Back Morningstar Druva Brings Behavioral Intelligence to Cyber Recovery with New Identity and Ransomware ...
Druva Brings Behavioral Intelligence to Cyber Recovery with New Identity and Ransomware Detection Capabilities
Dru MetaGraph and a proprietary AI threat pipeline analyze suspicious behavior, validate impact, and guide precise containment and clean recovery
Druva , the resilience foundation for the AI enterprise, today announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspicious behavior into actionable evidence, definitively confirm impact, and accelerate precise containment and clean recovery.
AI is making it harder for security teams to distinguish real compromise from normal behaviors and activity. Attackers are using AI to test more paths, shift tactics faster, and hide malicious behavior inside legitimate activity, while stolen credentials and constantly evolving ransomware make traditional signals less conclusive.
Druva gives customers evidence-based cyber recovery by unlocking behavioral intelligence from backup data. The new identity resilience capabilities use Dru MetaGraph to analyze suspicious identity behavior and visualize the blast radius, while the proprietary AI threat pipeline powering Ransomware Detection analyzes backup data to validate ransomware behavior. Together, they move teams from signals to evidence, accelerating investigation, confirming impact, and guiding precise containment and recovery back to clean, trustworthy states.
“Security teams know they can’t stop every attack. The challenge is knowing exactly what happens when a threat breaks through,” said Yogesh Badwe, Chief Security Officer at Druva. “AI makes that uncertainty more dangerous. Before you recover, you need evidence of what changed, how far the compromise spread, and what can still be trusted. Druva has years of backup telemetry we use to validate threat signals and turn them into evidence, giving customers a trusted basis for recovery instead of an assumption.”
Identity Resilience reconstructs attack paths for faster, trusted recovery
Building on the unified identity protection introduced earlier this year, new Druva Identity Resilience capabilities bring Dru MetaGraph’s connected intelligence directly to customers. This capability provides an interactive view of human and non-human identities (NHIs) activities and relationships across Microsoft Entra ID, Active Directory, and Okta.
Dru MetaGraph contextualizes change across identities, permissions, applications, policies, and time to show how suspicious activity propagated through an environment and cut investigation time from days to hours. With these new capabilities, customers can:
Understand attacker behavior and blast radius: See where an attacker gained access, escalated privileges, established persistence, or moved laterally through the environment, with mapping to the relevant MITRE ATT&CK TTPs.
Establish a trusted pre-attack state: Use historical changes and snapshots to identify the environment before compromise and determine what needs to be restored.
Turn behavioral evidence into precise containment and recovery: Generate a tailored, pre-validated recovery plan that identifies each impacted object, recommends the action to take, and pinpoints the clean snapshot to restore.
"Finding suspicious activity is only the beginning. Security teams still have to determine the legitimacy of the threat and how it may impact the business, as well as knowing what can be safely recovered,” said Jennifer Glenn, Research Director for Information and Data Security at IDC. “AI is driving greater attack volume and complexity, making it difficult to answer those questions quickly and confidently. Evidence-based cyber recovery gives organizations a clearer path to get from threat signals to trusted recovery."
Druva Ransomware Detection confirms ransomware impact for evidence-based recovery
The announcement also marks the launch of Ransomware Detection, powered by a proprietary AI threat pipeline that detects known and unknown ransomware behavior, confirms impact through built-in validation, and pinpoints clean recovery points.
Traditional anomaly detection can flag unusual file activity but leaves teams sorting through noise to determine what is truly malicious. Ransomware Detection replaces that guesswork with multi-stage behavioral analysis and forensic validation that filters out false signals and delivers confirmed evidence teams can act on. With these new capabilities, customers can:
Identify ransomware behavior across snapshots: Evaluate data against high-risk patterns such as ransom notes, suspicious & known extensions, mass file renaming, and other indicators across backup snapshots using purpose-built AI and machine learning models.
Validate high-risk findings : Confirm the presence of ransomware and reduce false positives by applying in-platform forensics, such as structural verification, entropy, Multipurpose Internet Mail Extensions (MIME) type analysis, file integrity, and data analysis.
Turn evidence into recovery action: Surface explainable findings in Recovery Insights, distinguish impacted data from clean snapshots, and validate recovery points before restore.
Ransomware Detection is in limited availability. New Druva Identity Resilience capabilities will be generally available month.
Explore how Druva Cyber Resilience helps organizations detect threats, validate risk, and accelerate clean recovery.
See how Druva Identity Resilience brings identity-aware intelligence to investigation and recovery.
Learn how Ransomware Detection confirms ransomware impact and enables fast, evidence-based recovery.
Druva is the resilience foundation for the AI enterprise, helping organizations secure and recover from connected risk across data, cyber, identity, and AI. The Resilience Cloud is a fully managed, cloud-native SaaS platform that delivers air-gapped and immutable protection across cloud, SaaS, on-premises, endpoint, and edge environments. Powered by Dru MetaGraph, Druva’s graph-powered intelligence layer, the platform connects critical business context so customers can understand risk, respond faster, recover cleanly, and govern data with greater confidence.
Alex Cardenas Director of Corporate Brand and Communications, Druva 1-888-821-0592 [email protected]
View source version on businesswire.com:
The articles, information, and content displayed on this webpage may include materials prepared and provided by third parties. Such third-party content is offered for informational purposes only and is not endorsed, reviewed, or verified by Morningstar.
Morningstar makes no representations or warranties regarding the accuracy, completeness, timeliness, or reliability of any third-party content displayed on this site. The views and opinions expressed in third-party content are those of the respective authors and do not necessarily reflect the views of Morningstar, its affiliates, or employees.
Morningstar is not responsible for any errors, omissions, or delays in this content, nor for any actions taken in reliance thereon. Users are advised to exercise their own judgment and seek independent financial advice before making any decisions based on such content. The third-party providers of this content are not affiliated with Morningstar, and their inclusion on this site does not imply any form of partnership, agency, or endorsement.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
