[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFjXB2Vh8rTpSWgsQJ_ibAECyqc6o7XVwjzHAgVZ630E":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"c5c72318-41a8-4373-8dcd-d9c875f2ce06","undetected-threats-linger-for-years-due-to-monitoring-and-response-gaps","e39fd33c-6a3f-49ad-87a5-bf698a3eda09","Undetected Threats Linger for Years Due to Monitoring and Response Gaps","Kaspersky's 2025 compromise assessment findings reveal that 60% of security incidents went undetected because organizations lacked high-confidence alerts, allowing threat actors to persist unnoticed for months or even years. The oldest discovered threat had been active for four years, demonstrating how dangerously long dwell times can become when continuous monitoring and proactive threat hunting are absent. Attackers leveraged Living-off-the-Land Binaries (LoLBins) and legitimate remote management tools specifically to evade detection, blending into normal network activity. This matters because extended dwell time dramatically increases the potential damage from data exfiltration, ransomware deployment, and lateral movement across the environment.","**Immediate Actions:**\n- Deploy a SIEM or XDR solution tuned to generate high-confidence alerts for anomalous behaviors, including LoLBin abuse and unauthorized remote management tool usage.\n- Conduct an emergency compromise assessment or threat hunt to identify any currently active, undetected threats within the environment.\n\n**Detection Measures:**\n- Establish continuous 24\u002F7 monitoring with defined alert thresholds and escalation paths to ensure no critical signals are missed.\n- Implement behavioral analytics to detect lateral movement, credential misuse, and abuse of legitimate administrative tools such as RMM software.\n- Create detection rules specifically targeting LoLBins (e.g., certutil, mshta, wscript) executing in unusual contexts or from unexpected parent processes.\n\n**Long-term Improvements:**\n- Build a formal threat hunting program with scheduled, hypothesis-driven hunts focused on low-and-slow attacker tactics that evade automated alerting.\n- Define and enforce incident response SLAs that mandate investigation timelines, escalation triggers, and containment deadlines to prevent prolonged dwell times.\n- Regularly review and audit remote management tool usage, whitelisting only approved tools and flagging unauthorized installations across all endpoints.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 8: Audit Log Management","CIS Control 13: Network Monitoring and Defense","CIS Control 17: Incident Response Management","NIST SP 800-61: Computer Security Incident Handling Guide","NIST DE.CM-1: The network is monitored to detect potential cybersecurity events","NIST DE.AE-3: Event data are collected and correlated from multiple sources","NIST RS.AN-1: Notifications from detection systems are investigated","MITRE ATT&CK: Living-off-the-Land Binaries (T1218)","MITRE ATT&CK: Remote Access Tools (T1219)","ISO\u002FIEC 27001: A.16 Information Security Incident Management","ITIL: Event Management and Incident Management processes","published","2026-07-02T10:20:40.02152+00:00","2026-07-02T10:20:39.933+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fsecurelist.com\u002Fcompromise-assessment-findings-2025\u002F120542\u002F","missed-incidents-persistent-threats-and-response-gaps-insights-from-compromise-a-a663f8","Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":44,"name":45,"slug":46,"description":47,"color":48},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",[]]