Threat-led pentest for Veeam backup & recovery.
ZeroPEN tests your Veeam Backup & Replication environment using the real tactics of active ransomware operators — simulating the attack chain that neutralizes backups before production encryption. Zero compromise: find it before the attacker destroys your Veeam backups.
Production-safe
PoC only — no live exploit
Audit-ready
Full findings report
Re-test included
Critical findings
Threat-led pentest for your last line of defense.
ZeroPEN is a threat-led penetration testing service that pressure-tests your most critical recovery layer — Veeam Backup & Replication — using the same tactics active ransomware operators use to neutralize backups before encrypting production. We simulate that attack chain in a controlled, non-destructive way and measure how resilient your Veeam infrastructure really is.
- Any organization running Veeam Backup & Replication
- IT organizations pursuing or maintaining ISO 27001 certification
- Organizations with GDPR / KVKK personal-data obligations
- Financial entities operating in the EU market under DORA
- Banks, participation banks, and financial institutions (BDDK / SPK scope)
Attackers target Veeam first. So do we.
Veeam is the de facto standard for enterprise backup — and exactly for that reason it is the attacker’s number-one target. Flaws such as CVE-2023-27532 and CVE-2024-40711 have been actively used by groups including Akira, Fog, Cuba, and FIN7 to take over Veeam servers and delete backups. ZeroPEN simulates that chain in a controlled, non-destructive manner.
Kill-chain simulation mapped to MITRE ATT&CK.
Each stage reflects observed behavior of real threat actors in Veeam environments — from initial access through backup neutralization.
-
Network access via VPN/RDP/phishing; internet-exposed VBR or Enterprise Manager ports.
-
Mapping the Veeam server, proxies, repositories, and job topology.
-
Kerberoasting the Veeam service account; configuration database credential extraction.
-
CVE-2024-40711 / CVE-2025-23120 RCE paths, authentication bypass, and config DB access.
-
SMB/NFS repository access, immutability bypass attempts, and VBR job manipulation.
-
Disabling jobs, shortening retention, and testing restore-point deletion authority.
-
Reading data from backups and controlled exfiltration — double-extortion simulation.
-
Controlled proof-of-capability only — no real encryption of production or backup data.
Safety commitment: ZeroPEN never deletes real backups, performs real encryption, or stops production or backup services. Destructive actions are limited to proof-of-capability and evidence collection.
Every Veeam component, systematically tested.
Veeam security best practices, verified.
Alongside the attack simulation, ZeroPEN verifies compliance with Veeam’s own hardening guide — and assesses critical CVE patch levels without active exploitation in production.
- VBR server domain-isolated, standalone, and hardened
- Hardened Linux Repository — XFS immutable (reflink) configuration
- Immutable cloud/S3 backup via Object Lock (compliance mode)
- Four-eyes authorization for backup deletion
- MFA and RBAC separation for Veeam management accounts
- Backup encryption (AES-256) and secure key storage
- 3-2-1-1-0 backup rule and immutability period verification
- Current Veeam patch level; known CVEs assessed at patch level only
Validated critical Veeam CVEs
| CVE | Title | CVSS | Impact |
|---|---|---|---|
| CVE-2025-23120 | Veeam B&R RCE by authenticated domain user (domain-joined) | 9.9 | Critical |
| CVE-2023-38547 | Veeam ONE information disclosure / RCE | 9.9 | Critical |
| CVE-2024-40711 | Veeam B&R unauthenticated RCE (CISA KEV, ransomware-exploited) | 9.8 | Critical |
| CVE-2024-29849 | Veeam Enterprise Manager auth bypass | 9.8 | Critical |
| CVE-2024-40710 | Veeam B&R RCE as service account / credential extraction | 8.8 | High |
| CVE-2024-40713 | Veeam B&R low-privilege MFA bypass | 8.8 | High |
| CVE-2023-27532 | Veeam B&R credential dump / auth bypass (Akira, Cuba, FIN7) | 7.5 | High |
Assessed for patch-level verification and controlled proof only — active exploitation is not performed in the production environment.
Mapped to frameworks auditors recognize.
Evidence your auditors can use.
Pressure-test your Veeam backups before an attacker does.
Complete the scope form or book a confidential scoping call. If ZeroPEN is not the right fit for your environment, we will say so — and point you to what is.
ZeroPEN questions, answered.
Is this safe to run against a production Veeam environment?
Yes. ZeroPEN never deletes real backups, performs real encryption, or stops production or backup services. Testing runs under agreed rules of engagement with proof-of-capability only, named stop conditions, and a direct comms channel with your team.
How is ZeroPEN different from a regular pentest?
Generic pentests scope networks and applications. ZeroPEN scopes Veeam — VBR, Veeam ONE, Enterprise Manager, repositories, immutability, and the full ransomware kill chain mapped to MITRE ATT&CK, including CVE patch-level verification for flaws actively exploited in the wild.
Do you actively exploit CVEs in production?
No. Critical Veeam CVEs (including CVE-2024-40711, CVE-2025-23120, and CVE-2023-27532) are assessed for patch-level verification and controlled proof-of-capability — active exploitation is not performed in the production environment.
What is included in a ZeroPEN engagement?
Scope and inventory, an approved test procedure, controlled kill-chain simulation, restore integrity and immutability verification, and an audit-ready report package — executive summary, technical findings, MITRE-mapped narrative, hardening scorecard, regulatory matrix, remediation plan, and re-test for critical findings.
What does the re-test cover?
After report delivery, BackupSec re-tests critical findings you remediated and updates the report with the new status — included in the engagement deliverables.
Let's talk backup
Talk to our team about backup security, Veeam backup monitoring, ransomware recovery validation, technical advisory, backup penetration testing, pricing, or a live demo of BackupSec.
Prefer to browse first? Read the FAQ