A new report from detection engineering vendor Conifers, based on an analysis of 14,652 individual detections deployed across live enterprise environments, found that 47 percent needed attention before they would actually fire as intended, and that organizations averaged working coverage for only 63 percent of the threats their own threat intelligence had flagged as relevant. Announced via PR Newswire on September 24, the report, titled “The Detection Blind Spot,” also found coverage extended to only 64 percent of the MITRE ATT&CK techniques organizations considered in scope.
The finding is not that organizations lack detection rules, it is that a rule can look deployed on every dashboard and still never fire when the exact technique it was built for is used. Conifers documented three failure modes: logic bugs where a detection runs but can never trigger because of a wrong operator or a condition that is never true, missing telemetry where the detection queries a data source that stopped flowing or was never onboarded, and detections pointed at the wrong table or index entirely, while still reporting as healthy.
“For years, the industry has measured detection strength by counting rules and tools. But deployed is not the same as protected,” said Tom Findling, CEO and co-founder of Conifers. Rutger de Boer, CTO at DTX, added that the problem is not that detections were poorly written, but that “the telemetry beneath them changes, making detections stale” with no visible signal that they degraded.
The original insight for a SOC leader is that a dashboard measuring “detections deployed” answers a different question than “threats detected,” and the two numbers can diverge for months with no alert telling anyone it happened. CyberTech’s prior reporting on CISA’s own exercise finding one of two tested SOCs failed to detect the intrusion it was built to catch and on a human attacker who slipped past a detection trap built for automated speed point to the same root cause Conifers is now putting a number on.
Source: PR Newswire