Dwell Time
In cybersecurity, dwell time is the length of time a malicious actor has access to a compromised system before the intrusion is detected. In simple terms, it measures how long an attacker goes unnoticed inside an environment. Shorter dwell time generally reflects stronger detection capabilities, since the attacker has less opportunity to cause harm before being discovered.
Dwell time typically denotes the interval between an attacker's initial compromise of a system or environment and the point at which the threat is detected. The evidence provided defines it as the amount of time a malicious actor has access to a compromised system before a threat is detected. Note that dwell time is also used outside cybersecurity in fields such as retail, transportation, logistics, out-of-home advertising, and SEO, where it refers to the duration a person, vehicle, or visitor spends in a location, viewing content, or on a page; these usages should not be conflated with the security meaning. Because the evidence packet does not specify accepted start and end points beyond compromise-to-detection or enumerate common variants, practitioners should confirm the precise measurement boundaries used by a given source or vendor rather than assuming a single industry-standard definition.
Why it matters
Dwell time is one of the most telling indicators of how effective an organization's detection capabilities really are. As the evidence describes, it measures how long a malicious actor has access to a compromised system before a threat is detected. The longer an attacker remains undetected, the more opportunity they have to move laterally, escalate privileges, exfiltrate data, or establish persistence. A short dwell time generally reflects stronger detection, while a long dwell time suggests gaps in monitoring, logging, or alerting that allow an intrusion to go unnoticed.
From a security leadership perspective, dwell time is useful precisely because it reframes security as a question of detection speed rather than prevention alone. No control set eliminates the possibility of compromise, so the practical question becomes how quickly an intrusion is discovered once it occurs. Tracking dwell time over time can help leaders assess whether investments in detection and response are improving outcomes, and it provides a business-relevant way to discuss risk with executives and boards who may not engage with more technical metrics.
Because the term is used differently across industries, care is warranted when interpreting figures. As the evidence shows, dwell time also refers to how long a person spends in a retail location, how long a shipping vehicle sits at a facility, how long someone views an out-of-home ad, or how long a visitor stays on a webpage before returning to search results. These usages should not be conflated with the cybersecurity meaning. Practitioners should also confirm the exact measurement boundaries a given source or vendor uses, since the evidence does not establish a single industry-standard definition beyond the compromise-to-detection interval.
Who it's relevant to
Inside Dwell Time
Common questions
Answers to the questions practitioners most commonly ask about Dwell Time.