Druva today announced expanded Identity Resilience tools alongside Ransomware Detection. This new feature relies on an AI threat pipeline. Powered by Dru MetaGraph, these capabilities bring behavioral intelligence directly to Cyber Recovery. Consequently, security teams turn suspicious signals into clear evidence. The platform confirms impact and speeds up precise incident containment.
Artificial intelligence makes distinguishing compromise from normal enterprise activity difficult. Attackers use automated tools to test pathways faster. Modern bad actors hide malicious actions inside everyday traffic. Meanwhile, stolen credentials reduce confidence in legacy alerts. Therefore, modern enterprises need reliable Cyber Recovery to validate backup telemetry safely.
“Security teams know they can’t stop every attack. The challenge is knowing exactly what happens when a threat breaks through,” said Yogesh Badwe, Chief Security Officer at Druva. “AI makes that uncertainty more dangerous. Before you recover, you need evidence of what changed, how far the compromise spread, and what can still be trusted. Druva has years of backup telemetry we use to validate threat signals and turn them into evidence, giving customers a trusted basis for recovery instead of an assumption.”
Reconstructing Identity Paths for Rapid Investigations
New capabilities bring connected graph intelligence directly to IT teams. The interactive interface maps human and non-human identities. Furthermore, it links Microsoft Entra ID, Active Directory, and Okta. Dru MetaGraph evaluates historical permission changes across systems. As a result, analysts shrink investigation timelines from days to hours.
The platform maps lateral movement to MITRE ATT&CK frameworks. Security personnel pinpoint pre-attack states using historical snapshots. Next, Druva generates tailored plans for effective Cyber Recovery. This guided process isolates infected objects while preserving safe restore points.
“Finding suspicious activity is only the beginning. Security teams still have to determine the legitimacy of the threat and how it may impact the business, as well as knowing what can be safely recovered,” said Jennifer Glenn, Research Director for Information and Data Security at IDC. “AI is driving greater attack volume and complexity, making it difficult to answer those questions quickly and confidently. Evidence-based cyber recovery gives organizations a clearer path to get from threat signals to trusted recovery.”
Ransomware Detection Confirms Real Threat Impact
The launch also features dedicated Ransomware Detection mechanisms. A proprietary pipeline evaluates both known and novel threats. Traditional anomaly tools create excess noise for security teams. However, Druva uses forensic validation to filter out false positives.
File name changes, ransom messages, and unusual changes in extensions can be detected by the platform. Machine learning models analyze all the backups in their entirety. Furthermore, multi-step forensic validation checks file entropy and MIME types. Actionable results can be found in Recovery Insights within Cyber Recovery processes.
Corrupted data is easily differentiated from healthy data that is not affected by malware. Automated processes ensure security before any restoration takes place. As a result, enterprises optimize Cyber Recovery without restoring any malicious content.
To explore how Security Operations Centers (SOC) play a crucial role in defending against modern cyber threats, read our latest SOC News.
News Source: Businesswire