A suspicious process launches, a container behaves unexpectedly, or an identity begins doing something it should not, and a runtime detection fires. The good news is that the security stack has done what it was designed to do: raise the alarm. The trickier part is what happens in the minutes and hours after that alert appears.
This is where the timeline gets uncomfortable. According to one study, organizations take an average of 8.6 hours to activate forensics after an incident, even though many CISOs believe evidence collection should begin immediately. The average investigation does not produce results until 8.5 days after discovery, while CISOs estimate the cost of delay in responding to a known cyberattack at $114,000 per hour.
The real problem, then, has less to do with whether an organization can detect malicious activity and more to do with how quickly detection becomes understanding. That delay is where attackers can keep moving while responders lose evidence, particularly in cloud environments where workloads may disappear long before an analyst reaches the ticket.
Wiz is one of the platforms now moving forensic collection closer to the moment of detection, rather than treating it as a separate investigative step that begins only once an analyst is involved.
What Actually Happens Between Detection and Understanding
A detection is an important signal, but it is rarely the complete story. Knowing that a shell was spawned or an unexpected binary executed does not automatically explain how an attacker arrived there, what happened immediately before the event, which credentials were involved, what systems were reachable, or whether the activity continued elsewhere.
Also Read
Answering those questions traditionally means assembling evidence after the fact. An analyst may need to reconstruct process trees, examine shell or command history, inspect memory, review network connections and system logs, and then correlate those artifacts against identity activity and events elsewhere in the environment.
That work becomes harder in modern cloud infrastructure because the system under investigation may not remain long enough to be investigated conventionally. Containers can be destroyed, processes can exit, and memory-only payloads can disappear without leaving the artifacts an analyst would normally expect to retrieve. By the time triage or escalation begins, short-lived workloads and memory artifacts may already be gone.
This is what the 8.6-hour activation delay ultimately represents. Every hour of it lets potentially useful evidence get older, harder to correlate, or disappear altogether.
Why Waiting for a Human to Start Is the Expensive Part
The $114,000-per-hour cost CISOs impose for delayed response to a known cyberattack is especially revealing because it puts a price on investigation delays specifically.
Once an organization knows something suspicious has happened, every additional hour without a reliable picture creates uncertainty. An attacker may be moving laterally, using compromised credentials, accessing additional data or attempting to obscure earlier activity. Meanwhile, the security team is still trying to establish the scope of the original event.
This changes the role of automated forensic collection. Capturing evidence immediately does more than save analysts a few manual steps; it moves the investigation’s start earlier.
Instead of treating forensics as an activity initiated after an alert has been triaged and assigned, evidence collection can become part of the detection itself. The relevant state is preserved while it still exists, giving the eventual investigator a starting point based on what was happening when the suspicious activity occurred.
That distinction matters because incident response is ultimately constrained by two clocks. One measures how quickly the security team sees suspicious behavior. The other measures how quickly it understands enough of that behavior to make a defensible containment decision. Improving the first without addressing the second leaves a significant part of the problem with the response intact.
How Automated Forensics Changes the Timeline
Automated forensics moves collection forward in that sequence. Rather than requiring an analyst to request evidence after receiving an alert, the security platform captures relevant artifacts at the time of the event.
Increasingly, vendors are also automating parts of the analysis, so the analyst receives structured findings rather than only a raw dataset to work through.
The distinction between solutions is therefore becoming less about whether forensic evidence exists and more about what happens to that evidence between detection and the moment an analyst begins investigating.
Wiz: Evidence Captured and Analyzed Automatically
Wiz Forensics takes an event-driven approach. When a threat detection rule fires, the Wiz Runtime Sensor automatically creates a forensic package, the triggering script or binary, process tree, shell histories, SSH configuration, container drift layer, and system logs, captured before an ephemeral workload has the opportunity to disappear.
Wiz’s Forensics AI Engine then analyzes the package before an analyst manually opens the underlying files, feeding the findings into the Blue Agent’s broader threat investigation, which reconstructs an attack timeline and produces a verdict with supporting evidence.
The Security Graph adds cloud context, identities and permissions, network exposure, resource relationships, and data sensitivity, so investigators can see why the affected workload matters and how an attacker could move through the surrounding environment.
Response can then follow the investigation through cloud-native containment workflows. Wiz documents response capabilities, including workload isolation, credential or permission revocation, network blocking, and process-level containment, with workflows supporting automated execution for appropriate high-confidence scenarios or human approval for sensitive actions.
In practical terms, that model targets both sides of the investigation delay. Evidence collection no longer needs to wait 8.6 hours for someone to initiate it, while automated analysis is intended to reduce the work between having the evidence and producing an actionable conclusion.
Sysdig Secure: Runtime Policy Triggers the Capture Itself
Sysdig Secure approaches the same problem from its runtime monitoring foundation. The platform’s Activity Audit and Forensics capabilities maintain records of user and system activity that can help reconstruct what files were accessed or modified, what commands were executed, and who performed specific actions. Runtime events can also expose an enriched process tree, allowing investigators to trace process lineage and examine related activity around a detection.
Importantly, Sysdig policies can be configured to create a capture when an event occurs, including a defined period before and after the triggering event. This means the forensic starting point can be generated as part of the runtime policy, rather than waiting for an investigator to manually begin collecting evidence.
Sysdig also connects detection with containment. Its response actions include killing processes, pausing or stopping containers, and quarantining suspicious files, while its automation system can execute supported response actions when runtime events meet configured conditions.
The emphasis is therefore on preserving runtime visibility around the event and providing the analyst with an immediate reconstruction path, rather than starting with a blank ticket and rebuilding workload activity from whatever evidence remains.
That focus speaks directly to the activation delay. Because captures are triggered automatically by policy rather than by a person deciding to start one, there’s no equivalent of an 8.6-hour wait built into the process.
Trellix EDR with Forensics: Deep Endpoint Capture, Framework-Mapped
Trellix approaches the problem from the endpoint side, combining EDR telemetry with integrated forensic collection and automated investigation. Its forensic capabilities can capture and store files, memory and process information, as well as disk images, while endpoint snapshots can include active processes, process memory, driver memory, network connections, services, registry keys and autorun entries.
That endpoint-first foundation reflects where Trellix has traditionally focused, on protecting individual devices, and it still gives the product deep visibility even in environments where cloud-native tooling is not the primary control point.
Trellix also automatically maps events within alerts to the MITRE ATT&CK framework. That gives investigators a structured view of observed techniques, rather than requiring them to manually classify every activity before determining where it fits in the attack sequence.
The platform’s Trellix Wise capability extends the automation into investigation by analyzing and correlating threat artifacts, anomalies and techniques. Trellix claims that the system can contextualize alerts and connect related events, reducing the amount of raw evidence an analyst has to interpret independently.
The common thread across Wiz, Sysdig and Trellix is more important than any individual implementation. All three move forensic collection closer to the security event itself, reducing reliance on an analyst to manually initiate the evidence-gathering process. Where they differ is in what happens next: how evidence is correlated, how much analysis is automated, what environmental context is attached, and how directly an investigation can lead to containment.
Conclusion
The 8.6 hours organizations take on average to activate forensics and the 8.5 days required to produce investigation results point to a problem that better detection alone cannot solve. The security team may know that something happened long before it knows what happened, how far it went, and what needs to be contained.
Automated runtime forensics changes that sequence by making evidence collection part of detection rather than a task waiting in an analyst’s queue. In environments where processes, containers, and memory artifacts can disappear quickly, that shift is increasingly fundamental to preserving the evidence an investigation depends on.
At an estimated $114,000 per hour of delayed response, how fast a platform generates an alert matters less than how much of the investigation is already underway by the time a human opens it.
Community Discussion
Join the conversation. Ask questions, share solutions, and help others.
Be the first to start the discussion!
