Stairwell's CTO Built Backstory Around One Question: What's Never Been Seen Before

Stairwell's CTO Built Backstory Around One Question: What's Never Been Seen Before

BackerLeader 44 236 410
calendar_today agoschedule4 min read

In 2010, Mike Wiacek was helping lead Google's response to Operation Aurora, the nation-state attack that hit Google and dozens of other companies. At the time, threat intelligence wasn't even a real job category yet. Wiacek says Google wouldn't let him post a job listing asking for candidates with intelligence backgrounds.

That gap is where Stairwell started. Sixteen years, a stint building Chronicle, and one acquisition of VirusTotal later, Wiacek's company has launched Backstory, an agentic investigation platform designed to answer a question most security tools still can't: once you find one piece of malware, what else is out there that looks like it, and how far has it spread?

The problem with logs

Wiacek's argument starts with a flaw he says the entire industry has quietly accepted. Most detection tools are built on logs, and logs only show you activity, not the files themselves.

"Logs are like a CCTV camera that's looking down a hallway in one direction," Wiacek said. Anyone who's watched a heist movie knows how easy that camera is to dodge.

Stairwell's answer is to skip logs and go straight to the source: collect a copy of every executable, driver, and script that touches an enterprise's machines, and store it indefinitely. Wiacek calls it ground-truth data. It lets a security team ask a very specific kind of question — does anything in my environment resemble something no one else in the world has ever seen?

He points to Stuxnet as the example that shaped his thinking. One of its core components was a driver signed with Realtek's private key. If you could ask "does my environment have any signed drivers nobody else has ever seen," and the answer came back yes, you'd have found it. As Wiacek put it, a penguin in Antarctica isn't interesting. A penguin in the Sahara is.

Data lake, then a way to use it

Stairwell has been collecting that file-level data for six years. According to Wiacek, the company now tracks roughly 44 billion file sightings across customer environments, backed by trillions of DNS records and billions of Yara rule matches. The hard part was never getting the data. It was making it usable.

Wiacek compares it to being handed a fully equipped operating room, a donor heart, and the best surgeon's tools available — and still not being able to perform a transplant without the training to use them. Backstory is meant to be that missing layer: it takes Stairwell's file corpus and lets a security engineer ask a plain question, like "I found this, what do I need to do next," and get an answer instead of a dashboard.

What the AI actually does

"Agentic" gets attached to a lot of security products right now, and Wiacek is upfront that a lot of the heavy lifting inside Backstory comes from a fairly conventional rules engine, not a language model. Tokens aren't free, so the system leans on rules where rules are enough.

Where the LLM earns its place is pattern recognition across large, messy graphs. Wiacek's example: a piece of malware talks to a command-and-control domain that's resolved to five different IP addresses over time. Map out everything connected to that domain and you can end up with a graph of 500 nodes and edges. A frontier model can spot a pattern buried in that graph — say, that 67% of the time, the traffic touches one specific network before branching out — that would take a human hours to find by hand, if they found it at all.

He's skeptical of vendors who treat AI as a feature to bolt on. "If you don't give AI data that you didn't already have, you're going to get to the same conclusions faster," he said. Same outcome, just quicker. Stairwell's bet is that the file corpus is the part nobody else has, and the AI is only as useful as what it's reasoning over.

Explainability was a recurring theme. Wiacek said every finding in Backstory comes with the detection rules that matched, where the file spread, and anonymized signals showing how many other Stairwell customers have seen something similar — without exposing who they are. The AI's job, in his framing, isn't to declare something bad. It's to interpret facts a human would otherwise have to piece together from what he described as 30 pages of spreadsheets.

The numbers behind the pitch

Wiacek says a full Backstory investigation — triage, checking for similar files across the fleet, threat intel enrichment, and a containment report — runs about 200 to 250 seconds. He argues the alternative, before Backstory, wasn't a slower version of the same process. It often wasn't possible at all without disk-level forensics, which he described as security teams carrying imaging equipment machine to machine, on a timeline measured in weeks.

"Millions of dollars down to a latte," is how he summed up the shift from a Mandiant-style forensic engagement to what Backstory claims to do per alert.

Where this goes next

Asked what comes after blast-radius mapping, Wiacek described wanting to build something closer to a forecast than a report — modeling where a malware family is likely to spread next, the way meteorologists model storm paths, rather than only reconstructing where it's already been. He compared it, only half-joking, to targeted ads that pick up on a pregnancy before the person searching knows themselves. Creepy, in his words. But he thinks the data Stairwell has already collected puts that closer than most people would guess.

His broader point is less about any one feature. It's that defenders are still budgeting the way they did two years ago, while attackers are already using frontier models to accelerate malware development. "The goal cannot be do what we did before, faster," he said. "We have to do it differently, not just better."

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

Cyera: Non-Human Identities Grew 480% in Six Months. Most Companies Have No Idea What They're Doing.

Tom Smithverified - Aug 3

Accenture and Google: AI Agents Didn't Just Cheat on a Safety Test — They Built a Chat Room to Help

Tom Smithverified - Aug 6

Your Backup Data Knows More Than You Think. HYCU aiR Is Finally Asking It the Right Questions.

Tom Smithverified - May 14

Helping Clients Move from Pilot to Production: The Agentic AI Governance Playbook

Tom Smithverified - Jun 8

From Prompts to Goals: The Rise of Outcome-Driven Development

Tom Smithverified - Apr 11
chevron_left
16.3k Points690 Badges
210Posts
123Comments
83Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

5 comments
3 comments
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!