What is Dwell Time?
Dwell Time is the number of days an attacker remains inside a compromised environment before being detected and contained. Shorter dwell time means less opportunity for data theft, lateral movement, and damage.
What it is
Dwell Time is the gap between the moment an attacker first gains access and the moment a defender discovers and stops them. It is measured in days. Industry reports have historically placed median dwell time anywhere from a few days to several weeks, depending on the sector and detection maturity of the organization.
The clock starts at initial compromise, which may be a phishing email, an exploited vulnerability, or stolen credentials. The clock stops when the intrusion is identified, whether by an internal team, an external service, or the attacker themselves (for example, a ransomware note).
Why it matters
Every day an attacker stays undetected is a day they can:
- Move laterally to higher-value systems
- Exfiltrate sensitive data
- Establish additional persistence mechanisms
- Disable or tamper with logging and backups
Shorter dwell time directly limits the blast radius of a breach. Organizations that detect intrusions in hours rather than weeks typically face lower recovery costs and less regulatory exposure.
How tools address it
No single product eliminates dwell time, but several categories reduce it:
- Managed Detection and Response (MDR) services provide 24/7 human and automated monitoring. Platforms like those in the MDR category correlate endpoint, network, and cloud telemetry to surface threats that internal teams might miss overnight or on weekends.
- Threat Hunting teams proactively search for attacker activity that automated alerts have not flagged, directly targeting hidden dwell.
- Extended Detection and Response (XDR) tools unify telemetry across endpoints, identity, and cloud so analysts can spot lateral movement faster.
- Honeypots and deception technology can cut dwell time sharply by triggering an alert the moment an attacker touches a decoy asset.