Home  ›  Glossary  ›  Breach Detection

What is breach detection?

Breach detection is the identification of unauthorized access to systems or data, either while an intrusion is under way or after it has happened. It works by collecting activity records from computers, networks, sign-in systems, applications and storage, flagging signs of compromise, and confirming them through investigation.

Two weeks of restore points taken with the attacker inside

Each day an intruder goes unnoticed adds another backup that may carry their tools, and gives them another day to study the backup system before destroying it. The gap is usually counted in weeks: the median time between intrusion and detection was 14 days in 2025. With nightly jobs, that places roughly the fourteen newest restore points inside the attacker's stay.

Detection time therefore sets how deep a clean restore has to go. Recovery means stepping back past the moment of entry, which is possible only when retention reaches further back than the intrusion did. Seven days of restore points offer nothing clean to an intrusion found on day fourteen.

Signals scattered across endpoints, identity and storage

  • Endpoints: programs launched, files changed and tools run on servers and workstations.
  • Network: connections to unfamiliar hosts and unusual outbound volume.
  • Identity: sign-ins from new places or at odd hours, new administrator accounts, new access keys.
  • Applications and storage: database queries, object reads and deletions, configuration changes.
  • Decoys: planted credentials or files with no legitimate use, so any touch is suspect.
  • Outside notice: a partner, law enforcement or the attacker announcing the breach.

Detection tools read those signals in different ways. Signature matching catches known malicious files and domains, and misses attackers who work with ordinary admin tools. Behavior analysis compares activity with a baseline and raises false alarms whenever normal work changes. A SIEM joins events from many sources into one timeline and is only as complete as the logs it receives. Threat hunting sends analysts after a specific attack pattern and depends on staff time that a small team rarely has spare.

No single source sees the whole intrusion. Logins with a stolen password look ordinary on their own, and the pattern only emerges when they line up with something odd elsewhere, such as a burst of deletions on the backup repository an hour later.

Early warnings from the backup repository

Attackers preparing ransomware or backup tampering leave traces in the backup environment before production goes dark: restore points removed in bulk, retention shortened, jobs disabled, fresh access keys, requests that try to bypass governance-mode retention, or one identity reading far more of the repository than any restore would need. Once encryption starts on production, the next backup jobs show it as well. Change rates jump and deduplication ratios collapse, because encrypted blocks no longer match anything stored before.

Those warnings help only if they reach a person and outlast the attack. An alert raised inside a backup console the attacker has signed in to can be read and cleared by the attacker. Logs kept on the system under attack disappear with it. Logs retained for less time than the intrusion lasted no longer show how it began, which leaves the investigation guessing at the entry point. Without a security operations center, a mid-sized IT team depends heavily on storage and backup events landing somewhere the intruder cannot reach.

ARTESCA and breach detection

ARTESCA can forward its audit logs to Splunk, Graylog, Elasticsearch or syslog, placing storage events such as object deletions, key creation and permission changes on the same timeline as endpoint and sign-in data. Capacity and performance metrics appear in the management UI and in Grafana and Prometheus, where a surge of reads or writes stands out against the regular backup schedule. Accounts lock after three invalid login attempts within 15 minutes, so password guessing against the storage leaves a record of its own. ARTESCA supplies the storage half of the picture; matching those events against endpoint and identity activity happens in the SIEM or log platform that receives them.