TL;DR: BrickStorm, attributed to UNC5221, shows how attackers can live inside enterprise blind spots for an average of 393 days by targeting appliances, virtualisation layers, and credential paths that traditional endpoint tools miss, according to SafeBreach. The case reinforces that detection gaps and stale trust assumptions, not just malware, determine how long espionage campaigns can persist.
NHIMG editorial — based on content published by SafeBreach: The Next-Level Threat: Defending Against BrickStorm and the 393-Day Dwell Time
By the numbers:
- the astonishing average time they remain inside a victim’s network before being detected is well over a year, 393 days to be exact
Questions worth separating out
Q: What breaks when attackers can hide in appliance and virtualisation layers?
A: Traditional endpoint-centric detection breaks first, because the malicious activity happens on systems that either cannot host EDR or are not instrumented with enough depth.
Q: Why do management-plane identities create such a large attack surface?
A: Management-plane identities often control hypervisors, backups, orchestration, and directory access at once, so one compromise can unlock many downstream assets.
Q: How do security teams know whether virtualisation blind spots are still open?
A: Look for privileged actions that are not producing matching alerts, such as VM cloning, disk mounting, and unusual control-plane logins.
Practitioner guidance
- Map management-plane blind spots Inventory appliances, hypervisors, and orchestration systems that cannot run EDR, then define compensating log sources and alert paths for each one.
- Harden virtualisation-based credential paths Restrict who can clone virtual machines, mount offline disks, or access hypervisor management functions, and monitor those actions as privileged events.
- Validate dormant persistence after response Run follow-up hunts and re-validation after incident response closes, with special attention to delayed beaconing and long-interval callbacks.
What's in the full article
SafeBreach's full blog covers the operational detail this post intentionally leaves for the source:
- Exact detection test scenarios for identifying offline VM cloning in vCenter and similar control planes
- Examples of network telemetry that should flag suspicious appliance traffic, including DNS over HTTPS from infrastructure that should not generate it
- SafeBreach Exposure Validation Platform guidance for testing whether your environment can detect in-memory credential theft on a vCenter server
- Recommended workflows for validating blind spots in IT and OT environments without relying on endpoint agents
👉 Read SafeBreach’s analysis of the BrickStorm campaign and 393-day dwell time →
BrickStorm and 393-day dwell time: are your controls seeing blind spots?
Explore further
BrickStorm shows that blind spots are now a primary control failure, not an operational inconvenience. When attackers can live on appliances and management planes that EDR cannot see, the security model has already failed at the visibility layer. This changes the governance question from "can we detect malware" to "which trusted systems remain outside our control boundary." For practitioners, the lesson is to treat infrastructure visibility as a first-class security requirement.
A few things that frame the scale:
- only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, according to The State of Non-Human Identity Security.
- Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.
A question worth separating out:
Q: Who is accountable when an attacker persists through trusted infrastructure for months?
A: Accountability usually sits with the teams that own the management plane, identity controls, and incident validation process, not only the endpoint or SOC teams. Frameworks such as NIST CSF and NIST SP 800-53 place responsibility on access control, audit, and continuous monitoring, which is where long-dwell campaigns are decided.
👉 Read our full editorial: BrickStorm exposes the blind spot problem in modern enterprise defense