Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Druva: Continuous Malware Scanning for Backups

Druva
06/27/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Ransomware is evolving, threats are becoming stealthier, and increasingly, attackers are targeting backup data. Knowing that if they can compromise your last line of defense, they can significantly increase pressure to pay. Most security tools like EDR, SIM, XDR, focus on production systems. But attackers often dwell undetected for weeks or even months, embedding dormant malware in systems which end up in your backup data. If you're not scanning those backups, you risk restoring infected data back into production and restarting the attack all over again. That's where Druva Threat Insights comes in. It transforms your immutable backups into a proactive threat detection layer, continuously scanning for dormant threats and delivering clean, verifiable recovery points. With two key capabilities, ThreatWatch and ThreatHunt, you gain early visibility, forensic context and a confident path to recovery. All of this is powered by Druva's dynamic Indicator of Compromise library, a continuously updated intelligence engine that combines industry-sourced threats from CISA and Google Mandiant, original research from Druva's own ReconX Labs which is focused on ransomware behavior in the wild, and customer-defined IOCs which can be uploaded directly via API or CSV. This curated, extensible library ensures you're always scanning backup data against the latest known threats, plus the ones most relevant to your environment. Let's explore ThreatWatch, Druva's zero-touch, continuous threat monitoring engine for backup data. ThreatWatch scans new backups every 8 hours and automatically re-scans the past 30 days of backups when new Indicators of Compromise are added. You don't need to install or maintain any infrastructure to run this. It's fully managed, agentless, and built for speed and scale, all in the Druva cloud. Drill into any alert and find out which IOCs cause the trigger, how many resources are impacted, and which objects are malicious. Infected snapshots can be manually or automatically quarantined. This ensures you're not just alerted, you're already protected. ThreatWatch effectively closes the gap between detection and response, helping teams avoid reinfection loops and meet audit or disclosure timelines with confidence. Now let's look at ThreatHunt. This is your on-demand investigation tool, designed for when new threat intel surfaces like a new hash or file extension. You can perform retroactive scans across the last 30 days of backup data to see exactly where threats may be hiding, across cloud, data center, or endpoint workloads. Find a match? One click to quarantine those snapshots, and you'll get visibility into which resources are impacted, when the threat first appeared, and which recovery points are clean and safe to use. This brings powerful forensic-level threat hunting directly into backups, without needing a separate toolchain or infrastructure overhead. Together, ThreatWatch and ThreatHunt form a powerful threat detection and response loop for backup data. You're not just scanning for malware, you're building a verifiable chain of trust from threat detection to clean recovery. Dormant threats are surfaced and quarantined before they spread, clean restore points are identified and validated, and forensic audit trails help satisfy NIST, DORA, SEC, and GDPR requirements. Combined with Druva's 24-7 managed data detection and response, and our always-on anomalous data behavior monitoring, ThreatInsights completes a full-spectrum defense, helping you spot attacks early, isolate threats fast, and recover with precision. Because in today's threat landscape, it's not enough to just have backups. You need to know they're clean, prove they're safe, and recover with certainty. That's where Druva comes in. Learn more at druva.com.

TL;DR

  • Druva Threat Insights continuously scans backup data for dormant malware that traditional security tools miss, preventing reinfection loops during recovery operations.
  • ThreatWatch provides automated, zero-touch monitoring that scans new backups every 8 hours and re-scans the past 30 days when new threat intelligence is added.
  • ThreatHunt enables on-demand retroactive investigations across backup data to identify where threats are hiding and which recovery points are clean and safe to use.

Summary

This demonstration introduces Druva Threat Insights, a proactive threat detection capability designed to address a critical security gap: dormant malware embedded in backup data. While traditional security tools like EDR, SIEM, and XDR focus on production systems, attackers often dwell undetected for weeks or months, allowing malware to infiltrate backup snapshots. If these infected backups are restored without detection, organizations risk restarting the attack cycle—a phenomenon known as a reinfection loop. Druva Threat Insights transforms immutable backups from passive storage into an active security layer through two core capabilities: ThreatWatch, which provides zero-touch continuous monitoring that scans backups every 8 hours, and ThreatHunt, which enables on-demand retroactive forensic investigations across the entire backup footprint. Both capabilities are powered by Druva's dynamic Indicator of Compromise (IOC) library, which aggregates threat intelligence from CISA, Google Mandiant, Druva's own ReconX Labs research, and customer-defined IOCs. The solution automatically quarantines infected snapshots and identifies clean restore points, helping organizations meet compliance requirements from NIST, DORA, SEC, and GDPR while ensuring confident, verifiable recovery from cyber incidents.

Chapters

0:00 - The Backup Security Gap
0:36 - Introducing Druva Threat Insights
1:24 - ThreatWatch: Continuous Monitoring
2:09 - ThreatHunt: On-Demand Investigation

Key Quotes

0:22 "But attackers often dwell undetected for weeks or even months, embedding dormant malware in systems which end up in your backup data."
0:38 "It transforms your immutable backups into a proactive threat detection layer, continuously scanning for dormant threats and delivering clean, verifiable recovery points."
1:30 "ThreatWatch scans new backups every 8 hours and automatically re-scans the past 30 days of backups when new Indicators of Compromise are added."

FAQ

How does Druva Threat Insights prevent reinfection loops during recovery?

Threat Insights continuously scans backup snapshots for dormant malware using an updated IOC library, automatically quarantines infected snapshots, and identifies clean restore points. This ensures that when you recover from backups, you're restoring verified clean data rather than reintroducing malware back into production systems.

What's the difference between ThreatWatch and ThreatHunt?

ThreatWatch is a zero-touch, continuous monitoring engine that automatically scans new backups every 8 hours and re-scans the past 30 days when new threats are identified. ThreatHunt is an on-demand investigation tool that allows you to perform retroactive scans across the last 30 days of backup data when new threat intelligence surfaces, such as a new hash or file extension.


Categories:
  • » Webinar Library » Druva
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Threat Intelligence
  • Backup & Recovery
  • Compliance & Governance
  • Demo
  • Backup Security
  • Malware Detection
  • Ransomware Protection
  • Forensic Investigation
  • Compliance Requirements
  • Data Recovery
  • Reinfection Prevention
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Druva: Continuous Malware Scanning for Backups

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    13

                    Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada

                    08/13/202612:00 PM ET
                    • Aug
                      27

                      Unveiling the FunFoneFarm: A Dive into the Off-the-Shelf Scam Empire

                      08/27/202601:00 PM ET
                      More events

                      Upcoming Webinar Calendar

                      • 08/13/2026
                        12:00 PM
                        08/13/2026
                        Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                        https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                      • 08/27/2026
                        01:00 PM
                        08/27/2026
                        Becoming Agent Ready with Cyera: Essential Strategies and Insights
                        https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                      • 08/27/2026
                        01:00 PM
                        08/27/2026
                        Unveiling the FunFoneFarm: A Dive into the Off-the-Shelf Scam Empire
                        https://www.truthinit.com/index.php/channel/2086/unveiling-the-funfonefarm-a-dive-into-the-off-the-shelf-scam-empire/
                      • 09/02/2026
                        12:00 PM
                        09/02/2026
                        Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                        https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                      • 09/03/2026
                        01:00 PM
                        09/03/2026
                        Verge.io: Can You Afford Your Next Storage Refresh?
                        https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                      • 09/30/2026
                        04:00 AM
                        09/30/2026
                        AI Command Center: Optimizing Visibility and Control in Your Operations
                        https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                      • 11/19/2026
                        01:00 PM
                        11/19/2026
                        360View: Govern, Secure & Recover Your Microsoft 365 Environment
                        https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version