Skip to main content


 

 

How can we help you?

 

Druva Documentation

Add file hash values of malicious files for scanning

Heads up!

We've transitioned to a new documentation portal to serve you better. Access the latest content by clicking here.

License editions: To understand the applicable license editions, see Plans & Pricing.

Overview

When you have identified a set of malicious files doing rounds in your organization, you can add the SHA1 value of those files so that Druva scans the data for those hash values. Whenever Druva finds a match, it will block the file from being restored.

Malicious file scan is not supported for files beyond 1 GB in size.

 

Add a SHA1 value that you want Druva to scan

  1. Login to Druva Cloud Platform Console and click Ransomware Recovery.

  2. On the left pane, click the Malicious File Scan > Settings tab.

  3. In the Indicators - File Hashes section, click Add File Hashes

  4. Add the files hashes and click Save

If you want to add multiple SHA1 hash values, then use the Import CSV option. 

Delete a SHA1 value from the list

  1. Login to Druva Cloud Platform Console and click Ransomware Recovery.

  2. On the left pane, click the Malicious File Scan > Settings tab.

  3. In the Indicators - File Hashes section, select the file hashes that you want to delete.

  4. Click More Options > Delete.

  5. On the Confirm Deletion confirmation pop-up, specify the reason for deletion (the reason is mandatory with a character limit between 10-150) and then click Delete. The reason for deletion will be captured in the Audit Trail for auditing purposes.

​​

  • Was this article helpful?