The hypervisor landscape is no longer VMware by default. Enterprises are running Nutanix, Hyper-V, Azure Local, Red Hat OpenShift, OpenStack, and OLVM, sometimes several at once. This makes perfect sense: infrastructure diversification can help match the right technologies with changing workload requirements, cost pressures, and vendor strategies.
This is hypervisor modernization in its truest form: not a one-time event, but an ongoing evolution of your compute estate.
Getting data protection coverage in place on a new hypervisor is table stakes and most teams get there. But diversification comes with a challenge most teams don't anticipate: are you watching what's happening inside those protected workloads?
Coverage without visibility creates a dangerous dynamic: you might be faithfully backing up data that's already compromised. You might be restoring clean-looking files that carry hidden threats. You might have sensitive data sitting undetected in your VM backups for months—and have no idea until a regulator or attacker tells you.
Backup alone is not enough. The backup pipeline needs to be threat-aware.
Data Threat Analytics for Your Virtualized Environment
Rubrik Data Threat Analytics (DTA) turns the backup pipeline into a continuous threat intelligence layer. Rubrik sees every workload, so it captures every change and stores every version of your data. In that way, Rubrik is uniquely positioned to provide an additional perspective for detecting threats from within, without replacing your endpoint detection and response, integrating with your security information and event management or security orchestration, automation and response, and without impacting your production workloads.
For hypervisor environments specifically, this matters more than most teams realize. Every VM that spins up across your estate is automatically within DTA's scope as soon as a backup is taken. There is no per-hypervisor configuration, no secondary scanning infrastructure to deploy, and no gap between when a workload is protected and when it is being watched. Anomaly detection, sensitive data discovery, threat hunting, and threat monitoring all run natively inside the backup pipeline across every supported hypervisor—consistently, continuously, and without adding operational overhead to your team.
How It Works: Inside the Pipeline
The reason DTA works at this depth is architectural. Traditional backup tools operate on a full-trust model: backup software writes to a separate storage target and the two share no real context.
Rubrik fundamentally changed this by combining backup software and storage into a single platform, with data and metadata co-located. That architecture is what makes it possible to build the data threat engine natively into the same software, not layered on top after the fact.
Here is how it flows from snapshot to signal:
Step 1 - Snapshot Ingestion: Rubrik takes a VM backup and writes it to its proprietary, append-only file system—immutable by design, protected by logical air gap with no agent on the VM and no impact to production workloads.
Step 2 - Metadata Indexing and Fingerprinting: As the snapshot is ingested, Rubrik indexes file system metadata: file counts, sizes, types and modification timestamps. This builds a behavioral baseline for each workload. Every subsequent snapshot refines the model, making anomaly detection progressively more precise.
Step 3 - Anomaly Detection: The 2-stage ML model runs automatically against every snapshot. Stage 1 detects file-level anomalies—deletions, additions, or modifications far outside the workload's established baseline. Stage 2 runs entropy analysis to identify encryption patterns consistent with ransomware.
Step 4 - Threat Monitoring: Data surveillance runs continuously alongside the other operations, matching each backuped up file against a curated intelligence feed in near real time. Multiple threat intelligence feeds are supported (not just Rubrik's built-in feed) and results from treat monitoring are cataloged, which improves the performance of threat hunting.
Step 5 - Sensitive Data Discovery: In parallel, the data discovery and classification engine inspects file data within the snapshot, classifying sensitive data patterns. This runs entirely against the immutable backup copy. Production is never touched
Step 6 - Alert, Investigate, Recover: The results are surfaced in the Rubrik Security Cloud console. Security teams can drill into the snapshot, trace the anomaly timeline across prior backups, identify the last clean recovery point, and initiate recovery without switching tools or re-importing data. Rubrik takes an API-first approach and has native integrations with many of the most popular security tools, so detection surfaces where your security team already works. Detection and recovery action live in the same workflow: no handoff is necessary, so you experience no delay.
Every step runs entirely on the same Rubrik nodes that handle your backup—same platform, zero extra footprint. No additional infrastructure is required, no separate scanning appliance is necessary, and there is zero production impact. The moment you protect a workload, you are already watching it.
Expanding DTA Coverage, Now Including OpenStack and OLVM
Data Threat Analytics is available today for platforms where the majority of hypervisor modernization is happening right now—VMware, Nutanix AHV/NC2, Hyper-V, Azure Local, and Red Hat OpenShift Virtualization. We are pleased to share that the full Data Threat Analytics suite is now generally available for OpenStack and OLVM.
This matters beyond breadth. OpenStack and OLVM are disproportionately deployed in financial services, telecommunications, and public sector environments—industries where sensitive data discovery and threat hunting are not optional features. They are audit requirements and compliance mandates. Customers in these industries now have the same depth of threat intelligence and detection that any other Rubrik-supported platform delivers, with no trade-off by hypervisor choice.
That is the point. No matter which hypervisor you choose or how many you run, your security posture should not be a function of that choice. Rubrik Data Threat Analytics follows your workload, across every platform.
Ready to see Data Threat Analytics in action? Watch this on-demand webinar and see how Rubrik detects, hunts, and recovers—across every hypervisor you run.
Any unreleased services or features referenced in this document are not currently available and may not be made generally available on time or at all, as may be determined in our sole discretion. Any such referenced services or features do not represent promises to deliver, commitments, or obligations of Rubrik, Inc. and may not be incorporated into any contract. Customers should make their purchase decisions based upon services and features that are currently generally available.