Dwell Time
¿Qué es Dwell Time?
Dwell TimeThe interval between an adversary's initial compromise of an environment and the defender's detection of that compromise — a headline industry metric reported annually by IR firms such as Mandiant.
Dwell time is the duration between initial intrusion and detection (sometimes broken into 'attacker dwell' until any defender action and 'detection dwell' until first confirmed alert). It is the single most cited efficacy metric in industry incident-response reports — Mandiant's M-Trends, IBM/Ponemon, CrowdStrike — and tracks how successful defenders are at finding adversaries before they finish their objectives. Historically median dwell times were measured in many months (Mandiant reported 416 days in 2011); by 2023–2024 medians had fallen to around 10 days globally for externally-notified incidents and a few days for ransomware-driven cases, both because attackers moved faster (ransomware shifted to days-to-encryption) and because defenders deployed better tooling (EDR, SIEM rule coverage, MDR). Dwell time alone can be misleading — fast detection of a brief intrusion may be worse than slow detection of a long one — so mature programs report it alongside Mean Time to Contain and Mean Time to Recover.
● Ejemplos
- 01
A red-team retrospective records a 21-day dwell from initial AWS key compromise to first alert; the after-action focuses on cloud-control-plane detections.
- 02
A board update reports that median dwell time fell from 32 days last year to 7 days this year following EDR + MDR rollout.
● Preguntas frecuentes
¿Qué es Dwell Time?
The interval between an adversary's initial compromise of an environment and the defender's detection of that compromise — a headline industry metric reported annually by IR firms such as Mandiant. Pertenece a la categoría de Defensa y operaciones en ciberseguridad.
¿Qué significa Dwell Time?
The interval between an adversary's initial compromise of an environment and the defender's detection of that compromise — a headline industry metric reported annually by IR firms such as Mandiant.
¿Cómo funciona Dwell Time?
Dwell time is the duration between initial intrusion and detection (sometimes broken into 'attacker dwell' until any defender action and 'detection dwell' until first confirmed alert). It is the single most cited efficacy metric in industry incident-response reports — Mandiant's M-Trends, IBM/Ponemon, CrowdStrike — and tracks how successful defenders are at finding adversaries before they finish their objectives. Historically median dwell times were measured in many months (Mandiant reported 416 days in 2011); by 2023–2024 medians had fallen to around 10 days globally for externally-notified incidents and a few days for ransomware-driven cases, both because attackers moved faster (ransomware shifted to days-to-encryption) and because defenders deployed better tooling (EDR, SIEM rule coverage, MDR). Dwell time alone can be misleading — fast detection of a brief intrusion may be worse than slow detection of a long one — so mature programs report it alongside Mean Time to Contain and Mean Time to Recover.
¿Cómo defenderse de Dwell Time?
Las defensas contra Dwell Time combinan habitualmente controles técnicos y prácticas operativas, como se detalla en la definición.
¿Cuáles son otros nombres para Dwell Time?
Nombres alternativos comunes: Attacker dwell time, Compromise-to-detect time.
● Términos relacionados
- defense-ops№ 735
MTTD (tiempo medio de detección)
Tiempo medio transcurrido entre el inicio de un incidente de seguridad y el momento en que los defensores lo identifican.
- defense-ops№ 734
MTTC (tiempo medio de contención)
Tiempo medio entre la detección de un incidente y el momento en que la amenaza ya no puede propagarse, exfiltrar datos ni causar más daño.
- defense-ops№ 737
MTTR (tiempo medio de respuesta)
Tiempo medio entre la detección de un incidente de seguridad y el inicio de una acción de respuesta efectiva.
- defense-ops№ 736
MTTR (tiempo medio de recuperación)
Tiempo medio necesario para restablecer los sistemas y servicios afectados a su funcionamiento normal tras un incidente o una caída.
- forensics-ir№ 582
Respuesta a incidentes
Proceso organizado para preparar, detectar, analizar, contener, erradicar y recuperarse de incidentes de ciberseguridad, capturando además lecciones aprendidas.
- defense-ops№ 1267
Caza de Amenazas
Búsqueda proactiva basada en hipótesis sobre la telemetría para descubrir amenazas que han eludido las detecciones existentes.