Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

SIEM coverage versus volume: what detection teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: A study across more than 13,000 detection rules and 2.5 million log sources found enterprises could technically cover 90% of MITRE ATT&CK techniques, yet their actual coverage was only 22%, with 10% of deployed rules broken, according to Gurucul. The real constraint is routing, normalization, and enrichment, not raw telemetry volume.

NHIMG editorial — based on content published by Gurucul: Most enterprises already collect enough data to cover 90% of the MITRE ATT&CK framework. They cover 22%

By the numbers:

Questions worth separating out

Q: How should security teams improve SIEM coverage without simply ingesting more data?

A: Start by mapping each data source to the detections it actually enables.

Q: Why do organisations still miss attacks even when they collect plenty of telemetry?

A: Because collection is not the same as detection readiness.

Q: What do security teams get wrong about log management?

A: Teams often treat logging as a data plumbing task and overlook the identity controls around it.

Practitioner guidance

  • Audit detections against source usability Inventory the top log sources, then map each one to the rules and ATT&CK techniques that depend on it.
  • Separate routing from dropping Use deduplication and conditional routing to move low-signal telemetry into lower-cost storage while keeping a searchable copy for hunts and investigations.
  • Enrich identity logs before analytics Attach identity, asset, entitlement, and threat context at the pipeline layer so authentication and cloud events arrive ready for behavioural analysis.

What's in the full article

Gurucul's full blog covers the operational detail this post intentionally leaves for the source:

  • Per-source reduction logic for common telemetry classes, including cloud control plane, Windows Security, DNS, firewall, and proxy logs
  • The six-stage pipeline sequence showing where optimization sits before normalization and enrichment
  • Examples of how routing, deduplication, and drop behave differently in live log streams
  • Source-level statistics that show which telemetry classes contribute most to cost reduction and preserved coverage

👉 Read Gurucul's analysis of why SIEM detection gaps are a routing problem →

SIEM coverage versus volume: what detection teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Coverage without usable routing is a false sense of control. Organisations often interpret ingest volume as maturity, but this article shows that data can exist in abundance while detections remain sparse or broken. That gap is especially relevant in identity-heavy environments where authentication, access, and workload logs must be normalized before they can support monitoring. The practitioner lesson is to measure detection readiness by source usability, not by raw terabytes.

A question worth separating out:

Q: How can SOC teams measure whether SIEM modernisation is working?

A: Use operational measures, not just deployment status. Track time to search, time to correlate, number of identity-relevant detections, and whether the platform can support investigations without workarounds. If analysts still export data into side tools to understand access abuse, modernisation has not yet delivered the intended value.

👉 Read our full editorial: SIEM detection gaps are a routing problem, not a data problem



   
ReplyQuote
Share: