Back to all lessons
Awareness Lessons
3 months ago

Undetected Threats Linger for Years Due to Monitoring and Response Gaps

Kaspersky's 2025 compromise assessment findings reveal that 60% of security incidents went undetected because organizations lacked high-confidence alerts, allowing threat actors to persist unnoticed for months or even years. The oldest discovered threat had been active for four years, demonstrating how dangerously long dwell times can become when continuous monitoring and proactive threat hunting are absent. Attackers leveraged Living-off-the-Land Binaries (LoLBins) and legitimate remote management tools specifically to evade detection, blending into normal network activity. This matters because extended dwell time dramatically increases the potential damage from data exfiltration, ransomware deployment, and lateral movement across the environment.

Tactical Insight

Immediate Actions

  • Deploy a SIEM or XDR solution tuned to generate high-confidence alerts for anomalous behaviors, including LoLBin abuse and unauthorized remote management tool usage.
  • Conduct an emergency compromise assessment or threat hunt to identify any currently active, undetected threats within the environment.

Detection Measures

  • Establish continuous 24/7 monitoring with defined alert thresholds and escalation paths to ensure no critical signals are missed.
  • Implement behavioral analytics to detect lateral movement, credential misuse, and abuse of legitimate administrative tools such as RMM software.
  • Create detection rules specifically targeting LoLBins (e.g., certutil, mshta, wscript) executing in unusual contexts or from unexpected parent processes.

Long-term Improvements

  • Build a formal threat hunting program with scheduled, hypothesis-driven hunts focused on low-and-slow attacker tactics that evade automated alerting.
  • Define and enforce incident response SLAs that mandate investigation timelines, escalation triggers, and containment deadlines to prevent prolonged dwell times.
  • Regularly review and audit remote management tool usage, whitelisting only approved tools and flagging unauthorized installations across all endpoints.