VYPR
researchPublished Jul 29, 2026· 1 source

Stairwell Launches Backstory for Agentic Malware Investigation

Stairwell introduces Backstory, an AI-powered platform designed to rapidly trace malware variants, identify affected systems, and map the full blast radius of an incident.

Stairwell has announced the release of Backstory, a new agentic investigation platform aimed at revolutionizing how organizations respond to malware incidents. This AI-powered tool is engineered to swiftly trace related malware variants, pinpoint affected systems, and map the complete blast radius of an attack within seconds. The objective is to provide enterprises with immediate clarity on the scope of an incident, enabling faster containment and risk reduction.

The launch comes at a critical juncture, as AI-generated malware becomes increasingly prevalent, making it easier for adversaries to craft novel variants. Traditional alert-based security tools are struggling to keep pace with this evolving threat landscape. While many AI security solutions focus on reducing alert noise and accelerating triage, Backstory prioritizes risk reduction by providing a comprehensive view of what truly exists within an environment, where it has spread, and precisely what requires containment.

This initiative is informed by Stairwell's recent Hidden Malware Report, which revealed that malware families are significantly larger than publicly reported. The report analyzed 1,085 public threat reports and found that, on average, each published malware hash represents 2.4 additional malicious variants. Stairwell's analysis uncovered over 46,000 related malicious files that were not included in the original research, suggesting that defenders often investigate only a fraction of an attack's true scope.

The implications of these findings are substantial. Because variants often differ just enough to evade traditional hash- and signature-based detection methods, organizations may unknowingly leave related malware active within their systems. This highlights a critical gap in current incident response capabilities, where the focus on individual alerts can obscure the broader impact of a sophisticated attack.

Mike Wiacek, founder and CTO of Stairwell, emphasized this point, stating, "Closing tickets faster does not mean you contained the threat." He elaborated that the crucial questions for security teams are not just about closing alerts, but about understanding the full scope: "What else looks like it, where did it land, how long has it been here, and what do I need to do to contain it?" Backstory aims to equip every team with this level of investigative power, irrespective of their staffing levels.

Jeff Moore, CSO at H&M Group, echoed the sentiment, noting that attackers can test against global threat intelligence and common detection rules, but they cannot test against an organization's specific environment. He advocates for shifting the focus from the external question of "what's bad out there?" to the internal question of "what changed in here?" This internal focus, he argues, is the more honest and effective approach to security.

Backstory is built upon Stairwell's ground-truth architecture, which continuously collects all executable files from customer endpoints and stores them in a private, secure corpus. This approach allows Stairwell to reason over actual files within an environment, rather than solely relying on alerts. The platform is powered by an AI trained on over 110,000 detection rules, intelligence from more than 20 public threat sources, and has processed over 8.7 billion historical rule matches, leveraging a corpus of more than 1.5 billion executable files to provide historical context for identifying previously unseen variants.

Stairwell plans to showcase Backstory at Black Hat USA, providing attendees with a firsthand look at its capabilities in tackling the challenges posed by increasingly sophisticated and variant-rich malware.

Synthesized by Vypr AI