Dwell time is the length of time an attacker is present in an environment before being detected or removed, measured from the first sign of compromise to discovery or containment. It’s a measure of how long an intruder has to explore, steal credentials, move between systems and take data before anyone stops them. Shorter dwell time generally means a smaller incident.
At a glance
- Dwell time runs from the attacker’s first access to detection, or in some definitions to containment.
- It is usually worked out after an incident, by investigators tracing evidence back to the start.
- Longer dwell time gives attackers more chance for lateral movement, data theft and ransomware staging.
- Around-the-clock monitoring, threat hunting and good logging are the main ways to shorten it.
- Definitions vary between reports, so compare figures carefully.
What problem it solves
As a measure, dwell time puts a number on a risk that’s otherwise easy to ignore: an attacker who’s already inside and quiet. Many attacks don’t announce themselves on day one. An attacker may gain access through a phishing email or stolen password, then spend days or weeks mapping the network, escalating privileges and copying data before deploying ransomware or making demands.
Each day undetected raises the cost of the incident: more systems to clean, more data potentially exposed, more notification and legal work. Tracking dwell time, and the detection capabilities that drive it, gives buyers a way to judge whether their monitoring is working and whether a security provider is actually finding intrusions or only reacting to the obvious ones.
How it works
Start point. Investigators look for the earliest evidence of attacker activity: a first malicious login, a planted file, a suspicious process. Gaps in log retention can make the true start unknowable, which is a reason to keep logs long enough.
End point. Detection is when the organization or its provider identifies the intrusion. Some definitions instead end at containment, when the attacker’s access is cut off. Know which a report or contract uses.
Contributing factors. Dwell time tends to be longer when logs aren’t collected or reviewed, when alerts go unanswered outside business hours, when attackers use legitimate tools and valid credentials, and when a breach is discovered by an outside party rather than internal monitoring.
Reducing it. Common measures include:
- Collecting endpoint, identity, network and cloud telemetry in one place.
- 24/7 monitoring, in-house or through managed detection and response (MDR).
- Proactive threat hunting for activity that doesn’t trigger alerts.
- Using threat intelligence and indicators of compromise (IOCs) to search for known attacker activity.
- A practiced incident response process so detection quickly becomes containment.
When it matters for buyers
- When choosing an MDR or SOC service. Ask how the provider detects quiet intrusions, not just loud ones, and what proactive hunting is included. Our managed detection and response overview covers what to compare.
- When cyber insurance renews. Monitoring, logging and response capabilities affect how insurers view your risk.
- When setting log retention. If logs only go back a few days, investigators may not be able to find the start of an intrusion.
- When a peer is breached. Their investigation’s timeline is a useful prompt to ask how quickly you’d have spotted the same activity.
Questions to ask vendors
- How do you detect attackers using valid credentials and legitimate admin tools?
- Is proactive threat hunting included, how often, and what do you report from it?
- What telemetry do you need from us to detect intrusions early, and how long do you retain it?
- How do you measure time to detect and time to contain, and can we see those figures for our account?
- After an incident, will you establish the timeline and dwell time as part of the investigation?
How it differs from MTTD and MTTR
Mean time to detect (MTTD) is an average across many incidents or alerts, used to track a security team’s performance over time. Dwell time usually describes a single intrusion. Mean time to recovery (MTTR) measures how long it takes to restore service after detection. Together they describe the whole timeline: how long the attacker was in, how fast you noticed, and how fast you recovered.
