Security Monitoring Gaps
ATT&CK Coverage Blindspots
Most environments detect fewer than 20% of MITRE ATT&CK techniques.
What it is
The MITRE ATT&CK framework documents over 600 adversary techniques and sub-techniques across 14 tactics. Most organisations have detection coverage for a small fraction of these — typically the most visible techniques with the most established signatures. Techniques under Defense Evasion (TA0005), Command and Control (TA0011), and Collection (TA0009) are commonly undetected because they require specific log sources or correlation logic that generic SIEM rules do not provide.
Attack techniques
- LOLBin execution evading process monitoring (T1218)
- Encrypted C2 over legitimate protocols (T1071)
- Data staged in unusual locations (T1074)
- Timestomping and log deletion (T1070)
- Living off the land — no malware involved
Business impact
Attackers who understand common detection gaps deliberately use the techniques least likely to be detected. Operating only on well-known detection signals creates a predictable blind spot.