Key Takeaways
- Druva Identity Resilience now maps identity attack paths across Microsoft Entra ID, Active Directory, and Okta.
- Druva’s new Ransomware Detection uses behavioral analysis and forensic validation to confirm malicious activity.
- The capabilities use backup telemetry to identify affected objects and help organizations select clean recovery points.
Druva has expanded Druva Identity Resilience and launched Ransomware Detection, bringing identity investigation, ransomware validation, and recovery planning closer together within its data-protection environment.
Both offerings are designed to address a persistent incident-response problem: detecting suspicious activity does not automatically tell security teams what was compromised, how far an attacker traveled, or which recovery point can still be trusted. Druva is using historical backup telemetry and behavioral intelligence to help answer those questions.
The identity capabilities are powered by Dru MetaGraph, which analyzes relationships and activity involving human and non-human identities across Microsoft Entra ID, Active Directory, and Okta. The technology contextualizes changes to identities, permissions, applications, and policies over time, producing an interactive view of how suspicious behavior moved through an environment.
That historical context matters because identity has become closely tied to ransomware. Sophos reported in its State of Ransomware 2026 research that 79% of ransomware attacks began with an identity-based approach. Malicious email accounted for 26%, while phishing represented 24% (source).
Druva Identity Resilience is intended to reconstruct the attack path after access has been obtained. It can show where an attacker entered, escalated privileges, established persistence, or moved laterally. Detected behavior is also mapped to relevant MITRE ATT&CK tactics, techniques, and procedures.
Because attackers frequently use valid credentials and legitimate administrative functions, their actions can appear routine when viewed individually. However, when analyzed as a connected sequence across identities, applications, policies, and time, these movements reveal the broader attack path.
Dru MetaGraph also helps identify a trusted pre-attack state by comparing historical changes and snapshots. Customers can use that evidence to determine which objects require restoration and which clean snapshots should be selected. The resulting recovery plan identifies affected objects, recommends actions, and associates each object with a prevalidated recovery point.
“Security teams know they can’t stop every attack. The challenge is knowing exactly what happens when a threat breaks through,” said the chief security officer at Druva. “AI makes that uncertainty more dangerous. Before you recover, you need evidence of what changed, how far the compromise spread, and what can still be trusted.”
The chief security officer stated that the platform uses years of backup telemetry to validate threat signals and provide an evidence-based foundation for recovery. Druva claims that the connected analysis can reduce identity investigations from days to hours, although results will depend on an organization’s specific environment, available telemetry, and incident scope.
Ransomware Detection applies a related approach to protected data. Its proprietary AI threat pipeline analyzes backup activity through multiple behavioral and forensic validation stages, with the goal of distinguishing ransomware from unusual but legitimate file operations.
Traditional anomaly detection can identify sudden file changes, deletion spikes, or other irregular behavior, but security teams still must determine whether the activity was caused by ransomware, a bulk migration, an administrator, or a malfunctioning application. Druva’s pipeline is designed to filter noisy signals, validate ransomware behavior, confirm the affected data, and locate clean recovery points.
The timing reflects broader pressure on security and recovery operations. Microsoft’s Digital Defense reporting has documented more than 600 million identity attacks per day across its ecosystem, with 97% described as password-based. Meanwhile, Mordor Intelligence estimates that the identity threat detection and response market will grow from $2.78 billion in 2025 to $3.42 billion in 2026, reaching $10.51 billion by 2031 at a 25.17% compound annual growth rate.
This product expansion focuses on connecting detection with recovery decisions. Security teams often have plenty of alerts, but lack reliable evidence showing what changed and what remains usable during a high-pressure incident.
For customers, the practical test will be whether Druva Identity Resilience and Ransomware Detection reduce manual investigation without obscuring how conclusions were reached. If the behavioral evidence proves clear enough for incident responders to validate, the new capabilities could help shorten the uncertain period between detecting an attack and restoring trusted operations.
⬇️