Dru MetaGraph and a proprietary AI threat pipeline analyze suspicious behavior, validate impact, and guide precise containment and clean recovery
SANTA CLARA, Calif., September 17, 2026–(BUSINESS WIRE)–Druva, the resilience foundation for the AI enterprise, today announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspicious behavior into actionable evidence, definitively confirm impact, and accelerate precise containment and clean recovery.
AI is making it harder for security teams to distinguish real compromise from normal behaviors and activity. Attackers are using AI to test more paths, shift tactics faster, and hide malicious behavior inside legitimate activity, while stolen credentials and constantly evolving ransomware make traditional signals less conclusive.
Druva gives customers evidence-based cyber recovery by unlocking behavioral intelligence from backup data. The new identity resilience capabilities use Dru MetaGraph to analyze suspicious identity behavior and visualize the blast radius, while the proprietary AI threat pipeline powering Ransomware Detection analyzes backup data to validate ransomware behavior. Together, they move teams from signals to evidence, accelerating investigation, confirming impact, and guiding precise containment and recovery back to clean, trustworthy states.
“Security teams know they can’t stop every attack. The challenge is knowing exactly what happens when a threat breaks through,” said Yogesh Badwe, Chief Security Officer at Druva. “AI makes that uncertainty more dangerous. Before you recover, you need evidence of what changed, how far the compromise spread, and what can still be trusted. Druva has years of backup telemetry we use to validate threat signals and turn them into evidence, giving customers a trusted basis for recovery instead of an assumption.”
Identity Resilience reconstructs attack paths for faster, trusted recovery
Building on the unified identity protection introduced earlier this year, new Druva Identity Resilience capabilities bring Dru MetaGraph’s connected intelligence directly to customers. This capability provides an interactive view of human and non-human identities (NHIs) activities and relationships across Microsoft Entra ID, Active Directory, and Okta.
Dru MetaGraph contextualizes change across identities, permissions, applications, policies, and time to show how suspicious activity propagated through an environment and cut investigation time from days to hours. With these new capabilities, customers can:
