- What counts
- Distinct non-ransomware malware artifacts found inside backup data, cloud storage, and replicated volumes. Includes trojans, backdoors, rootkits, and cryptominers. Reported separately because detection outcomes differ from ransomware.
- What does not count
- Ransomware artifacts, which are counted above. Duplicates across snapshots of the same source asset.
- Context
- These artifacts were undetected by endpoint protection and backup vendor detection. They had survived replication cycles and backup rotations. Without detection at the data layer, they would have been restored into a production environment during recovery.