Detection
Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them
Conifers published The Detection Blind Spot on September 24, based on 14,652 detections in live enterprise environments, and said deployed detection counts are a weak proxy for real coverage.
Ava Okello, DetectionLondon2 min read
DALLAS - Conifers on September 24, 2026, released The Detection Blind Spot, a research report based on an analysis of 14,652 detections in live enterprise environments. In a PR Newswire statement that day, the company said security programs still treat detection volume, including rules deployed and tools onboarded, as a measure of detection strength, and that the study found that assumption masks a larger operational gap.
Across the environments studied, organizations had working detections, hunts, or compensating visibility for only 63 percent of the threats they had already identified as relevant, according to the release. Coverage extended to only 64 percent of the MITRE ATT&CK techniques relevant to each environment. The research also found that 47 percent of detections required attention before they could be trusted to work as intended, even when those detections could still appear as deployed or healthy in traditional inventory-based reporting.
The issues fell into five primary categories named in the release: logic problems that stopped detections from firing correctly; missing telemetry from data sources that stopped flowing or were never onboarded; queries pointed at the wrong data tables; duplicate detections that raised alert volume without improving coverage; and noisy detections that fired so often or so imprecisely that analysts learned to ignore them. The company said validation work has traditionally focused on SIEM rules because those are visible and editable, while endpoint, cloud, identity, email, and network products each contribute vendor-authored detections that security teams often cannot rewrite. When those vendor detections are noisy or ineffective, teams are left to suppress them, accept the blind spot, or live with the noise.
Tom Findling, chief executive and co-founder of Conifers, said in the release that deployed is not the same as protected, and that as agentic adversaries compress the time defenders have to adapt, teams need to know which detections work, which threats remain uncovered, and how quickly intelligence becomes protection.
Rutger de Boer, chief technology officer at DTX, said in the same release that the underlying problem is often telemetry drift that makes detections stale without anyone noticing, and that continuous detection validation is becoming a foundational modern SOC function. The report lists six actions for security leaders: measure coverage through verified working detections mapped to relevant threats and techniques rather than raw rule counts; extend detection health management beyond the SIEM to vendor-managed detections teams cannot edit; establish a control point that tunes, deduplicates, and suppresses detections across tools before they reach analysts; track how long it takes to turn relevant intelligence into a verified working detection; anchor threat hunting in exposure data and crown-jewel assets; and feed validated hunt findings back into detection engineering.
For detection engineering and SOC managers, treat the report as a coverage and health problem rather than a staffing sermon. Priority work is inventorying which rules are verified to fire on current telemetry, separating SIEM-owned logic from vendor-owned detections you can only suppress, measuring false positives, duplicates, and time-to-attention by rule, and closing the gap between threats your intel team already flags as relevant and detections that actually work in production. The full report is posted at conifers.ai under The Detection Blind Spot.
Sources:
Ava Okello covers detection engineering, alert operations, and blue-team signal quality for SOCtember from London.