S

Stairwell Backstory

by Stairwell

Governance & SecurityAI Agents & OrchestrationData & Analytics

Agentic malware investigation that maps blast radius from every executable you have ever run

Contact for pricing·Added Aug 8, 2026·Updated Aug 8, 2026
Share:
THE DAILY BRIEF
Stairwell Backstory

by Stairwell

Governance & SecurityAI Agents & OrchestrationData & Analytics

Agentic malware investigation that maps blast radius from every executable you have ever run

Contact for pricing

Stairwell Backstory is an agentic investigation platform that traces related malware variants, identifies every affected system and maps an incident's full blast radius in seconds. It is built for security operations and incident response teams who can already detect an alert but cannot answer what else the same actor left behind in the environment.

At a Glance

Category
Governance & Security
Pricing
Contact for pricing
Target Market
CISOs, Security Operations Leads, Incident Responders, Detection Engineers
Deployment
Cloud-first
Founded
2020
Headquarters
Sunnyvale, California, United States

Key Features

  • Ground-truth executable corpus
  • Continuous retro-hunt
  • Blast radius mapping
  • Agentic investigation
  • MITRE-mapped campaign reporting
  • Autonomous detection
  • SOC tool integrations

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Scoping an active intrusion
  • Retro-hunting a new indicator
  • Catching polymorphic variants
  • Supply chain compromise investigation
  • Post-incident regulatory evidence

Ideal For

Best For

  • Incident response teams that need to establish the full scope of an intrusion, not just contain the one file that alerted
  • Retro-hunting historical exposure when new threat intelligence lands, across files collected long before the indicator existed
  • Finding polymorphic or lightly modified malware variants that hash- and signature-based detection misses entirely
  • Detection engineering teams wanting MITRE-mapped campaign reports with concrete remediation actions rather than raw alert streams
  • Security teams in financial services, healthcare and fintech that must evidence the scope of a compromise to regulators or auditors

Not Ideal For

  • Organisations that cannot accept continuous collection and indefinite retention of every executable from their endpoints, for privacy, legal or data residency reasons
  • Threat models dominated by script-based, living-off-the-land, identity or SaaS attacks, since the corpus and the analysis are built around executable files
  • Small teams looking for a first EDR or a single consolidated security platform — this is an investigation layer that assumes you already run one
  • Buyers who require published pricing, since Stairwell discloses none and the product is sold entirely through sales conversations

Market Analysis

Enterprise-gradeSpecialist investigation layerVenture-backed

Pros

  • The retained-corpus architecture answers a question alert-centric tools structurally cannot: what else is already here that nobody has looked for
  • Continuous retro-hunt converts new threat intelligence into historical coverage automatically, without re-instrumenting endpoints
  • The Hidden Malware Report gives the pitch an evidenced basis — 2.4 additional variants per published hash across 1,085 threat reports
  • Integrates with the SOC stack customers already run (Google SecOps, Splunk, CrowdStrike, SentinelOne, Cortex, Tines) rather than demanding replacement
  • Deep pedigree and backing: founded by Chronicle's ex-CSO with Sequoia, Accel, Section 32 and Lux Capital investment

Cons

  • No independent user reviews exist on G2, Capterra, TrustRadius or PeerSpot, and Hacker News carries only Stairwell's 2022 Maui ransomware research rather than product experience
  • Backstory does not appear in independent 2026 agentic-SOC vendor comparisons, which cover CrowdStrike, SentinelOne, Torq, Intezer, Dropzone and others — a sign of limited analyst and buyer mindshare
  • Continuously collecting and permanently retaining every executable from every endpoint is a substantial privacy, legal and data-residency review, and a permanent storage cost
  • Coverage is executable-centric, so script-based, living-off-the-land, identity and SaaS-native attack paths fall largely outside what the corpus can answer
  • The last disclosed funding round was the October 2022 Series B, with no newer round announced in nearly four years
  • No pricing, no free trial, no published security certifications and no publicly named reference customers — only industry sectors are disclosed

Pricing

Enterprise

Contact for pricing

  • Agentic blast radius investigation
  • Continuous retro-hunt across preserved file history
  • MITRE-mapped campaign reporting
  • SOC platform integrations
  • Access to the 1.5B+ file corpus and 110,000+ detection rules

Stairwell publishes no list pricing for Backstory or the underlying platform; neither the launch announcement nor the product pages disclose a rate card, tiers, or a free trial, so every deal is quoted through sales. Because the architecture depends on continuously collecting and permanently retaining every executable from every endpoint, buyers should assume cost scales with endpoint count and with retained corpus volume, and should establish how storage growth is billed over a multi-year retention horizon before signing. Independent review sites carry no pricing data points to benchmark against either.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

THE DAILY BRIEF

Enterprise AI insights for technology and business leaders, twice weekly.

beri.net

Subscribe at beri.net/subscribe for twice-weekly AI insights delivered to your inbox.

LinkedIn: linkedin.com/in/rberi  |  X: x.com/rajeshberi

© 2026 Rajesh Beri. All rights reserved.

Stairwell Backstory is an agentic investigation platform that traces related malware variants, identifies every affected system and maps an incident's full blast radius in seconds. It is built for security operations and incident response teams who can already detect an alert but cannot answer what else the same actor left behind in the environment.

Stairwell launched Backstory on 29 July 2026, positioning it as the first agentic investigation platform for malware blast radius and demonstrating it at Black Hat USA. It sits on top of the ground-truth architecture Stairwell has built since 2020: rather than analysing alerts, the platform continuously collects and preserves every executable file from customer endpoints into a private corpus that is kept indefinitely and re-examined whenever new threat intelligence lands. Backstory runs that corpus through four stages — gather, store, analyse and answer — so an investigation starts from files that actually touched the environment rather than from detections another tool happened to fire. Its agentic layer traces related variants, locates every affected host, tracks copies across all hosts and time periods, and produces MITRE-mapped campaign reports with concrete remediation actions, with verdicts claimed within 200 seconds. The scale behind it is the differentiator Stairwell leans on: over 1.5 billion preserved executable files, AI trained on more than 110,000 detection rules, intelligence from over 20 public threat sources, and 8.7 billion historical rule match records. The company's Hidden Malware Report supplies the thesis — across 1,085 public threat reports, every published malware hash represented on average 2.4 additional malicious variants, surfacing over 46,000 related malicious files that the original research omitted and that hash- and signature-based detection tends to miss. Backstory integrates with Google Security Operations and Chronicle, Palo Alto Cortex, Splunk, SentinelOne, CrowdStrike, Tines, Slack and The Hive. Stairwell was founded by Mike Wiacek, formerly Chronicle's chief security officer and founder of Google's Threat Analysis Group, and has raised $69.5 million, most recently a $45 million Series B led by Section 32 in October 2022 with Sequoia Capital, Accel, Lux Capital and Gradient Ventures participating.

Ideal Buyer

The incident response or detection engineering lead who can triage alerts adequately but cannot prove what else an intrusion left behind across hosts and months of history.

Key Benefit

Blast radius mapped from a permanently retained corpus of every executable, so a single detection becomes a complete variant and host list rather than one closed ticket.

At a Glance

Category
Governance & Security
Pricing
Contact for pricing
Target Market
CISOs, Security Operations Leads, Incident Responders, Detection Engineers
Deployment
Cloud-first
Founded
2020
Headquarters
Sunnyvale, California, United States

Key Features

  • Ground-truth executable corpus

    Continuously collects and preserves every executable from customer endpoints into a private corpus kept indefinitely for later re-analysis

  • Continuous retro-hunt

    Automatically rescans the entire preserved file history whenever new threat intelligence arrives, surfacing exposure that predates the indicator

  • Blast radius mapping

    Traces variants and copies across every host and time period to show exactly what must be contained

  • Agentic investigation

    Runs the investigation autonomously from file evidence rather than requiring an analyst to pivot manually between tools

  • MITRE-mapped campaign reporting

    Delivers campaign reports mapped to MITRE ATT&CK with concrete remediation actions rather than raw indicator lists

  • Autonomous detection

    Analyses new executables independently of other security tools, so coverage does not depend on another vendor firing first

  • SOC tool integrations

    Connects to Google Security Operations, Palo Alto Cortex, Splunk, SentinelOne, CrowdStrike, Tines, Slack and The Hive

Capabilities

text generation
image generation
video generation
code generation
workflow automation
api access
audio generation
fine tuning
agent orchestration

Use Cases

  • Scoping an active intrusion

    Turn one detected file into the complete list of related variants and every host that ever executed them

  • Retro-hunting a new indicator

    Rescan years of preserved executables when fresh intelligence lands to find exposure that existed before anyone was looking

  • Catching polymorphic variants

    Identify the average 2.4 additional variants behind each published hash that signature-based detection reliably misses

  • Supply chain compromise investigation

    Determine whether a compromised vendor binary ever landed in the estate and which systems executed it

  • Post-incident regulatory evidence

    Produce MITRE-mapped campaign reports evidencing the scope of a breach for auditors, regulators or cyber insurers

Ideal For

Best For

  • Incident response teams that need to establish the full scope of an intrusion, not just contain the one file that alerted
  • Retro-hunting historical exposure when new threat intelligence lands, across files collected long before the indicator existed
  • Finding polymorphic or lightly modified malware variants that hash- and signature-based detection misses entirely
  • Detection engineering teams wanting MITRE-mapped campaign reports with concrete remediation actions rather than raw alert streams
  • Security teams in financial services, healthcare and fintech that must evidence the scope of a compromise to regulators or auditors

Not Ideal For

  • Organisations that cannot accept continuous collection and indefinite retention of every executable from their endpoints, for privacy, legal or data residency reasons
  • Threat models dominated by script-based, living-off-the-land, identity or SaaS attacks, since the corpus and the analysis are built around executable files
  • Small teams looking for a first EDR or a single consolidated security platform — this is an investigation layer that assumes you already run one
  • Buyers who require published pricing, since Stairwell discloses none and the product is sold entirely through sales conversations

Deployment

On-Premise

Market Analysis

Enterprise-gradeSpecialist investigation layerVenture-backed

Pros

  • The retained-corpus architecture answers a question alert-centric tools structurally cannot: what else is already here that nobody has looked for
  • Continuous retro-hunt converts new threat intelligence into historical coverage automatically, without re-instrumenting endpoints
  • The Hidden Malware Report gives the pitch an evidenced basis — 2.4 additional variants per published hash across 1,085 threat reports
  • Integrates with the SOC stack customers already run (Google SecOps, Splunk, CrowdStrike, SentinelOne, Cortex, Tines) rather than demanding replacement
  • Deep pedigree and backing: founded by Chronicle's ex-CSO with Sequoia, Accel, Section 32 and Lux Capital investment

Cons

  • No independent user reviews exist on G2, Capterra, TrustRadius or PeerSpot, and Hacker News carries only Stairwell's 2022 Maui ransomware research rather than product experience
  • Backstory does not appear in independent 2026 agentic-SOC vendor comparisons, which cover CrowdStrike, SentinelOne, Torq, Intezer, Dropzone and others — a sign of limited analyst and buyer mindshare
  • Continuously collecting and permanently retaining every executable from every endpoint is a substantial privacy, legal and data-residency review, and a permanent storage cost
  • Coverage is executable-centric, so script-based, living-off-the-land, identity and SaaS-native attack paths fall largely outside what the corpus can answer
  • The last disclosed funding round was the October 2022 Series B, with no newer round announced in nearly four years
  • No pricing, no free trial, no published security certifications and no publicly named reference customers — only industry sectors are disclosed

Pricing

Enterprise

Contact for pricing

  • Agentic blast radius investigation
  • Continuous retro-hunt across preserved file history
  • MITRE-mapped campaign reporting
  • SOC platform integrations
  • Access to the 1.5B+ file corpus and 110,000+ detection rules

Stairwell publishes no list pricing for Backstory or the underlying platform; neither the launch announcement nor the product pages disclose a rate card, tiers, or a free trial, so every deal is quoted through sales. Because the architecture depends on continuously collecting and permanently retaining every executable from every endpoint, buyers should assume cost scales with endpoint count and with retained corpus volume, and should establish how storage growth is billed over a multi-year retention horizon before signing. Independent review sites carry no pricing data points to benchmark against either.

Security & Compliance

soc2
gdpr
hipaa
iso27001
sso
data residency

Sources

This page was written from 6 sources, 5 on domains other than stairwell.com.

  1. 1.stairwell.comstairwell.comvendor
  2. 2.globenewswire.comstairwell launches backstory the first agentic investigation
  3. 3.helpnetsecurity.comstairwell backstory agentic investigation
  4. 4.helpnetsecurity.comstairwell funding
  5. 5.underdefense.comagentic soc platforms
  6. 6.hn.algolia.comsearch
Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe