Long dwell times give attackers the opportunity to conduct reconnaissance, escalate privileges, move laterally, and exfiltrate data before being discovered. Reducing dwell time is a key objective for SOC teams, as earlier detection limits the total damage an attacker can cause. The global average dwell time for breaches has historically been measured in weeks or months, highlighting the importance of proactive detection and threat hunting.