Threat Detection Dashboards Can Hide Security Coverage Gaps

· Original article ↗

Summary

Conifers assessed 14,652 detections and found that 47% in the average organization need attention. Organizations averaged 63% coverage of relevant threats and 64% protection for relevant MITRE ATT&CK techniques.

Key points

  • Conifers reviewed 14,652 customer detections across SIEM, endpoint, cloud, identity, email and network tools.
  • In the average organization, 47% of detections needed attention, despite appearing deployed on coverage dashboards.
  • Reported failure causes include logic bugs, missing telemetry, querying the wrong data source, duplicate rules and excessive false alerts.
  • Vendor-managed detections can be difficult for security teams to inspect or edit, forcing a choice between tolerating noisy alerts and suppressing them.
  • Organizations had detections, hunts or compensating visibility for an average of 63% of threats their own intelligence identified as relevant.
  • Average protection covered 64% of relevant MITRE ATT&CK techniques, leaving about one-third without reliable detection. The article advocates automating parts of the threat-intelligence-to-detection process with AI.

Article Details

Publisher
Help Net Security
Scope
Conifers assessment of customer detections across SIEM, endpoint, cloud, identity, email, and network tools.
Sample Size
14,652 detections in Conifers' customer base; number of organizations not disclosed.
Key Statistics
  • Conifers found that 47% of detections in the average organization needed attention.
  • Organizations averaged coverage for 63% of threats their own intelligence identified as relevant.
  • Average protection was 64% for MITRE ATT&CK techniques relevant to each organization.
Recommendations
  • Continuously test whether deployed detections work, including whether required telemetry is available.
  • Identify threats without matching detections, hunts, or compensating visibility.
  • Connect threat intelligence to detection and hunting workflows to reduce the delay between identifying a threat and establishing coverage.