VYPR
researchPublished Aug 3, 2026· 1 source

Stairwell's Backstory AI Maps Malware 'Blast Radius' Beyond Single Alerts

Stairwell's new AI agent, Backstory, analyzes security alerts to reveal the full scope of malware campaigns, uncovering an average of 2.4 undocumented variants per known sample.

In an era where threat actors increasingly leverage AI to generate malware at unprecedented scale and speed, traditional security defenses are struggling to keep pace. Mike Wiacek, founder and CTO of Stairwell, introduces Backstory, an AI agent designed to tackle this challenge by moving beyond single-alert investigations. Backstory aims to provide security teams with a comprehensive understanding of malware campaign reach, a task that is currently time-consuming and often incomplete.

Backstory operates by taking a single security alert as its starting point and then systematically investigating outward. It identifies structurally related malware variants, traces their command-and-control infrastructure, and searches an organization's historical data to pinpoint every instance of the threat. This process continues until the entire campaign is mapped, revealing the complete "blast radius" – a crucial metric that is difficult to ascertain with current tools. Wiacek emphasizes that attackers rarely deploy just one piece of malware; instead, they use variants to evade detection, making the initial alert only a small part of the overall picture.

Stairwell's research highlights a significant gap in threat intelligence: for every publicly documented malware sample, there exist, on average, 2.4 undocumented variants. Analyzing a corpus of 19,418 known malware samples from 32 security vendors, Stairwell's proprietary Variant Discovery technology identified an additional 46,594 malicious files that were never publicly reported. The company defines a "related variant" not merely by shared code snippets, but by a combination of technical signals including shared signatures, import-table similarity, and code reuse, ensuring a meaningful connection to the original threat.

The core of Backstory's capability lies in Stairwell's unique "ground truth" architecture. This involves continuously collecting and permanently storing every executable file—binaries, scripts, and DLLs—that runs on a customer's endpoints. Unlike log-based systems that provide secondhand accounts of events and are limited by retention periods, Stairwell's approach preserves the actual files that existed on a device. This permanent archive allows for re-examination as new intelligence emerges, providing a more robust and enduring investigative foundation.

This "ground truth" approach offers distinct advantages over alert-driven systems and live telemetry. Backstory can uncover threats that never trigger an alert because they never executed, executed without matching a rule, or appeared benign at the time. By having a complete historical record, Stairwell can measure the rarity of a file within an environment and across all environments, quantifying risk in a way that is impossible with ephemeral log data. This allows for the detection of subtle, low-and-slow attacks that might otherwise remain hidden.

Wiacek explains that Backstory automates the investigative pivots that human analysts typically perform manually, moving between different tools and indicators. This automation, combined with the visibility into the underlying evidence, significantly accelerates the incident response process. The platform is designed for Security Operations Centers (SOCs) and incident response teams, empowering them to answer the critical question behind every alert: "How far did this actually spread, and did we find it all?"

The implications of Backstory's findings are profound. The sheer volume of undocumented malware variants suggests that organizations are likely facing a much larger threat landscape than they currently perceive. By providing a tool that can map the full extent of these campaigns, Stairwell aims to equip defenders with the visibility needed to effectively neutralize threats and prevent future compromises. The platform's ability to analyze historical data and identify previously unknown variants represents a significant step forward in proactive threat hunting and incident response.

Ultimately, Backstory addresses the growing asymmetry in the cybersecurity landscape, where adversaries can operate with speed and scale facilitated by AI. By offering a method to comprehensively map malware "blast radii" and uncover hidden variants, Stairwell provides a critical capability for organizations seeking to understand and defend against the full scope of modern cyberattacks.

Synthesized by Vypr AI