Stairwell presents Backstory: an AI agent to map malware spread
Stairwell, a cybersecurity company, has launched Backstory, an AI agent designed to investigate malware spread starting from a single alert. Mike Wiacek, founder and CTO of Stairwell, explained to Help Net Security how this tool revolutionizes the response to cyber attacks.
An innovative approach to cybersecurity
Backstory is described as an "agentic investigation platform for malware spread radius". In simple terms, this tool starts with a single alert and works outward to map how far a malware campaign has spread. It is designed for SOC (Security Operations Center) and incident response teams, who need to answer the fundamental question behind every alert: how far has this malware actually spread and have we found it all?
The problem of malware variants
Stairwell discovered that every published malware sample hides an average of 2.4 undocumented variants. This means that for every known malware sample, there are on average 2.4 related variants that have not been included in public threat reports. In total, Stairwell identified 46,594 hidden malicious files associated with publicly known malware samples.
Malware variants are not just files that share some code fragments. Stairwell uses proprietary variant discovery technology that evaluates multiple technical signals, including shared signatures, import table similarities, code reuse, and other proprietary indicators, to determine if a file is significantly related to the original malware.
The power of "ground truth"
Stairwell collects every executable that runs on customers' endpoints, including binaries, scripts, and DLLs, and preserves them in a dedicated environment forever. This approach, called "ground truth", is different from other security tools that rely on logs.
"Ground truth" preserves what actually existed on a device, not a secondary description of what was seen being done. Since everything is preserved, rarity becomes a strategic advantage that attackers cannot quantify or overcome. Stairwell can measure how unusual a file is within your environment and across all environments, providing a unique measurable value. The rarity of a file, combined with the reputation of its variant neighborhood, quantifies the risk in a way that no other approach can match.
The future of AI-generated malware
Stairwell does not claim that a measurable percentage of malware in customer environments is written by AI. However, the change in the attacker economy is already real. AI reduces the time and cost required to modify, test, and customize malware. Attackers no longer have to reuse the same sample on thousands of victims. They can produce many distinct versions of the same tool, test them against common defenses, and distribute the one that passes.
Backstory starts with the opposite assumption: the first sample might be unknown. It can ask and reason about what that file is structurally related to, where related files have existed, what appeared around them, and how far the campaign has reached. This changes the dynamic. Knowledge of your environment becomes a security control in itself.
Managing noise in large corporate environments
Backstory does not generate an alert for every new file, which would avoid overwhelming teams with a different type of flood. A Chrome update that appears on thousands of machines and across the entire Stairwell corpus appears ordinary. A new executable that appears on a single financial workstation, on the other hand, is a significant signal.
Backstory represents a significant step forward in the fight against malware, offering security analysts a more efficient and comprehensive way to understand and respond to threats.
The impact of Backstory on corporate security
Backstory represents a revolution in how companies address cyber threats. Its ability to map the entire spread radius of a malware offers a significant strategic advantage. Traditionally, security teams were forced to work with partial information, limited by initial alerts and available resources. With Backstory, however, analysts can obtain a complete and contextualized view of every malicious campaign.
This depth of analysis allows organizations to identify not only active threats but also dormant or potential ones. Knowledge of the complete spread radius enables assessing the real impact of an attack, understanding infection paths, and implementing more effective containment measures.
The evolution of the threat landscape
The threat landscape has evolved rapidly, with attackers increasingly leveraging advanced technologies such as malicious language models (malicious LLMs) to generate malware. This change has made attacks more frequent, more diverse, and harder to detect with traditional methods.
AI-generated malware not only increases the volume of threats but also introduces greater variability. Attackers can now create numerous variants of the same malicious tool, test them against common defenses, and distribute those that manage to evade security systems. This approach makes malicious campaigns more effective and harder to counter.
The challenge of alert management
One of the biggest obstacles for security teams is alert management. With the increase in the volume and complexity of threats, analysts often find themselves overwhelmed by a high number of reports. Backstory solves this problem by offering a more efficient and automated approach.
The system does not generate an alert for every new file but rather evaluates the context and rarity of each element. This selective approach allows identifying the most significant signals, reducing noise, and improving the efficiency of security operations.
The value of knowing your environment
In-depth knowledge of your environment becomes a security control in itself. Backstory enables organizations to better understand internal dynamics, identifying weak points and risk areas. This awareness allows implementing more effective preventive measures and responding more quickly to emerging threats.
In a context where attackers increasingly exploit variability and adaptability, Backstory's ability to map connections between files and malicious samples offers a unique strategic advantage. Organizations can thus adopt a more proactive approach to security, anticipating attackers' moves and reducing the impact of threats.
The future of cybersecurity
Backstory represents only the beginning of a new era in cybersecurity. With the continuous evolution of threats, it is essential to adopt innovative and adaptable solutions. AI-based tools like Backstory offer a more efficient and comprehensive way to address the challenges of modern security.
Organizations that adopt these technologies can not only improve their response capabilities but also gain a significant competitive advantage. Cybersecurity is no longer a cost but a strategic investment that can make the difference between success and failure.
Stairwell's Backstory represents a significant step forward in the fight against malware. Its ability to map the complete spread radius of malicious campaigns offers unique value to organizations seeking to protect their systems and data. With the evolution of the threat landscape, solutions like Backstory become increasingly essential to ensure the security and resilience of information infrastructures.
In a world where attackers exploit advanced technologies to evade traditional defenses, it is crucial to adopt innovative and proactive approaches. Backstory offers a comprehensive and automated solution that enables security teams to work more efficiently and effectively, improving response capabilities and reducing attack risk.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.