Dwell Time
Was ist Dwell Time?
Dwell TimeThe interval between an adversary's initial compromise of an environment and the defender's detection of that compromise — a headline industry metric reported annually by IR firms such as Mandiant.
Dwell time is the duration between initial intrusion and detection (sometimes broken into 'attacker dwell' until any defender action and 'detection dwell' until first confirmed alert). It is the single most cited efficacy metric in industry incident-response reports — Mandiant's M-Trends, IBM/Ponemon, CrowdStrike — and tracks how successful defenders are at finding adversaries before they finish their objectives. Historically median dwell times were measured in many months (Mandiant reported 416 days in 2011); by 2023–2024 medians had fallen to around 10 days globally for externally-notified incidents and a few days for ransomware-driven cases, both because attackers moved faster (ransomware shifted to days-to-encryption) and because defenders deployed better tooling (EDR, SIEM rule coverage, MDR). Dwell time alone can be misleading — fast detection of a brief intrusion may be worse than slow detection of a long one — so mature programs report it alongside Mean Time to Contain and Mean Time to Recover.
● Beispiele
- 01
A red-team retrospective records a 21-day dwell from initial AWS key compromise to first alert; the after-action focuses on cloud-control-plane detections.
- 02
A board update reports that median dwell time fell from 32 days last year to 7 days this year following EDR + MDR rollout.
● Häufige Fragen
Was ist Dwell Time?
The interval between an adversary's initial compromise of an environment and the defender's detection of that compromise — a headline industry metric reported annually by IR firms such as Mandiant. Es gehört zur Kategorie Verteidigung und Betrieb der Cybersicherheit.
Was bedeutet Dwell Time?
The interval between an adversary's initial compromise of an environment and the defender's detection of that compromise — a headline industry metric reported annually by IR firms such as Mandiant.
Wie funktioniert Dwell Time?
Dwell time is the duration between initial intrusion and detection (sometimes broken into 'attacker dwell' until any defender action and 'detection dwell' until first confirmed alert). It is the single most cited efficacy metric in industry incident-response reports — Mandiant's M-Trends, IBM/Ponemon, CrowdStrike — and tracks how successful defenders are at finding adversaries before they finish their objectives. Historically median dwell times were measured in many months (Mandiant reported 416 days in 2011); by 2023–2024 medians had fallen to around 10 days globally for externally-notified incidents and a few days for ransomware-driven cases, both because attackers moved faster (ransomware shifted to days-to-encryption) and because defenders deployed better tooling (EDR, SIEM rule coverage, MDR). Dwell time alone can be misleading — fast detection of a brief intrusion may be worse than slow detection of a long one — so mature programs report it alongside Mean Time to Contain and Mean Time to Recover.
Wie schützt man sich gegen Dwell Time?
Schutzmaßnahmen gegen Dwell Time kombinieren typischerweise technische Kontrollen und operative Praktiken, wie in der Definition oben beschrieben.
Welche anderen Bezeichnungen gibt es für Dwell Time?
Übliche alternative Bezeichnungen: Attacker dwell time, Compromise-to-detect time.
● Verwandte Begriffe
- defense-ops№ 735
MTTD (mittlere Erkennungszeit)
Durchschnittliche Zeitspanne zwischen dem Beginn eines Sicherheitsvorfalls und dem Moment, in dem die Verteidiger ihn erkennen.
- defense-ops№ 734
MTTC (mittlere Eindämmungszeit)
Durchschnittliche Zeitspanne zwischen Detektion eines Vorfalls und dem Zustand, in dem die Bedrohung sich nicht mehr ausbreiten, Daten exfiltrieren oder weiteren Schaden anrichten kann.
- defense-ops№ 737
MTTR (mittlere Reaktionszeit)
Durchschnittliche Zeitspanne zwischen der Detektion eines Sicherheitsvorfalls und dem Start einer wirksamen Reaktion darauf.
- defense-ops№ 736
MTTR (mittlere Wiederherstellungszeit)
Durchschnittliche Zeit, die benötigt wird, um betroffene Systeme und Dienste nach einem Sicherheitsvorfall oder Ausfall wieder in den Normalbetrieb zu bringen.
- forensics-ir№ 582
Incident Response
Strukturierter Prozess zur Vorbereitung, Erkennung, Analyse, Eindämmung, Bereinigung und Wiederherstellung nach Cyber-Sicherheitsvorfällen mit anschließender Auswertung.
- defense-ops№ 1267
Threat Hunting
Proaktive, hypothesengetriebene Suche in der Telemetrie nach Bedrohungen, die bestehenden Detektionen entgangen sind.