Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Threat Protection & Clean Data Recovery with Cohesity

Cohesity
03/20/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Let's start with a simple truth, cyberattacks are moving faster than ever. To that point, dwell time has been reduced to as little as one hour. Think about that, one hour. Meanwhile, organizations are taking days or even weeks to detect and respond to those attacks. Today, we're going to talk about how you can get clean data and confident recovery using Cohesity's threat protection capabilities. My name is Chris Hoff, Senior Product Marketing Manager here at Cohesity. And I'm Teresa Miller, Senior Director of Technical Marketing. Now, before we dive into our topic today, I have a question I want you to think about as Chris and I walk through everything here today. Why would you do threat hunting, threat scanning against your backup data instead of solely relying on your primary detection mechanisms? So from an enterprise challenge perspective, what our customers are telling us is that there are several considerations that factor into you making this decision. The first is defense evasion. Malware has one simple goal. It doesn't want to be detected, it's going to evade being found, which directly correlates to the next point of rapidly changing malware. Malware is going to evolve and change before your detection systems even stand a chance at detecting it. The third challenge I want to talk about is isolated network. So when you are being attacked and a cyber incident has unleashed on your environment, you're going to need to isolate either a small part, depending on what was impacted, or possibly the whole network. When you do that, you're likely going to be using forensics to discover what happened, but also there's a chance that you're going to be using that data as a recovery point. So you need clean data. We're going to unpack that a little bit more here in a little bit. And then the last challenge is hidden threats. So it is, just to reinforce, it's the ultimate goal of the malware or the attacker to not be detected. When we think about what Chris said earlier, dwell time could be as little as an hour, but it could actually be that those attackers are sitting in your network for months, and then your backup data has been impacted, and you can't get back to a clean state without having done some level of work to clean that data. So with Cohesity and the Cohesity Data Cloud, let's talk about pre-attack. In its most simplest form, what we can do from a prevention perspective against that backup data is we can do malware scanning, anomaly detection, as well as threat hunting based on indicators of compromise and hashes. Now let me turn this over to Chris, who's going to talk about post-attack. When a cyber attack happens, time isn't on your side. We need to make sure that we have the peace of mind that we're recovering clean data the first time. We can do that in multiple different ways. We can do either malware and anomaly detection based scanning, which allows us to find and pinpoint the threats within the data and remove them before they get put back into production. Now whether you're doing it pre-attack as part of a proactive threat hunting program or post-attack as part of your incident response process, we can operate in the same way in that we can create either full or incremental scans to find those threats faster. We create a hash of every file that we back up. And we can use that hash to compare it against known bad databases from leading vendors such as CISA or here at Cohesity Red Labs to determine whether or not a file is malicious. Taking it a step further, we can integrate with third-party threat feeds, the same feeds that you're using in your production data. As an example, we have an out-of-the-box integration with CrowdStrike Falcon's threat intelligence. The reason this is important to you is that we're enabling you to get early detection of your threats so that when you find out where the threats are, you can determine the scope or the blast radius of the attack, which allows you to have a better idea of what your response is going to look like. Using hashes and other threat intelligence feeds allows us to gain a better idea of the scope of an attack. The hash allows us to see how far a file might have spread and determine its propagation. Because hashes are a common form of telemetry, we can use them with our production tools such as our SIM or our EDR or our network threat intelligence tools to determine the larger scope of the threat. And this all leads to a better RTO because if we know where the threats are, we know when they started, we have an easier time of determining which snapshot that we can start recovery with. And that might be recovering directly into your production environment or it might be recovering into a clean room for further forensics. Either way, the net benefit of all of this is we're reducing your overall downtime so that you can keep your business up and running. So I want to go back to my earlier question that I asked all of you. So why would you scan or do threat hunting against your backup data? So I think we did a great summary of that today, but I also want to call out we're giving you global visibility into your data from an enterprise perspective that allows you to recover and be more resilient to attacks.

TL;DR

  • Cyberattack dwell time has decreased to as little as one hour, but organizations take days or weeks to detect threats, creating a critical need to scan backup data for hidden malware that evades primary detection systems.
  • Cohesity's threat protection creates hashes of every backed-up file and compares them against threat intelligence from CISA, Cohesity Red Labs, and third-party feeds like CrowdStrike Falcon to identify compromised data before recovery.
  • The platform enables both proactive threat hunting (pre-attack) and incident response scanning (post-attack) to determine the blast radius of attacks and identify clean recovery points, reducing RTO and preventing reinfection.
  • Hash-based telemetry provides common indicators that can be correlated with production security tools (SIEM, EDR, network intelligence) to understand the full scope of an attack across both backup and production environments.

The Urgency of Threat Detection in Backup Data

This presentation addresses a critical gap in cyber resilience strategy: the need to scan and hunt for threats within backup data, not just production environments. Chris Hoff and Teresa Miller explain that modern cyberattacks have reduced dwell time to as little as one hour, while organizations often take days or weeks to detect and respond. The core challenge is that malware is designed to evade detection, evolve rapidly, and can remain hidden in backup snapshots for months. When organizations need to recover from an attack, they must ensure they're restoring clean data rather than reintroducing compromised files. Cohesity's approach combines malware scanning, anomaly detection, and threat hunting capabilities that work against backup data both proactively (pre-attack) and reactively (post-attack), providing organizations with the confidence that their recovery points are free from threats.

Integration with Threat Intelligence and Recovery Workflows

The platform creates a hash of every backed-up file and compares these hashes against known malicious file databases from sources like CISA and Cohesity Red Labs. Beyond internal threat intelligence, Cohesity integrates with third-party feeds including an out-of-the-box connection to CrowdStrike Falcon's threat intelligence. This integration enables early threat detection and helps determine the blast radius of an attack by tracking file propagation across snapshots. The hash-based approach provides common telemetry that can be correlated with production security tools like SIEM, EDR, and network threat intelligence platforms. By identifying which snapshots contain threats and which are clean, organizations can make informed decisions about recovery points, whether restoring directly to production or into a clean room for forensics. This visibility into backup data integrity directly reduces recovery time objectives and overall business downtime.

Chapters

0:00 - Introduction: The Speed of Modern Cyberattacks
1:09 - Enterprise Challenges: Why Scan Backup Data
3:17 - Pre-Attack: Proactive Threat Hunting
3:48 - Post-Attack: Incident Response & Clean Recovery
5:31 - Reducing RTO Through Threat Intelligence

Key Quotes

0:13 "... dwell time has been reduced to as little as one hour ..."
2:56 "... dwell time could be as little as an hour, but it could actually be that those attackers are sitting in your network for months, and then your backup data has been impacted, and you can't get back to a clean state without having done some level of work to clean that data ..."
4:39 "We create a hash of every file that we back up. And we can use that hash to compare it against known bad databases from leading vendors such as CISA or here at Cohesity Red Labs to determine whether or not a file is malicious."
5:01 "... we have an out-of-the-box integration with CrowdStrike Falcon's threat intelligence ..."

Categories:
  • » Webinar Library » Cohesity
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Threat Intelligence
  • Backup & Recovery
  • Technical Deep Dive
  • Security Operations
  • Backup Data Threat Scanning
  • Cyber Resilience
  • Malware Detection
  • Threat Intelligence Integration
  • Clean Data Recovery
  • Incident Response
  • Hash-Based File Analysis
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Threat Protection & Clean Data Recovery with Cohesity

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Taking Control of You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-taking-control-of-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                Agentic Trust in Practice: Enhancing the Human Experience
                https://www.truthinit.com/index.php/channel/2026/agentic-trust-in-practice-enhancing-the-human-experience/
              • 07/14/2026
                11:00 AM
                07/14/2026
                Discover the Latest Innovations in Netwrix 1Secure During This Technical Session
                https://www.truthinit.com/index.php/channel/2014/discover-the-latest-innovations-in-netwrix-1secure-during-this-technical-session/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version