Rubrik Upgrades Data Protection Platform for Speedier Threat Hunting

Data security specialist Rubrik is upgrading its data protection platform to allow for quicker recoveries in the familiar backup & recovery process. The new Turbo Threat Hunting functionality more quickly scans an enterprise network to find clean recovery points after malware attacks, according to the company.

The new approach changes the current method that requires mounting and scanning data on a file-by-file basis to find signs of tampering, instead leveraging other techniques — including pre-computed hash values within Rubrik's metadata — that significantly speed up the process.

"Traditional recovery methods involve manually scanning each backup file, which can take an excruciatingly long time. Imagine having to sift through hundreds of thousands of backups to locate clean recovery points. For many organizations, that process can take days or even weeks, leaving them vulnerable to ongoing disruption and significant financial losses," the company said in a blog post. By contrast, the new tech reduces the time to find a backup that is free from Indicators of Compromise (IOCs) "from days to mere seconds."

In addition to those pre-computed hashes for instant scanning, other highlights of the upgrade include:

  • Automated Threat Hunts: During an incident, users input known malware indicators, and Rubrik's Turbo Threat Hunting feature will scan an entire backup environment to find unaffected recovery points.
  • Cluster-Level Scanning: Instead of tediously selecting individual servers or backups, users can scan entire clusters with a single click, speeding up the search for clean recovery points.
  • Quick Results: In a recent internal test, Turbo Threat Hunting scanned an estimated 75,000 backups within 60 seconds, identifying the one affected server and enabling a quick path to recovery.
  • Quarantining: Automatically quarantine impacted files and backups to ensure the attacker is not re-introduced into the environment.
  • Recovery Orchestration: Mass-recovery orchestration of all backups from the most recent non-anomalylous, non-quarentined backup in just a few clicks to massively reduce the recovery time objective of the data and applications.

The upgrade is being rolled out automatically around the end of January to Enterprise Edition and cloud customers.

For more information, visit the Rubrik site.

About the Author

David Ramel is an editor and writer at Converge 360.

Featured

  • abstract glowing circuit patterns

    Microsoft Reduces Copilot Integrations in Windows 11

    Microsoft is dialing back its aggressive Copilot push in Windows 11, promising a sweeping quality overhaul that puts performance and reliability ahead of AI feature expansion .

  • silhouette of business person facing wall of data

    Why AI Strategy Belongs in the President's Office

    Institutions that are succeeding with AI share one thing in common, and it is not a better committee, a larger budget, or a more sophisticated technology stack. It is a president who never handed off the steering wheel.

  • Profile silhouette of a person thoughtfully touching their chin, overlaid with transparent data visualizations and digital interface elements suggesting artificial intelligence and analytics.

    The Institutional Knowledge Shift Is Reshaping Higher Ed IT

    Higher education IT leaders are navigating a quiet but consequential transition: Experienced team members are retiring or leaving for private-sector roles, and the teams replacing them are smaller, newer, and often stretched thin. The result is a structural shift in how technology decisions are made, executed, and sustained.

  • large cloud icon on the right in an abstract world above a polygon with a dark blue background

    Cloud Security Alliance Expands Focus on Governance and Assurance for Agentic AI Systems

    The Cloud Security Alliance (CSA) recently announced a series of CSAI Foundation milestones aimed at securing what it calls the agentic control plane, including a new catastrophic risk initiative, CVE Numbering Authority authorization, and the acquisition of two agentic AI specifications.