Imagine that a hospital's electronic health record cluster gets hit on a Friday night. Or, consider if a manufacturer's plant-floor historian is encrypted mid-shift or a regional bank's core transaction database shows the first signs of compromise three weeks after the attacker got in.
In each of these cases, the incident response team eventually asks the same question: which snapshot do we recover from?
That can be a surprisingly difficult question to answer. The most recent snapshot is usually the compromised one. But if you roll back further, you have to discard every transaction, every chart update, every production run recorded between that snapshot and the attack.
For an attacker with weeks of undetected dwell time or an environment with only a handful of retained recovery points, clean and recent can be far apart.
Recovery has never really solved this problem. It has only offered a choice: accept the data loss of rolling back or go through a cumbersome manual process of restoring compromised assets and cleaning them before they can be promoted to the IRE (which can reintroduce malware or attackers).
Rubrik Surgical Recovery eliminates that tradeoff: it delivers the most recent snapshot, recovered clean—without the malware or encryption—rather than the cleanest available copy from further back.
Two Recovery Modes, Different Purposes
Rubrik now offers two distinct ways to recover a compromised snapshot, and the choice belongs to the recovery team, not the tooling:
Forensic Recovery reproduces the snapshot exactly as it was captured, every file, including the quarantined ones, delivered faithfully to the target. Use it when the complete record matters: an active investigation, a legal hold, or a forensic review that needs to see everything the attacker touched.
Surgical Recovery uses that same snapshot but excludes quarantined files from the recovery output. The snapshot is internally sandboxed to remove malicious files, then the normal process restore continues—including mass recovery support via Live Mount or Export.
In both modes, the source backup is immutable and untouched; nothing about the recovery process modifies it.
Different Platforms, Same Clean Principle
Rubrik Surgical Recovery is not a single piece of engineering bolted onto one workload type. It is a principle applied consistently: start with a real system image, identify what the attacker added, exclude it before recovery completes, and deliver a bootable result.
How that principle gets executed depends on the platform's own snapshot architecture:
On VMware, Rubrik resolves the quarantined file paths from its threat detection system in a single batch call. This is one lookup covering every VM in the recovery request, not one call per VM. Before any data reaches the target, Rubrik passes those paths to the recovery engine as exclusions. That engine is the same Live Mount and Export infrastructure customers already run in production every day. Surgical Recovery does not ask the recovery engine to do anything it was not already built to do; it asks it to leave a short list of files out.
On Amazon EC2, the surgery happens inside an isolated clean room. Rubrik Exocompute infrastructure, running in the customer's own AWS environment, creates EBS volumes from the compromised snapshot. It then mounts them read-write in a surgical cleaner pod, removes the quarantined files, and takes a fresh AWS snapshot of the cleaned volumes. Recovery then runs from that clean snapshot. The original snapshot is never touched and no target needs to exist ahead of time.
Two different platforms with different mechanics, but with the same guarantee: a bootable system, delivered to the target, with the threat excluded. No need to rollback to a stale recovery point. No file-by-file assembly that leaves OS state, registry entries, or application configuration for someone else to reconstruct later.
Operate on Existing Infrastructure
EC2 and VMware Surgical Recovery are built on the existing recovery engines such as Export and Live Mount. EC2 Surgical Recovery runs on Exocompute, the same managed compute Rubrik already uses for cloud-native backup and archival. VMware Surgical Recovery leverages Rubrik Secure Vault appliances.
Under incident pressure, that distinction is not academic. This capability needs to be effective on day one, so it’s safer to build on infrastructure that has years of production hours behind it rather than building on something new.
Surgical Recovery is also fail-closed by design. If the quarantine catalog is unreachable or the exclusion step cannot be completed, the request errors immediately rather than silently falling back to a recovery that includes the quarantined files. This way, the recovery team always knows exactly what it is getting.
What's Available Now and What's Coming Soon
Rubrik Surgical Recovery is generally available today for VMware VMs, with file-level and image-level recovery through live mount and export supporting up to 100 VMs in a single recovery workflow. It is also available for Amazon EC2 instances, through export and restore-in-place. This first phase covers the majority of real-world ransomware scenarios, since most malware arrives as net-new files rather than overwriting what was already there.
Surgical Recovery will soon extend to more sophisticated attack patterns: recovery-time replacement of files an attacker commandeered by overwriting them, and recovery-time substitution of files encrypted in place.
The goal of cyber recovery has always been to get back to operational with the least possible data loss. Surgical Recovery reframes what that goal can mean in practice: recovery no longer means choosing between the cleanest available copy and the most recent one. It means recovering clean from the most recent snapshot.
Ready to learn more? Schedule a demo.