Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Druva: Continuous Malware Scanning for Backups

Druva
06/27/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Ransomware is evolving, threats are becoming stealthier, and increasingly, attackers are targeting backup data. Knowing that if they can compromise your last line of defense, they can significantly increase pressure to pay. Most security tools like EDR, SIM, XDR, focus on production systems. But attackers often dwell undetected for weeks or even months, embedding dormant malware in systems which end up in your backup data. If you're not scanning those backups, you risk restoring infected data back into production and restarting the attack all over again. That's where Druva Threat Insights comes in. It transforms your immutable backups into a proactive threat detection layer, continuously scanning for dormant threats and delivering clean, verifiable recovery points. With two key capabilities, ThreatWatch and ThreatHunt, you gain early visibility, forensic context and a confident path to recovery. All of this is powered by Druva's dynamic Indicator of Compromise library, a continuously updated intelligence engine that combines industry-sourced threats from CISA and Google Mandiant, original research from Druva's own ReconX Labs which is focused on ransomware behavior in the wild, and customer-defined IOCs which can be uploaded directly via API or CSV. This curated, extensible library ensures you're always scanning backup data against the latest known threats, plus the ones most relevant to your environment. Let's explore ThreatWatch, Druva's zero-touch, continuous threat monitoring engine for backup data. ThreatWatch scans new backups every 8 hours and automatically re-scans the past 30 days of backups when new Indicators of Compromise are added. You don't need to install or maintain any infrastructure to run this. It's fully managed, agentless, and built for speed and scale, all in the Druva cloud. Drill into any alert and find out which IOCs cause the trigger, how many resources are impacted, and which objects are malicious. Infected snapshots can be manually or automatically quarantined. This ensures you're not just alerted, you're already protected. ThreatWatch effectively closes the gap between detection and response, helping teams avoid reinfection loops and meet audit or disclosure timelines with confidence. Now let's look at ThreatHunt. This is your on-demand investigation tool, designed for when new threat intel surfaces like a new hash or file extension. You can perform retroactive scans across the last 30 days of backup data to see exactly where threats may be hiding, across cloud, data center, or endpoint workloads. Find a match? One click to quarantine those snapshots, and you'll get visibility into which resources are impacted, when the threat first appeared, and which recovery points are clean and safe to use. This brings powerful forensic-level threat hunting directly into backups, without needing a separate toolchain or infrastructure overhead. Together, ThreatWatch and ThreatHunt form a powerful threat detection and response loop for backup data. You're not just scanning for malware, you're building a verifiable chain of trust from threat detection to clean recovery. Dormant threats are surfaced and quarantined before they spread, clean restore points are identified and validated, and forensic audit trails help satisfy NIST, DORA, SEC, and GDPR requirements. Combined with Druva's 24-7 managed data detection and response, and our always-on anomalous data behavior monitoring, ThreatInsights completes a full-spectrum defense, helping you spot attacks early, isolate threats fast, and recover with precision. Because in today's threat landscape, it's not enough to just have backups. You need to know they're clean, prove they're safe, and recover with certainty. That's where Druva comes in. Learn more at druva.com.

TL;DR

  • Druva Threat Insights continuously scans backup data for dormant malware that traditional security tools miss, preventing reinfection loops during recovery operations.
  • ThreatWatch provides automated, zero-touch monitoring that scans new backups every 8 hours and re-scans the past 30 days when new threat intelligence is added.
  • ThreatHunt enables on-demand retroactive investigations across backup data to identify where threats are hiding and which recovery points are clean and safe to use.

Summary

This demonstration introduces Druva Threat Insights, a proactive threat detection capability designed to address a critical security gap: dormant malware embedded in backup data. While traditional security tools like EDR, SIEM, and XDR focus on production systems, attackers often dwell undetected for weeks or months, allowing malware to infiltrate backup snapshots. If these infected backups are restored without detection, organizations risk restarting the attack cycle—a phenomenon known as a reinfection loop. Druva Threat Insights transforms immutable backups from passive storage into an active security layer through two core capabilities: ThreatWatch, which provides zero-touch continuous monitoring that scans backups every 8 hours, and ThreatHunt, which enables on-demand retroactive forensic investigations across the entire backup footprint. Both capabilities are powered by Druva's dynamic Indicator of Compromise (IOC) library, which aggregates threat intelligence from CISA, Google Mandiant, Druva's own ReconX Labs research, and customer-defined IOCs. The solution automatically quarantines infected snapshots and identifies clean restore points, helping organizations meet compliance requirements from NIST, DORA, SEC, and GDPR while ensuring confident, verifiable recovery from cyber incidents.

Chapters

0:00 - The Backup Security Gap
0:36 - Introducing Druva Threat Insights
1:24 - ThreatWatch: Continuous Monitoring
2:09 - ThreatHunt: On-Demand Investigation

Key Quotes

0:22 "But attackers often dwell undetected for weeks or even months, embedding dormant malware in systems which end up in your backup data."
0:38 "It transforms your immutable backups into a proactive threat detection layer, continuously scanning for dormant threats and delivering clean, verifiable recovery points."
1:30 "ThreatWatch scans new backups every 8 hours and automatically re-scans the past 30 days of backups when new Indicators of Compromise are added."

FAQ

How does Druva Threat Insights prevent reinfection loops during recovery?

Threat Insights continuously scans backup snapshots for dormant malware using an updated IOC library, automatically quarantines infected snapshots, and identifies clean restore points. This ensures that when you recover from backups, you're restoring verified clean data rather than reintroducing malware back into production systems.

What's the difference between ThreatWatch and ThreatHunt?

ThreatWatch is a zero-touch, continuous monitoring engine that automatically scans new backups every 8 hours and re-scans the past 30 days when new threats are identified. ThreatHunt is an on-demand investigation tool that allows you to perform retroactive scans across the last 30 days of backup data when new threat intelligence surfaces, such as a new hash or file extension.


Categories:
  • » Webinar Library » Druva
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Threat Intelligence
  • Backup & Recovery
  • Compliance & Governance
  • Demo
  • Backup Security
  • Malware Detection
  • Ransomware Protection
  • Forensic Investigation
  • Compliance Requirements
  • Data Recovery
  • Reinfection Prevention
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Druva: Continuous Malware Scanning for Backups

              Upcoming Webinar Calendar

              • 06/30/2026
                01:00 PM
                06/30/2026
                Master Active Directory Certificate Services and Maintain Your Edge
                https://www.truthinit.com/index.php/channel/2018/master-active-directory-certificate-services-and-maintain-your-edge/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Outsmarting You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-outsmarting-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                Resilience Insights from Hybrid Threats in a Dark Cloud Environment
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-in-a-dark-cloud-environment/
              • 07/08/2026
                02:00 PM
                07/08/2026
                Understanding the Crucial Role of Context in AI Data
                https://www.truthinit.com/index.php/channel/2037/understanding-the-crucial-role-of-context-in-ai-data/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Empowering Agentic Trust in Practice
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-empowering-agentic-trust-in-practice/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Worthy Security Team for Maximum Defense Effectiveness
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-worthy-security-team-for-maximum-defense-effectiveness/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers During the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-during-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Insights and Strategies from the DPDP Webinar
                https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-from-the-dpdp-webinar/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 08/19/2026
                12:00 PM
                08/19/2026
                Get Prepared to Thrive as an Agent in Just 30 Days
                https://www.truthinit.com/index.php/channel/2036/get-prepared-to-thrive-as-an-agent-in-just-30-days/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                30

                Master Active Directory Certificate Services and Maintain Your Edge

                06/30/202601:00 PM ET
                • Jul
                  01

                  Schutz von KI in Anwendungen, Agenten und APIs.

                  07/01/202604:00 AM ET
                  • Jul
                    01

                    Integrating Security in AI: Automated Red Teaming Strategies for Private Models

                    07/01/202604:00 AM ET
                    • Jul
                      01

                      How to Prevent Your AI from Outsmarting You

                      07/01/202601:00 PM ET
                      • Jul
                        02

                        Resilience Insights from Hybrid Threats in a Dark Cloud Environment

                        07/02/202610:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version