Commvault is adding threat intelligence data from Google Threat Intelligence to its recovery capabilities. According to the company, the integration is designed to help customers identify clean recovery points more quickly following cyberattacks.
Commvault has announced a new integration with Google Threat Intelligence, according to the company. The move brings data and scanning capabilities from Google’s threat intelligence platform directly into Commvault Threat Scan workflows. Commvault states that the integration is intended to let customers factor global threat intelligence into the recovery process itself, helping them locate clean recovery points more quickly and speeding up recovery after cyberattacks.
The announcement addresses a challenge familiar to many IT teams following a security incident: while security teams can typically identify indicators of compromise (IOCs) relatively quickly, the teams responsible for recovery must first validate backup data before the recovery process can begin. That intermediate step can delay recovery efforts at a point when time is a critical factor.
Google Threat Intelligence combines insight from several sources, the company says, including Mandiant Frontline Intelligence, VirusTotal, and Google Threat Insights. Through the connection to Commvault Threat Scan, customers are meant to be able to scan protected workloads for malware, detect threats, and determine which recovery points have been compromised. Commvault Threat Scan is designed to provide context around identified threats within a customer’s environment, intended to support further analysis and remediation.
New scanning capabilities for file hashes
Commvault is also introducing new scanning capabilities that capture file hashes inline, during the backup process itself. These hashes function as unique identifiers for individual files and are meant to let teams quickly cross-reference recovery points against threat indicators, helping them select files that are clean for recovery.
With the inline scanning capabilities, customers can validate backups against current threat intelligence and, where needed, trigger deeper analysis — for example, to search for malware or encryption artifacts or to begin forensic investigations. According to Commvault, this staged approach is intended to speed up recovery decisions while also providing clarity on the integrity of restored data.
Commvault says the new threat data and scanning features are also meant to reinforce its Synthetic Recovery capability, which uses an AI-driven process designed to automatically detect and remove threats during recovery while preserving unaffected data.
“Organizations need confidence that the data they are restoring is free of threats,” Pranay Ahlawat, Chief Technology and AI Officer at Commvault, is quoted as saying in the announcement. He added that combining Threat Scan and inline scanning with Google Threat Intelligence is meant to help customers validate recovery points more quickly and accelerate clean recovery.
Miton Adhikari, Head of Google Security OEM Partnerships, is quoted as saying that organizations are looking for ways to strengthen cyber resilience while reducing the complexity of incident response and recovery. According to Adhikari, the collaboration with Commvault is designed to let customers integrate Google Threat Intelligence into their recovery workflows, supporting faster, more informed decisions and reducing uncertainty during recovery.
The announcement builds on Commvault’s existing collaboration with Google Cloud, which according to the company already includes extended cyber resilience capabilities for Google Cloud environments through Clumio, as well as support for Google Cloud workloads.
Availability
According to Commvault, the Google Threat Intelligence integration, the inline scanning capabilities, and the associated Threat Scan enhancements are expected to become available in the coming months. Further information on the partnership between Commvault and Google is available on the companies’ partner page.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de