ZeroPEN · Veeam security test

Threat-led pentest for Veeam backup & recovery.

ZeroPEN tests your Veeam Backup & Replication environment using the real tactics of active ransomware operators — simulating the attack chain that neutralizes backups before production encryption. Zero compromise: find it before the attacker destroys your Veeam backups.

Production-safe

PoC only — no live exploit

Audit-ready

Full findings report

Re-test included

Critical findings

What is ZeroPEN?

Threat-led pentest for your last line of defense.

ZeroPEN is a threat-led penetration testing service that pressure-tests your most critical recovery layer — Veeam Backup & Replication — using the same tactics active ransomware operators use to neutralize backups before encrypting production. We simulate that attack chain in a controlled, non-destructive way and measure how resilient your Veeam infrastructure really is.

Service Threat-led penetration test and recovery proof for Veeam environments.
Focus Veeam Backup & Replication (VBR), Veeam ONE, and Enterprise Manager.
Approach Kill-chain simulation mapped to MITRE ATT&CK — proof-of-capability only, never destructive.
Regulatory scope ISO 27001 · NIST · GDPR · DORA · KVKK · BDDK · SPK.
  • Any organization running Veeam Backup & Replication
  • IT organizations pursuing or maintaining ISO 27001 certification
  • Organizations with GDPR / KVKK personal-data obligations
  • Financial entities operating in the EU market under DORA
  • Banks, participation banks, and financial institutions (BDDK / SPK scope)
Why Veeam

Attackers target Veeam first. So do we.

Veeam is the de facto standard for enterprise backup — and exactly for that reason it is the attacker’s number-one target. Flaws such as CVE-2023-27532 and CVE-2024-40711 have been actively used by groups including Akira, Fog, Cuba, and FIN7 to take over Veeam servers and delete backups. ZeroPEN simulates that chain in a controlled, non-destructive manner.

The attack chain we test

Kill-chain simulation mapped to MITRE ATT&CK.

Each stage reflects observed behavior of real threat actors in Veeam environments — from initial access through backup neutralization.

  1. Initial access

    T1566 · T1190

    Network access via VPN/RDP/phishing; internet-exposed VBR or Enterprise Manager ports.

  2. Discovery & inventory

    T1087 · T1018

    Mapping the Veeam server, proxies, repositories, and job topology.

  3. Credential abuse

    T1558.003

    Kerberoasting the Veeam service account; configuration database credential extraction.

  4. Veeam server takeover

    T1210

    CVE-2024-40711 / CVE-2025-23120 RCE paths, authentication bypass, and config DB access.

  5. Repository access

    T1021.002

    SMB/NFS repository access, immutability bypass attempts, and VBR job manipulation.

  6. Neutralizing backups

    T1490

    Disabling jobs, shortening retention, and testing restore-point deletion authority.

  7. Exfiltration simulation

    T1567.002

    Reading data from backups and controlled exfiltration — double-extortion simulation.

  8. Encryption capability proof

    T1486

    Controlled proof-of-capability only — no real encryption of production or backup data.

Safety commitment: ZeroPEN never deletes real backups, performs real encryption, or stops production or backup services. Destructive actions are limited to proof-of-capability and evidence collection.

Veeam test catalog

Every Veeam component, systematically tested.

VBR server Standalone/hardened posture, domain-joined risk, local admin isolation, RDP/WinRM exposure.
Configuration database MSSQL/PostgreSQL config DB access, job definitions, repository paths, stored credentials, privilege separation.
Credential vault DPAPI decryption, Veeam.Backup.DBConfig dumps, service-account password hygiene.
Authentication & API CVE-2023-27532 auth bypass (port 9401), REST/SOAP exposure, Enterprise Manager sessions, missing MFA.
Remote code execution Patch-level verification for CVE-2024-40711 and prior critical RCEs; deserialization vectors.
Backup repository SMB/CIFS & NFS access control, plaintext configs, production-network isolation.
Immutability Hardened Linux repo XFS flags, S3 Object Lock (compliance vs governance), bypass attempts.
Veeam ONE & Enterprise Manager Web interface exposure, privilege escalation, self-service restore portal security.
Job & retention Job disable, retention shortening, GFS chain break, backup-deletion authority.
Hypervisor integration vCenter/ESXi credential reuse, snapshot manipulation, proxy server trust.
Tape & cloud tier Tape catalog access, cloud tier (S3/Azure Blob) key management, protection of offloaded data.
Logging & detection Backup deletion/encryption alerting, SIEM integration, Veeam event log integrity.
Hardening verification

Veeam security best practices, verified.

Alongside the attack simulation, ZeroPEN verifies compliance with Veeam’s own hardening guide — and assesses critical CVE patch levels without active exploitation in production.

  • VBR server domain-isolated, standalone, and hardened
  • Hardened Linux Repository — XFS immutable (reflink) configuration
  • Immutable cloud/S3 backup via Object Lock (compliance mode)
  • Four-eyes authorization for backup deletion
  • MFA and RBAC separation for Veeam management accounts
  • Backup encryption (AES-256) and secure key storage
  • 3-2-1-1-0 backup rule and immutability period verification
  • Current Veeam patch level; known CVEs assessed at patch level only

Validated critical Veeam CVEs

CVETitleCVSSImpact
CVE-2025-23120Veeam B&R RCE by authenticated domain user (domain-joined)9.9Critical
CVE-2023-38547Veeam ONE information disclosure / RCE9.9Critical
CVE-2024-40711Veeam B&R unauthenticated RCE (CISA KEV, ransomware-exploited)9.8Critical
CVE-2024-29849Veeam Enterprise Manager auth bypass9.8Critical
CVE-2024-40710Veeam B&R RCE as service account / credential extraction8.8High
CVE-2024-40713Veeam B&R low-privilege MFA bypass8.8High
CVE-2023-27532Veeam B&R credential dump / auth bypass (Akira, Cuba, FIN7)7.5High

Assessed for patch-level verification and controlled proof only — active exploitation is not performed in the production environment.

Methodology & standards

Mapped to frameworks auditors recognize.

PTES End-to-end pentest lifecycle — from pre-engagement to reporting.
MITRE ATT&CK Every finding mapped to a technique — including T1490 Inhibit System Recovery.
NIST SP 800-115 Technical testing standard referenced in BDDK/SPK audits.
TIBER-EU / TLPT Threat-intelligence-led testing — DORA Art. 26–27 alignment.
Veeam best practices Compliance verification against Veeam’s official security hardening guide.
Deliverables & process

Evidence your auditors can use.

Deliverables Executive summary · technical findings report (CWE/CVE mapped, CVSS scored) · kill-chain narrative with MITRE mapping · Veeam hardening scorecard · regulatory mapping matrix (ISO/GDPR/DORA/KVKK/BDDK/SPK) · prioritized remediation plan · re-test for critical findings.
Regulatory coverage ISO 27001 / NIST SP 800-34 · GDPR Art. 32 · DORA Art. 11–12 & 17 TLPT · KVKK Art. 12 · BDDK (Art. 45 backup, Art. 51 security test, Art. 17 DR) · SPK III-35.1.
Engagement process 1. Scope & inventory · 2. Test procedure approval · 3. Controlled kill-chain simulation · 4. Restore integrity & immutability verification · 5. Audit-ready report package.
Next step Complete the Scope & Responsibility Form and BackupSec delivers a tailored test procedure shortly thereafter. Get started.
Get started

Pressure-test your Veeam backups before an attacker does.

Complete the scope form or book a confidential scoping call. If ZeroPEN is not the right fit for your environment, we will say so — and point you to what is.

FAQ

ZeroPEN questions, answered.

Is this safe to run against a production Veeam environment?

Yes. ZeroPEN never deletes real backups, performs real encryption, or stops production or backup services. Testing runs under agreed rules of engagement with proof-of-capability only, named stop conditions, and a direct comms channel with your team.

How is ZeroPEN different from a regular pentest?

Generic pentests scope networks and applications. ZeroPEN scopes Veeam — VBR, Veeam ONE, Enterprise Manager, repositories, immutability, and the full ransomware kill chain mapped to MITRE ATT&CK, including CVE patch-level verification for flaws actively exploited in the wild.

Do you actively exploit CVEs in production?

No. Critical Veeam CVEs (including CVE-2024-40711, CVE-2025-23120, and CVE-2023-27532) are assessed for patch-level verification and controlled proof-of-capability — active exploitation is not performed in the production environment.

What is included in a ZeroPEN engagement?

Scope and inventory, an approved test procedure, controlled kill-chain simulation, restore integrity and immutability verification, and an audit-ready report package — executive summary, technical findings, MITRE-mapped narrative, hardening scorecard, regulatory matrix, remediation plan, and re-test for critical findings.

What does the re-test cover?

After report delivery, BackupSec re-tests critical findings you remediated and updates the report with the new status — included in the engagement deliverables.

Contact

Let's talk backup

Talk to our team about backup security, Veeam backup monitoring, ransomware recovery validation, technical advisory, backup penetration testing, pricing, or a live demo of BackupSec.

Prefer to browse first? Read the FAQ