Druva reacts to AI ransomware raids with AI responses | #ransomware | #cybercrime


Druva is using AI-based responses to combat AI-fuelled ransomware raids.

The backup and data resilience vendor says attackers are using AI to test more paths, shift tactics faster, and hide malicious behavior inside legitimate activity, while stolen credentials and constantly evolving ransomware make traditional signals less conclusive. All in all, AI is making it harder for security teams to distinguish real compromise from normal behaviors and activity.

To combat this, Druva is using its Dru Metagraph technology to analyze suspicious identity behavior and visualize the blast radius. It combines this with its own AI threat pipeline, which analyzes backup data to validate potential ransomware behavior. This can confirm the impact and guide security staff and admins about the precise containment and recovery steps to get back to clean and trustworthy status. 


Yogesh Badwe

Yogesh Badwe, Chief Security Officer at Druva, said: “Security teams know they can’t stop every attack. The challenge is knowing exactly what happens when a threat breaks through. AI makes that uncertainty more dangerous. Before you recover, you need evidence of what changed, how far the compromise spread, and what can still be trusted. Druva has years of backup telemetry we use to validate threat signals and turn them into evidence, giving customers a trusted basis for recovery instead of an assumption.” 

Druva says traditional anomaly detection can flag unusual file activity but leaves admin teams sorting through multiple telemetry feeds and status reports to separate out actually malicious activities. Ransomware Detection’s AI-powered threat pipeline  replaces this with multi-stage behavioral analysis and forensic validation that filters out false signals and delivers confirmed evidence. With these new capabilities, Druva says, customers can: 

● Identify ransomware behavior across snapshots: Evaluate data against high-risk patterns such as ransom notes, suspicious and known extensions, mass file renaming, and other indicators across backup snapshots using purpose-built AI and machine learning models. 

● Validate high-risk findings: Confirm the presence of ransomware and reduce false positives by applying in-platform forensics, such as structural verification, entropy, Multi-purpose Internet Mail Extensions (MIME) type analysis, file integrity, and data analysis. 

● Turn evidence into recovery action: Surface explainable findings in Recovery Insights, distinguish impacted data from clean snapshots, and validate recovery points before restore.

The company says it’s also reconstructing attack paths to make recovery faster and more certain. Dru Metagraph provides an interactive view of human and non-human identities (NHIs, eg. AI agents), activities, and relationships across Microsoft Entra ID, Active Directory, and Okta. It contextualizes change across identities, permissions, applications, policies, and time to show how suspicious activity propagated through an environment and this can cut investigation time from days to hours. Druva says that with this attack context security admin staff can:

● Understand attacker behavior and blast radius to see where an attacker gained access, escalated privileges, established persistence, or moved laterally through the environment, with mapping to the relevant MITRE ATT&CK TTPs (see bootnote). 

● Establish a trusted pre-attack state: Use historical changes and snapshots to identify the environment before compromise and determine what needs to be restored. 

● Turn behavioral evidence into precise containment and recovery: Generate a tailored, pre-validated recovery plan that identifies each impacted object, recommends the action to take, and pinpoints the clean snapshot to restore. 

There’s more information here.

Bootnote

MITRE ATT&CK is a framework to describe attacker behavior maintained by the MITRE organization, a U.S. not-for-profit organization that works in the public interest as an independent technical adviser to government, known for operating federally funded research and development centers (FFRDCs) and for frameworks such as ATT&CK.

ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge, and is a publicly maintained knowledge base of real-world attacker behaviors. TTPs are Tactics, Techniques, and Procedures and describe how malware adversaries actually behave during their cyber operations.



Click Here For The Original Source.

——————————————————–

..........

.

.