Threat Detection Blind Spots
Known Bad IPs: Blocked. Valid Credentials Used. SMB Lateral Movement: Detected. Admin Tools Used.
6 min read · 19 May 2026 · Security
A logistics software vendor's SOC operated a mature detection engineering programme , over three hundred correlation rules in their Splunk SIEM, tuned over four years of operation, with false positive rates that the team was proud of. The rules had been developed from threat intelligence feeds, red team exercise findings, and MITRE ATT&CK mappings to the most commonly observed attack techniques. When a nation-state group targeted the vendor as part of a supply chain campaign, the campaign deliberately used techniques that circumvented every detection category the vendor's rules addressed. Authentication events came from legitimate Azure IP ranges , the blocklist-based detection had no flag. The initial access used credentials obtained through a third-party breach database , no authentication failure pattern, no brute force detection, no impossible travel because the attacker used a VPN exit node in the target's city. Lateral movement used Windows Management Instrumentation and PsExec with valid admin credentials , no SMB anomaly, no pass-the-hash, no unusual protocol. Data staging used native cloud storage tools , no DLP rule trigger, no unusual volume on anomaly rules calibrated to an earlier baseline. The attacker spent forty-seven days in the vendor's environment. Zero SIEM alerts. The detection programme was mature and rule-saturated. The attackers had studied the rules and used only techniques the rules did not cover.
What are Threat Detection Blind Spots, Really?
Threat detection blind spots are the gaps in a security monitoring programme's ability to detect attack activity , the attack techniques, attacker behaviours, and malicious activity patterns that the monitoring programme's current detection logic does not identify as anomalous or malicious. Every detection programme has blind spots: detection rules are designed from known attack patterns, threat intelligence about observed adversary techniques, and historical incident data. Attackers who understand the detection programme's rules can deliberately operate within the blind spots , using techniques not covered by existing rules, exploiting legitimate functionality in ways that are not detected as malicious, and operating at speeds and volumes below detection thresholds.
The living-off-the-land problem is the most prevalent modern detection blind spot category. Living-off-the-land (LotL) attacks use legitimate operating system tools, administrative utilities, and built-in functionality for malicious purposes , WMI, PowerShell, PsExec, BITSAdmin, and similar tools that are present on every Windows system and used regularly by IT administrators for legitimate purposes. Detection rules that flag these tools as suspicious generate high false positive rates due to their legitimate use, so rules are typically calibrated with behavioural qualifications that reduce false positives , but simultaneously create blind spots for attackers who can execute LotL techniques within the behavioural envelope that the detection rules exclude.
The threshold-calibrated blind spot is a secondary and insidious problem. Detection thresholds that trigger alerts above defined volumes , one hundred failed authentications per hour, data transfer volumes above defined baselines, API call rates above defined limits , create below-threshold operational space where attackers who know the thresholds can operate indefinitely without triggering alerts. Patient attackers who operate slowly, distribute activity across time and sources, and stay below every individual threshold can complete sophisticated operations in environments with extensive threshold-based detection.
- Living-off-the-land technique evasion , legitimate admin tools used maliciously outside detection rules
- Threshold-calibrated blind spots , attacker operating below all detection thresholds
- Valid credential use , no authentication failure indicators despite malicious activity
- Legitimate infrastructure use , traffic from valid cloud IP ranges bypassing IP-based detection
- Detection rule set designed for yesterday's techniques , advanced adversaries using current unpublished techniques
Why this matters
Threat detection blind spots matter for TPRM because a vendor's detection capability assessment typically confirms the existence and configuration of the detection programme rather than testing its effectiveness against realistic current attack techniques. A vendor with three hundred tuned SIEM rules has confirmed detection coverage for three hundred documented attack patterns. Whether those three hundred patterns represent the attack techniques that the vendor's actual adversaries , state-sponsored groups, sophisticated ransomware operators, and supply chain attackers , are currently using is a different question that rule count and tuning cadence do not answer.
The red team exercise gap is the specific assessment limitation. Detection effectiveness can only be validated through adversarial simulation , red team exercises, purple team engagements, or breach and attack simulation that tests whether the detection programme fires on realistic attack techniques. A vendor whose red team exercises test the same documented techniques that the detection rules were written to detect confirms that the rules fire on known techniques. Red team exercises that use current adversary techniques , including living-off-the-land, valid credential use, and below-threshold activity , test whether the detection programme covers the actual threat landscape.
Where most teams get this wrong
The most consistent failure is accepting detection programme maturity metrics , rule count, tuning cadence, false positive rates , as proxies for detection effectiveness against current threats. Maturity metrics describe programme quality for known techniques. Effectiveness testing describes whether the programme detects current attack techniques.
- Detection maturity accepted without effectiveness testing
- Red team exercises testing documented techniques not current adversary behaviour
- No ATT&CK coverage gap assessment for most relevant threat actors
- Living-off-the-land detection not specifically assessed
- Threshold-calibrated blind spot testing absent
What good looks like
Mature threat detection programmes conduct purple team exercises using current adversary techniques , specifically testing living-off-the-land detection, valid credential use scenarios, and below-threshold activity , and maintain ATT&CK coverage mapping that identifies techniques with no current detection coverage.
- Purple team exercises testing current adversary techniques not just documented patterns
- ATT&CK coverage mapping , which techniques have detection coverage, which do not
- Living-off-the-land detection specifically assessed and improved
- Threshold calibration testing , attack simulation at various speeds and volumes
- Detection engineering roadmap , known gaps and timeline for coverage improvement
Tooling
Breach and Attack Simulation , AttackIQ, SafeBreach, Cymulate
Breach and attack simulation platforms continuously test detection coverage against mapped adversary techniques , providing ongoing coverage assessment beyond periodic red team exercises. For TPRM practitioners, asking whether the vendor uses BAS for continuous detection coverage testing provides a specific effectiveness validation question.
MITRE ATT&CK Navigator
ATT&CK Navigator provides visualisation of detection coverage against the ATT&CK framework , identifying which technique categories have coverage and which are blind spots. For TPRM practitioners, asking vendors to provide their ATT&CK coverage map provides a specific detection gap disclosure request.
Governance challenges
The governance challenge with detection blind spots is that they are unknown unknowns , the vendor's SOC may not know which current adversary techniques their rules do not cover until an exercise or an incident reveals the gap. The governance resolution is regular adversarial testing with current techniques rather than documentation-based detection maturity assessment.
- Ask about purple team exercise findings , what techniques were not detected
- Request ATT&CK coverage map , which technique categories have coverage
- Ask about living-off-the-land detection specifically
- Ask about BAS deployment for continuous coverage testing
- Ask about last adversarial exercise that specifically tested detection against LotL techniques
If you are a small team
Ask your highest-risk vendor two questions about their last adversarial testing exercise. First: did the exercise specifically use living-off-the-land techniques , WMI, PsExec, PowerShell with valid credentials , and if so, how many of those techniques were detected by the SIEM? Second: what percentage of MITRE ATT&CK techniques relevant to their most likely threat actors are currently covered by their detection rules? Those two questions reveal whether the detection programme was tested against realistic current techniques or only against the documented patterns the rules were designed to detect.
- Ask whether last adversarial exercise used living-off-the-land techniques
- Ask how many LotL techniques were detected
- Request ATT&CK coverage percentage for most likely threat actors
- Ask whether BAS provides continuous coverage testing
What to require
Ask directly:
"In your most recent red team or purple team exercise , were living-off-the-land techniques such as WMI lateral movement with valid credentials used, and how many of those techniques generated SIEM alerts? And do you have an ATT&CK coverage map that shows which technique categories your current rules cover?"
Expect as evidence
- Red team or purple team exercise methodology , whether LotL techniques were included
- Detection rate for LotL techniques in last exercise
- ATT&CK coverage map or coverage percentage
- BAS deployment confirmation
A vendor with three hundred detection rules should be asked what percentage of MITRE ATT&CK techniques those rules cover , and specifically whether living-off-the-land techniques are in that coverage. Rule count describes volume. Coverage maps describe effectiveness.
How to evidence it
- Purple team exercise records with technique coverage
- ATT&CK coverage map documentation
- Living-off-the-land detection assessment
- BAS deployment confirmation
Key Takeaway
Three hundred rules. Forty-seven days of undetected activity. The rules covered every documented technique the detection engineering team had encountered. The attacker used every technique the rules did not cover. Rule saturation is not the same as detection coverage. Coverage is the fraction of relevant adversary techniques for which detection logic exists. Three hundred rules can have zero coverage for the techniques a specific adversary uses. Map coverage to ATT&CK. Test with current adversary techniques. Specifically test living-off-the-land. The rules are the known. The blind spot is what the adversary knows that the rules do not.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association