
Work Here?
Stairwell offers a cloud-based platform for automated threat detection and response by analyzing software binaries via static and dynamic analysis. It uses a library of over 4,200 YARA rules and lets security teams build custom queries to hunt threats across all files without endpoint bottlenecks. The platform runs continuously in the cloud, scalable across small to large organizations, enabling faster triage and reducing investigation costs. Stairwell aims to empower security teams, shorten threat-hunting and incident-response timelines, and cut the cost of threat assessments by providing clear visibility and reference data.
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
51-200
Company Stage
Series B
Total Funding
$69.5M
Headquarters
Mountain View, California
Founded
2019
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$69.5M
Above
Industry Average
Funded Over
3 Rounds
Industry standards
Stock Options
Stairwell has launched Backstory, an agentic investigation platform that maps malware blast radius in seconds. The platform traces related malware variants, identifies affected systems, and shows the full scope of incidents to help enterprises contain threats quickly. The launch follows Stairwell's Hidden Malware Report, which analysed 1,085 public threat reports and found that every published malware hash represents an average of 2.4 additional malicious variants — uncovering over 46,000 related files not included in original research. Backstory is powered by Stairwell's architecture, which continuously collects and preserves executable files from customer endpoints. The platform is built on a corpus of over 1.5 billion executable files, AI trained on more than 110,000 detection rules, intelligence from over 20 threat sources, and more than 8.7 billion historical rule matches. Stairwell will showcase Backstory at Black Hat USA.
Stairwell launches Backstory, the first agentic investigation platform for malware blast radius. Stairwell analysis finds 2.4 related malware variants for each sample named in public threat reports; confirms security teams lack true depth of malicious files across their environment. SUNNYVALE, Calif., July 29, 2026 (GLOBE NEWSWIRE) - Stairwell, the AI SOC that stops breaches no one else can, today announced the availability of Backstory, an agentic investigation platform that traces related malware variants, identifies affected systems, and maps the full blast radius of an incident in seconds, so enterprises know what happened, where it spread, and what needs to be contained before precious time is lost. AI-generated malware is making it easier for attackers to create new variants, and legacy alert-based tools are struggling to keep up. Many AI security operations tools focus on reducing noise and speeding up triage. Backstory focuses on reducing risk by showing what actually exists within the environment, where it spread, and exactly what needs to be contained. The launch comes as Stairwell's new Hidden Malware Report finds malware families are far larger than public reporting suggests. Across 1,085 public threat reports, Stairwell found that every published malware hash represents an average of 2.4 additional malicious variants, uncovering more than 46,000 related malicious files that were not included in the original research. The data suggests defenders routinely investigate only a fraction of an attack. While public reporting typically focuses on a single malware sample, Stairwell uncovered an average of 2.4 related variants connected to every published sample. Because these variants often differ just enough to evade traditional hash- and signature-based detection, enterprises may unknowingly leave related malware active inside their environments. "Closing tickets faster does not mean you contained the threat," said Mike Wiacek, founder and CTO of Stairwell. "When a team finds something malicious, the real question is not just, 'Can I close this alert?' It's, 'What else looks like it, where did it land, how long has it been here, and what do I need to do to contain it?' Backstory gives every team that level of investigation, regardless of headcount." "Attackers can test against global threat intel, EDR, and every common Yara rule on the internet," said Jeff Moore, Chief Security Officer, H&M Group. "What they can't test against is your environment because they've never seen it. That's the whole game. Stop asking 'what's bad out there?' an infinite question you will always lose and start asking 'what changed in here?' It's not a new idea. It's just the honest one." "Backstory gives us visibility beyond the first alert," said Michael Francess, Director Cybersecurity, at a Global Hotel Brand. "We get the full blast radius of an incident: are we affected, how far did it spread, and have we actually contained it? Because Stairwell retains all of our executable files, every new piece of intelligence is a question we can answer definitively in minutes instead of an investigation we have to start from scratch." Backstory is powered by Stairwell's ground-truth architecture, which continuously collects all executable files from customer endpoints and preserves them in a private customer corpus. Unlike tools that reason primarily over alerts, Stairwell reasons over facts: the actual files that have touched an environment, preserved indefinitely and continuously re-examined as new intelligence arrives. Backstory's foundation is built on: * A continuously preserved corpus of more than 1.5 billion executable files * AI trained on more than 110,000 detection rules * Intelligence from more than 20 public threat sources * More than 8.7 billion historical rule matches This gives Backstory all the historical context needed to find related variants that no other tools can see. Stairwell will showcase Backstory at Black Hat USA at booth 5006. About Stairwell Stairwell is the AI SOC built on ground truth. It reasons through every executable file that has touched an enterprise environment to find threats others miss, investigate them end-to-end, close the loop, and prove what has been contained or remediated. Stairwell preserves file history over time, enabling organizations to re-evaluate their entire environment as new intelligence arrives. Founded by Mike Wiacek, founder of Google's Threat Analysis Group and Alphabet's Chronicle, Stairwell is backed by Sequoia, Accel, and S32, with enterprise customers across financial services, healthcare, fintech, AI, media, and gaming. Learn more at www.stairwell.com.
Sunnyvale, CA - July 29, 2025 - Stairwell, a company that is redefining security using AI-powered signal intelligence focused on an enterprise's files to bring a data search approach to outmaneuver known and unknown malware in seconds, today announced the appointment of Emmy Linder as its new Chief Executive Officer (CEO).
SUNNYVALE, Calif., July 9, 2024 /PRNewswire/ -- Stairwell, a cyber resilience company and provider of AI-powered threat detection and incident response platform, today announced the appointment of Joe DeBlasio as Vice President of Global Sales and Customer Success. Joe will spearhead efforts to refine sales processes and drive strategic planning across all sales activities."With malware constantly evolving to evade the latest detection techniques, enterprises continue to find themselves at a disadvantage," said Mike Wiacek, founder and CEO of Stairwell. "Stairwell was founded on the principle of evasion-resistant architecture to give enterprises an advantage they never had before. Joe's proven track record of building and executing growth strategies will be pivotal in bringing the Stairwell advantage to every enterprise."Stairwell's evasion-resistant architecture allows enterprises to quickly detect cyber attacks that evade other security offerings. With AI-powered real-time analytics, the Stairwell platform instantly applies and derives new learnings from all executables and related artifacts an organization has ever encountered, even those that have been deleted. The cloud-based platform provides unparalleled insights into historical data as well as current and potential malware threats."I couldn't be more excited about joining the Stairwell team," said DeBlasio
SUNNYVALE, Calif., May 23, 2024 /PRNewswire/ -- Stairwell, a cyber resilience company and provider of AI-powered threat detection and incident response solutions, today announced the appointment of John Yun as Vice President of Marketing. Yun will spearhead the company's marketing strategy and amplify Stairwell's presence."Enterprises continue to find themselves reacting to cyber threats and struggling to get ahead," said Mike Wiacek, founder and CEO of Stairwell. "Our goal is to enable enterprises to be cyber resilient before, during, and after cyber attacks - continually strengthening their cyber defenses. John will play a pivotal role in evangelizing the values provided by Stairwell as we continue our growth trajectory."Stairwell's evasion-resistant architecture allows enterprises to swiftly detect cyber attacks that evade other security solutions. The platform offers unparalleled insights into malware and its variants, including previously removed threats. With AI-powered real-time analytics, Stairwell applies advanced detection techniques to an organization's empirical data at scale, providing comprehensive operationalized threat intelligence."What drew me to Stairwell is its innovative approach to threat detection and incident response," said Yun
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Enterprise Software
Cybersecurity
Company Size
51-200
Company Stage
Series B
Total Funding
$69.5M
Headquarters
Mountain View, California
Founded
2019
Find jobs on Simplify and start your career today