Druva Ransomware Detection Targets False Positives | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Druva is expanding its cyber recovery portfolio with new ransomware detection and identity resilience capabilities designed to help security teams validate attacks faster, reduce false positives, and identify clean recovery points before restoring data.

The company’s new Ransomware Detection capability analyzes backup snapshots for high-risk ransomware behavior and then applies additional forensic validation to determine whether suspicious activity constitutes an actual compromise. Druva is also expanding its Identity Resilience capabilities to help teams reconstruct identity-based attacks, assess blast radius, and determine what can still be trusted after a breach.

Druva expands identity attack investigation and recovery

The new Identity Resilience capabilities build on the unified identity protection Druva introduced earlier this year and use Dru MetaGraph, the company’s graph-powered intelligence layer.

According to Druva, the capabilities are designed to address a threat environment in which attackers use AI to test more attack paths and conceal malicious behavior within legitimate activity. The company said stolen credentials and evolving ransomware techniques are also making traditional threat signals less conclusive.

“Security teams know they can’t stop every attack. The challenge is knowing exactly what happens when a threat breaks through,” said Yogesh Badwe, chief security officer at Druva. 

“AI makes that uncertainty more dangerous. Before you recover, you need evidence of what changed, how far the compromise spread, and what can still be trusted.”

Dru MetaGraph provides an interactive view of activity and relationships across human and non-human identities in Microsoft Entra ID, Active Directory, and Okta. It contextualizes changes across identities, permissions, applications, policies, and time to reconstruct how suspicious activity moved through an environment.

According to Druva, the new capabilities allow security teams to:

  • Understand attacker behavior and blast radius: Identify where an attacker gained access, escalated privileges, established persistence, or moved laterally through an environment, with activity mapped to relevant MITRE ATT&CK tactics, techniques, and procedures (TTPs).
  • Establish a pre-attack state: Use historical changes and snapshots to identify the state of an environment before compromise and determine what needs to be restored.
  • Guide containment and recovery: Generate a tailored, pre-validated recovery plan that identifies impacted objects, recommends actions, and pinpoints the clean snapshots to restore.

Druva said the additional context can reduce identity investigation time from days to hours.

Ransomware Detection adds forensic threat validation

Druva also launched Ransomware Detection, a new capability powered by what the company describes as a proprietary AI threat pipeline.

The feature analyzes backup snapshots for ransomware behavior and applies additional forensic validation to determine whether suspicious activity represents an actual compromise.

According to Druva, Ransomware Detection can:

  • Identify ransomware behavior across snapshots: Evaluate backup data for high-risk patterns including ransom notes, suspicious and known extensions, mass file renaming, and other indicators using purpose-built AI and machine learning models.
  • Validate high-risk findings: Apply in-platform forensics including structural verification, entropy analysis, Multipurpose Internet Mail Extensions (MIME) type analysis, file integrity checks, and data analysis to confirm ransomware activity and reduce false positives.
  • Connect findings to recovery: Surface findings through Recovery Insights, distinguish impacted data from clean snapshots, and validate recovery points before restoration.

“Finding suspicious activity is only the beginning. Security teams still have to determine the legitimacy of the threat and how it may impact the business, as well as knowing what can be safely recovered,” said Jennifer Glenn, research director for information and data security at IDC. 

“AI is driving greater attack volume and complexity, making it difficult to answer those questions quickly and confidently.”

Ransomware Detection is currently in limited availability. Druva said its new Identity Resilience capabilities will become generally available next month.

For a closer look at MSP technology options, visit our guide to the best MSP software for 2026 for comparisons across RMM, PSA, ITSM, security, help desk, and automation tools. 

——————————————————–


Click Here For The Original Source.

.........................