Conifers’ analysis of 14,652 detections finds nearly half of deployed detections don’t work as intended, and the problem extends far beyond the SIEM into every layer of the security stack
DALLAS and TEL AVIV, Israel, Sept. 24, 2026 /PRNewswire/ — Conifers, developer of the CognitiveSOC™ agentic AI SOC platform, today released The Detection Blind Spot, a new research report based on an analysis of 14,652 detections in live enterprise environments. The security industry has treated detection volume, including rules deployed and tools onboarded, as a measure for detection strength. Conifers’ research suggests that assumption is masking a much larger problem.
Detection gaps are not new but the speed and scale at which agentic adversaries can find and exploit them is. That makes reliable, continuously validated detections more important than ever, yet many detection programs still rely on manual tuning, periodic reviews, or, too often, no review at all.
Across the environments studied, organizations had working detections, hunts or compensating visibility for only 63% of the threats they had identified as relevant. More than a third of the threats organizations already know are coming at them have no corresponding operational coverage to defend against them. Coverage extended to only 64% of the MITRE ATT&CK® techniques relevant to each environment. The findings reveal an operationalization gap between the threats organizations know matter and the working detections in place to find them.
The research also found that 47% of detections required attention before they could be trusted to work as intended. Yet these detections could still appear as deployed or healthy in traditional inventory-based reporting.
The issues fell into five primary categories, including logic issues that prevented detections from firing correctly; missing telemetry caused by data sources that stopped flowing or were never onboarded; queries pointed at the wrong data tables; duplicate detections that increased alert volume without improving coverage; and noisy detections that fired so frequently or imprecisely that analysts learned to ignore them.
Efforts to validate detection quality have traditionally focused on the SIEM because those rules are directly visible and editable by security teams. But SIEM rules represent only one source of the detections entering the SOC queue. Endpoint, cloud, identity, email, and network security products each generate their own vendor-authored detections. When a vendor-owned detection is noisy or ineffective, security teams often cannot fix the underlying logic. They are left to suppress it, accept the blind spot, or allow the noise to continue until analysts begin tuning it out.
“The underlying problem with threat detection isn’t that detections were poorly written. It’s that the telemetry beneath them changes, making detections stale and ineffective without anyone realizing it. That creates a real blind spot,” said Rutger de Boer, CTO at DTX. “Conifers’ research validates what we see with our customers every day: continuous detection validation is becoming a foundational function of the modern SOC. By continuously testing detections at scale, organizations gain confidence in their security posture while significantly reducing the manual effort required from analysts, improving both effectiveness and operational efficiency.”
“For years, the industry has measured detection strength by counting rules and tools. But deployed is not the same as protected,” said Tom Findling, CEO and co-founder of Conifers. “As agentic adversaries compress the time defenders have to adapt, security teams need to know which detections work, which threats remain uncovered, and how quickly intelligence becomes protection. That requires threat intelligence, exposure data, hunting, and detection engineering to operate as one continuous system, not as siloed functions connected by tickets and quarterly reviews.”
The report outlines six actions security leaders can take to close the gap: measure coverage through verified working detections mapped to the threats and techniques relevant to the organization, rather than raw detection counts; extend detection health management beyond the SIEM to include vendor-managed detections that security teams cannot directly edit; establish a control point that tunes, deduplicates, and suppresses detections across tools before they reach the analyst queue; track intelligence operationalization, including the time between identifying a relevant threat and deploying a verified working detection; anchor threat hunting in exposure data and the organization’s crown-jewel assets; and feed relevant, validated hunt findings back into detection engineering to improve coverage.
The full report, The Detection Blind Spot, is available at: https://www.conifers.ai/white-papers/the-detection-blind-spot/.
About Conifers
Conifers builds CognitiveSOC™, the agentic AI SOC platform that powers Resilient Cyber Defense. It connects threat intelligence, threat hunting, detection engineering, investigation, and remediation as one adaptive system on top of the security tools organizations already own. Organizations use CognitiveSOC to evolve their existing security operations into a continuously adapting operating layer capable of keeping pace with the frontier model era. Learn more at conifers.ai.
Learn more at www.conifers.ai.
Media Contact:
Rachel Glaser
White City PR for Conifers [email protected]
SOURCE Conifers Inc





