Dwell Time
O que é Dwell Time?
Dwell TimeThe interval between an adversary's initial compromise of an environment and the defender's detection of that compromise — a headline industry metric reported annually by IR firms such as Mandiant.
Dwell time is the duration between initial intrusion and detection (sometimes broken into 'attacker dwell' until any defender action and 'detection dwell' until first confirmed alert). It is the single most cited efficacy metric in industry incident-response reports — Mandiant's M-Trends, IBM/Ponemon, CrowdStrike — and tracks how successful defenders are at finding adversaries before they finish their objectives. Historically median dwell times were measured in many months (Mandiant reported 416 days in 2011); by 2023–2024 medians had fallen to around 10 days globally for externally-notified incidents and a few days for ransomware-driven cases, both because attackers moved faster (ransomware shifted to days-to-encryption) and because defenders deployed better tooling (EDR, SIEM rule coverage, MDR). Dwell time alone can be misleading — fast detection of a brief intrusion may be worse than slow detection of a long one — so mature programs report it alongside Mean Time to Contain and Mean Time to Recover.
● Exemplos
- 01
A red-team retrospective records a 21-day dwell from initial AWS key compromise to first alert; the after-action focuses on cloud-control-plane detections.
- 02
A board update reports that median dwell time fell from 32 days last year to 7 days this year following EDR + MDR rollout.
● Perguntas frequentes
O que é Dwell Time?
The interval between an adversary's initial compromise of an environment and the defender's detection of that compromise — a headline industry metric reported annually by IR firms such as Mandiant. Pertence à categoria Defesa e operações da cibersegurança.
O que significa Dwell Time?
The interval between an adversary's initial compromise of an environment and the defender's detection of that compromise — a headline industry metric reported annually by IR firms such as Mandiant.
Como funciona Dwell Time?
Dwell time is the duration between initial intrusion and detection (sometimes broken into 'attacker dwell' until any defender action and 'detection dwell' until first confirmed alert). It is the single most cited efficacy metric in industry incident-response reports — Mandiant's M-Trends, IBM/Ponemon, CrowdStrike — and tracks how successful defenders are at finding adversaries before they finish their objectives. Historically median dwell times were measured in many months (Mandiant reported 416 days in 2011); by 2023–2024 medians had fallen to around 10 days globally for externally-notified incidents and a few days for ransomware-driven cases, both because attackers moved faster (ransomware shifted to days-to-encryption) and because defenders deployed better tooling (EDR, SIEM rule coverage, MDR). Dwell time alone can be misleading — fast detection of a brief intrusion may be worse than slow detection of a long one — so mature programs report it alongside Mean Time to Contain and Mean Time to Recover.
Como se defender contra Dwell Time?
As defesas contra Dwell Time costumam combinar controles técnicos e práticas operacionais, conforme detalhado na definição acima.
Quais são outros nomes para Dwell Time?
Nomes alternativos comuns: Attacker dwell time, Compromise-to-detect time.
● Termos relacionados
- defense-ops№ 735
MTTD (tempo médio de detecção)
Tempo médio decorrido entre o início de um incidente de segurança e o momento em que os defensores o identificam.
- defense-ops№ 734
MTTC (tempo médio de contenção)
Tempo médio entre a detecção de um incidente e o ponto em que a ameaça já não consegue se propagar, exfiltrar dados ou causar mais danos.
- defense-ops№ 737
MTTR (tempo médio de resposta)
Tempo médio entre a detecção de um incidente de segurança e o início de uma ação eficaz de resposta.
- defense-ops№ 736
MTTR (tempo médio de recuperação)
Tempo médio necessário para restabelecer sistemas e serviços afetados à operação normal após um incidente de segurança ou indisponibilidade.
- forensics-ir№ 582
Resposta a incidentes
Processo organizado para preparar, detetar, analisar, conter, erradicar e recuperar de incidentes de cibersegurança, capturando lições aprendidas.
- defense-ops№ 1267
Caça a Ameaças
Busca proativa e orientada por hipóteses na telemetria para encontrar ameaças que escaparam das detecções existentes.