Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Automated Threat Hunting in Cohesity Alta View

Cohesity
03/26/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hello everyone, my name is Shelley Calhoun-Jones and I'm a Technical Marketing Director at Cohesity. Today, I'm excited to introduce enhancements to Threat Hunting in Cohesity Alta View. This feature automates threat hunting in backups and enhances cyber recovery by preventing malware reinfection during restoration. In this video, we'll examine a security event and demonstrate how to use this feature to understand the impact of an attack. We'll also explore a new automated capability that enables you to search daily feeds for malicious file hashes published by reputable third parties such as CISA and Malware Bazaar. Let's get started. The Cyber Resiliency Dashboard provides an overview of your Cohesity Alta environment. It allows you to monitor the risk score of your data centers or a specific data center. A higher risk score could indicate the presence of a security threat. In the event of an active threat, you can quickly identify high-risk locations to expedite your investigation. You can also view misconfigurations and recent changes corresponding to the event's timeline. The dashboard lets you correlate suspicious activities and assess whether malware is spreading across systems. You can also categorize assets by risk severity, helping you prioritize responses for those classified as high-risk. By correlating these various data points, you can effectively track the progression of a security event, evaluate the impact, and respond swiftly. Let's take a look at an example from the Malware Impact Analysis section. Malware Impact Analysis provides a visual representation of data centers, primary servers, and assets, highlighting the impact of malware on them. This information is critical because once ransomware infiltrates an infrastructure, it spreads rapidly and intentionally expands the attack's reach. This feature allows you to identify the affected assets and minimize the overall impact. In this example, an infected server is represented by a red bubble. A connected web displays all of the machines involved, which can help your security team reduce the blast radius. On this screen, we can see details about the asset, including the how, when, and where backups were taken. The policy represents the workload that is being backed up. For example, you may want to have a specific policy for your Active Directory servers or a database workload. Cohesity NetBackup can also detect data anomalies during an asset's backup and send this information to Cohesity AltiveView. For instance, events related to encryption may indicate ransomware activity on a system. We can adjust the time range to identify when the event was first detected. You can also add protection and choose the users you want to allow to manage the asset. You'll also notice a recovery points tab, but you may still be gathering evidence if you're dealing with an active security event. Let's return to the Cyber Resiliency Dashboard and examine some other ways to use Cohesity AltiveView for threat hunting. The Malware Detection section can be used for tracking infected hosts and file hashes. File hashes can detect malware and custom files in backup images. They serve as unique digital fingerprints for files and you can compare them to malware hashes from threat intelligence feeds to determine if a threat is in the environment. You can also use them to understand how the threat is spreading and isolate infected systems. From this screen, we can search for a specific file hash or upload a CSV file from my system. We talked earlier about how custom hashes could be used when dealing with an active threat event, but they can also help from a compliance perspective. Custom hash uploads create an audit trail, proving due diligence in incident handling. You can use this information to tighten your security policies. Here's an example of what to include when uploading a CSV file. Also note that you have the ability to search for a specific hash using the search option. You can also enable daily searches of file hashes using CISA, open source feeds like Malware Bazaar, and uploaded hashes. If a malicious file is found in your backup images, the associated assets or clients are marked as malicious. Another new feature for threat hunting is Anomaly Detection. We took a look at this feature when describing Blast Radius, and it uses real-time entropy detection to identify ransomware. This feature leverages AI and machine learning capabilities to assess the randomness or unpredictability of data within a file. Real-time entropy detection works alongside file hash detection by identifying new and unknown ransomware variants based on their behavior. While hash detection focuses on blocking known threats. Together these features provide proactive and reactive defense, ensuring early detection of anomalies and rapid containment, even when confronted with new threats. One advantage is that when an anomaly is detected, it triggers a malware scan. If malware is found, the IOC is submitted into Cohesity Altiview to execute a search across the enterprise and limit the blast radius. The scan provides indicators of compromise related to file-based hash scanning. IOCs are pieces of evidence that indicate malicious activity. For example, a ransomware note in a readme.txt file that demands payment in Bitcoin serves as an IOC. You can use this information when addressing an active security incident or documenting what occurred during the lessons learned phase. This completes the demonstration. We explored recent enhancements to threat hunting in Cohesity Altiview. This feature automates threat hunting in backups and improves cyber recovery by preventing malware reinfection during restoration. Thanks for watching.

TL;DR

  • Cohesity Alta View automates threat hunting in backups using hash-based detection integrated with CISA and Malware Bazaar feeds, plus AI-powered entropy analysis to identify unknown ransomware variants
  • The Cyber Resiliency Dashboard provides risk scoring and malware impact visualization showing infected servers and connected systems to help security teams reduce blast radius during active attacks
  • Real-time entropy detection triggers automatic malware scans when anomalies are found, submitting indicators of compromise across the enterprise to prevent reinfection during restoration
  • Custom file hash uploads enable tracking of organization-specific threats while creating compliance audit trails for incident handling and security policy refinement

Automated Threat Detection in Backup Images

Cohesity Alta View introduces enhanced threat hunting capabilities that automate malware detection within backup images using hash-based detection and real-time entropy analysis. The platform integrates daily threat intelligence feeds from CISA and Malware Bazaar to identify known malicious file hashes, while AI-powered entropy detection identifies unknown ransomware variants based on behavioral patterns. When anomalies are detected during backup operations, the system automatically triggers malware scans and submits indicators of compromise across the enterprise to limit blast radius. This dual-layer approach combines proactive detection of new threats with reactive blocking of known malware, preventing reinfection during restoration processes and strengthening cyber recovery posture.

Cyber Resiliency Dashboard and Impact Analysis

The Cyber Resiliency Dashboard provides centralized visibility into security threats across Cohesity Alta environments through risk scoring, misconfiguration tracking, and malware impact visualization. Security teams can monitor risk scores at data center or asset levels, with higher scores indicating potential security events requiring investigation. The Malware Impact Analysis feature displays infected servers and their connected systems in a visual web, enabling rapid identification of affected assets and containment of spreading ransomware. The platform correlates suspicious activities, data anomalies detected during backups, and encryption events to track security event progression. Custom file hash uploads create audit trails for compliance purposes, while the recovery points interface allows teams to identify clean backup snapshots for restoration after gathering forensic evidence.

Chapters

0:00 - Introduction to Threat Hunting Enhancements
0:47 - Cyber Resiliency Dashboard Overview
1:46 - Malware Impact Analysis and Blast Radius
3:26 - File Hash Detection and Custom Uploads
4:55 - Anomaly Detection and Entropy Analysis
5:58 - Indicators of Compromise and IOC Scanning

Key Quotes

0:18 "This feature automates threat hunting in backups and enhances cyber recovery by preventing malware reinfection during restoration."
0:39 "We'll also explore a new automated capability that enables you to search daily feeds for malicious file hashes published by reputable third parties such as CISA and Malware Bazaar."
2:01 "Once ransomware infiltrates an infrastructure, it spreads rapidly and intentionally expands the attack's reach."
5:27 "Together these features provide proactive and reactive defense, ensuring early detection of anomalies and rapid containment, even when confronted with new threats."
Categories:
  • » Webinar Library » Cohesity
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Security Operations
  • Threat Intelligence
  • Backup & Recovery
  • Technical Deep Dive
  • Demo
  • Threat Hunting
  • Malware Detection
  • Ransomware Protection
  • Cyber Recovery
  • Backup Security
  • Hash-Based Detection
  • Entropy Analysis
  • Threat Intelligence Integration
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Automated Threat Hunting in Cohesity Alta View

              Upcoming Webinar Calendar

              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                Preventing Your AI from Turning Against You: Essential Strategies
                https://www.truthinit.com/index.php/channel/2021/preventing-your-ai-from-turning-against-you-essential-strategies/
              • 07/02/2026
                10:00 AM
                07/02/2026
                Resilience Insights from Hybrid Threats Amidst Cloud Challenges
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-amidst-cloud-challenges/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Empowering Trust through Action and Agency
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-empowering-trust-through-action-and-agency/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Quality Security Team for Unmatched Defense
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-quality-security-team-for-unmatched-defense/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers During the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-during-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Insights and Strategies from the DPDP Webinar
                https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-from-the-dpdp-webinar/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 08/19/2026
                12:00 PM
                08/19/2026
                Witness Cyera Agent Security in Action: A Firsthand Experience
                https://www.truthinit.com/index.php/channel/2036/witness-cyera-agent-security-in-action-a-firsthand-experience/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                30

                Mastering Active Directory Certificate Services for Long-Term Success

                06/30/202601:00 PM ET
                • Jul
                  01

                  Integrating Security in AI: Automated Red Teaming Strategies for Private Models

                  07/01/202604:00 AM ET
                  • Jul
                    01

                    Schutz von KI in Anwendungen, Agenten und APIs.

                    07/01/202604:00 AM ET
                    • Jul
                      01

                      Preventing Your AI from Turning Against You: Essential Strategies

                      07/01/202601:00 PM ET
                      • Jul
                        02

                        Resilience Insights from Hybrid Threats Amidst Cloud Challenges

                        07/02/202610:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version