the practical checklist of things to verify before you attempt this type of recovery. So a really good article, as always, Mateusz, you know, he's always sharing good stuff, practical stuff, day-to-day stuff from his own experience. And I think these are very valuable. Thank you very much, Mateusz. Yeah, and one thing I'll add that really comes on to what you were just talking about, Maddy, is so many times people are super familiar with, like, whole VM recovery and file level recovery. But there's, like, over 100 other ways to recover when you think about the agents, theme backup, and replication, and things like that. So in that situation, it's really nice to have the familiarity of what those other options are. In fact, I had, when I talked to the support team about ransomware advice, meaning, what do they see kind of going wrong when folks go through a ransomware event? And one of the things is, like, not having familiarity with some of the other ways to recover. So going through drills like this is really, really helpful, especially when you're not under the pressure. So thank you, Mateusz, for this and glad it worked out okay. And the other thing I'll highlight is this EFI to BIOS conversion, which is one of the roots of the situation here. That is built in, for example, when we do recoveries to the cloud, you know, so it's like in one of those things that it's actually the other way around. I think it's UEFI to BIOS versus EFI to BIOS, or BIOS to EFI, right? So it's like all those different scenarios. In some scenarios, they're fully productized, but in other times, we have to take some interventions. So good stuff, Mateusz. Thank you for sharing. All right, Vanguard Blog Spotlight. And I had to look this one up. We got a new blog that we're talking about at Kucha Fresca IT. Tell me if I'm getting that right. Happy to feature Othon Oliveira from Brazil. Yeah. Welcome to the Veeam Weekly Recap. This is definitely the first time we are mentioning your name and your blog. And it's great to have you. I thought this was, even though it's a little bit older, it's from May, we are in July, but I thought this was a pretty good article in here with a good perspective. So, you know, I was like, okay, let's do it. I do see an old logo in there, an old Veeam logo. This is AI. And this is actually half old, half very old. This looks like the 2017 and earlier logo. And this looks like the 2017 to 23 font. But that's what AI does. It's learning on all the different logos that are out there. Yeah, we actually used it, you know, in our last Veeam 100 show, Matthias put it, but he really wanted that one, the first one, because it just works, you know, so he really wanted that one. I was like, okay, let's do it. So yeah. But anyway, Othon is talking about inline malware detection. And, you know, we talked previously about this v13 capability, I think, in many occasions since, you know, we kind of launched v13. But I thought, as I said, he had an interesting approach in this article. So I really wanted to discuss it. Also, I took the opportunity that, you know, it was a good article, and he was never mentioned in the recap. So I thought, yeah, for all good reasons, let's talk about it. So he starts by explaining how malware detection has traditionally worked in backup environments where data is scanned only after the backup job has finished. And from there, he explores how Veeam takes a different approach by analyzing data while it's already moving through the backup pipeline. And this way is kind of helping to identify any suspicious activity. You know, and discover it on time. Then he goes and he breaks down the two key technologies behind it, the inline scan, and then the guest indexing. So he talks about both. And then, to make these concepts easier to understand, Otten uses a really good airport security analogy showing how both layers work together to reduce false positives, and then help you identify which restore points may already be impacted. So I do remember when, you know, v13 was kind of launched, was GA, everyone was kind of excited about this. I think Shane wrote about it, and we talked. So all the community was pretty excited about this capability. And Otten, at the end, shares a practical ransomware scenario. And then an important reminder that, you know, these capabilities aren't designed to replace your EDR or security tools. So that's important. You know, it's just complimentary. You know, their role is basically to help you quickly identify the last known good restore points so recovery can begin just there. So I thought this was pretty good, very long, very German style, even though it's Brazilian. But yeah, happy to have you and thank you for this great article. Yeah, indeed. Thank you, Otten. And a couple of things, you might have caught it on the scrolling. The actual text is in Brazilian Portuguese, but I'm doing the browser translation. And you can see this diagram he made does have Portuguese logos or texts. But one thing I want to highlight that's a real important part of it is this this checkbox here. So this the file detection. Two things. One, I think he mentions it, but this does require that you have file system indexing running on the backup job. So meaning if you don't have file system indexing this won't kick in. I want to draw your attention to this one because this is actually an additional really interesting area where this box here will do mappings of things associated with TTPs from the MITRE ATT&CK framework. So on this show I've done a lot of times where I've brought up this KB4514, for example, and if you click on that actual file. And, you know, if you haven't updated it, by the way, it's time to do it. KB4514. But those indicators of compromise are down here at the bottom. So basically, if this file shows up that's associated with the TTP of impact. And then, for example, if these other files show up, you know, this is behavior associated with these different areas of impact and you just scrolling up. Let's take one that I'm a little more familiar with. Yeah. Let's do this one like initial access. Right. So some of these things to get into things or credential access like retrieving passwords, these types of tools, if they show up will be detected. So really good post Othon and while we're at it. If you have a Veeam backup and replication server that is not connected to the internet. Let's update that file here. KB4514. All right. Now we're going to go over to special department and I'm saving one for the last. And this one is from you, Maddy. I call it the bottom. BOTM. Bottom. You probably don't like that. We should probably just call it blog. Let's just skip it. Blog of the month. Okay. Don't try to make an acronym out of it. Okay. Yeah. But yeah, congratulations, Jason. I think that was a really great article and a great project. So I think everyone agreed he had he won with I think eight votes. So just taking the opportunity to thank Jason and everyone that is participating month after month and producing great content that goes to the blog of the month. He already got his badge. Let's see who's next in July for blogger of the month. Yeah. I love these visuals. They're great. So congrats, Jason. Blog of the month, July 2027. All right. Last up in special department. Big news at Veeam. The Gartner Magic Quadrant for 2026 is out. You can go to Veeam.com and download a copy right here. I can't show it to you on this, but I can talk about it a little bit. A lot of people go to the picture. Okay. But we did really well. We're really happy about the position. But I really recommend everyone read the stories. There's strengths and cautions for each vendor. There's some areas that really apply to the whole industry. And I want the market to be informed here. So definitely check it out. We're really happy about it. We love the highest ranking on ability to execute. So it's this kind of, I guess it would be the y-axis there. So really like that position there. Highly recommend you check it out. I can say myself and so many others on our product teams, this is really what the whole month of March goes to. We put a lot of work in and so do the other vendors. I mean, this is not something anyone takes lightly. An important moment for sure. Congratulations Veeam. Congratulations team. Congratulations everyone at Veeam. And yeah, everyone can just download it from here. But just to mention the strengths, because I think they are really great things that are, you know, they've been developed in the past months, 12 months at Veeam. Security, AI integration with Veeam, cyber extortion, incident response services like Cogware, Linux software appliance are all great achievements. So yeah, there is so much more in there. So, you know, just listen to Rick and just go and download it and be informed because it is important. It is, it is. And definitely encourage you to check it out. And you know what, talk about it with your Veeam contact, you know, if you have an account team. They've been kind of shared it internally. So definitely check it out and would love to talk more about that. And honestly, congratulations Gartner. It's a lot of work on their side too. I'm very close, you know, in a professional context to the folks right here. So Mike, Jason, Sankalp, Rizvan, and there's even more to the team there. But thank you all as well Gartner team. It's a fantastic asset for the industry. All right. Last up, who's new from the desk of Sofia right next door to me here. We're happy to welcome Plus 99, Red Carpet 1-2, Wilson Wilson. Nice, nice. I like that. Red 75. That sounds like a football play. Plankton 82 with Alfred's pick being Alchemist. Love that. Straight from Paulo Coelho's novels. Exactly, exactly. And so see if I get this right. I did. I'm getting to be an expert on this new platform. I'm very happy with myself. All right, Maddy. Well, hey, that's a great list of content this week. And I'll be back next week, believe it or not as well. That's good. So normal circumstances for us once again. And who knows the week after. I can do normal week after the three weeks in. I don't know. We'll see. What's going on? All right, everyone. Thanks for watching. This was 269. We will see you next week on 270.