Saturday, April 13, 2024

Most Enterprise SIEMs Fail Against MITRE ATT&CK Tactics

SIEM (Security Incident and Event Management) tools are being used in most organizations for monitoring, analyzing, and preventing threat actors.

Organizations are trying to build more and more in terms of security to protect against ransomware attacks, data breaches, and many other types of cybercriminal activities.

However, Security is a continuous process. These SIEM tools can help prevent threat actors only to a certain extent.

The detection mechanisms of SIEMs are far less when compared to the sophisticated attacks that threat actors use to infiltrate organizations.


MITRE has nearly 194 techniques in its framework, which are taken as a baseline for building SIEM tools.

According to report from Cardinalops, Enterprise SIEMs are covering only 24% of detections of the overall MITRE attack techniques.

Image: Enterprise security. Source: CardinalOps

Enterprise SIEMs currently have enough data to cover these techniques, which accounts for nearly 94% of all the MITRE ATT&CK techniques that only need a scale-up for detecting much faster and more efficiently.

The report also indicated that 12% of all the SIEM rules that are currently built are broken due to misconfigured data sources and missing field elements.

According to RedHat reports, Organisations using containers account for more than 68%. However, container security lags a lot, with only 32% in detection.

Common Security Layers

Most of the common security layers covered by SIEM are,

  1. Windows – 96%
  2. Network – 96%
  3. IAM – 96%
  4. Linux/Mac – 87%
  5. Cloud – 83%
  6. Email – 78%
  7. Productivity Suites – 63%
  8. Container – 32%
Image: Most Common Security layers. Source: CardinalOps

The most commonly used SIEMs were Splunk, IBM QRadar, Sentinel, and Sumologic. Analyzing these tools provided over 4000 rules in SIEMs, with the largest SIEM having more than 600 rules. 

The analyzed sectors include financial services, banking, insurance, energy, media and telecommunications, professional & legal services, and MSSP(Managed Security Service Provider) / MDR (Managed Detection and Response).

Recommendations for SIEM

Organizations are advised to review the current SIEM process and check for threats and techniques or behaviors that it is currently missing.

The ad-hoc combination of use case management must include manual pentesting, red teaming, breach and attack simulation tools (BAS), threat intelligence, and much more.

Measure and improve the SIEM with various detecting engineering process approaches in terms of IT management, DevOps, SOC, and other quality metrics that contribute to the security side of the organizations.

With increasing threats day by day, it is necessary for organizations to effectively manage and monitor the threats in every aspect of security. A single loophole can bring the entire organization down.

Hence, Security professionals are advised to take necessary security measures to protect against threat actors.

“AI-based email security measures Protect your business From Email Threats!” – Request a Free Demo.


Latest articles

Alert! Palo Alto RCE Zero-day Vulnerability Actively Exploited in the Wild

In a recent security bulletin, Palo Alto Networks disclosed a critical vulnerability in its...

6-year-old Lighttpd Flaw Impacts Intel And Lenovo Servers

The software supply chain is filled with various challenges, such as untracked security vulnerabilities...

Hackers Employ Deepfake Technology To Impersonate as LastPass CEO

A LastPass employee recently became the target of an attempted fraud involving sophisticated audio...

Sisence Data Breach, CISA Urges To Reset Login Credentials

In response to a recent data breach at Sisense, a provider of data analytics...

DuckDuckGo Launches Privacy Pro: 3-in-1 service With VPN

DuckDuckGo has launched Privacy Pro, a new subscription service that promises to enhance user...

Cyber Attack Surge by 28%:Education Sector at High Risk

In Q1 2024, Check Point Research (CPR) witnessed a notable increase in the average...

Midnight Blizzard’s Microsoft Corporate Email Hack Threatens Federal Agencies: CISA Warns

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive concerning a...
Guru baran
Guru baran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Top 3 SME Attack Vectors

Securing the Top 3 SME Attack Vectors

Cybercriminals are laying siege to small-to-medium enterprises (SMEs) across sectors. 73% of SMEs know they were breached in 2023. The real rate could be closer to 100%.

  • Stolen credentials
  • Phishing
  • Exploitation of vulnerabilities

Related Articles