We analyzed 338 million attack simulations in production. Perimeter defense blocks 69% of attacks, but post-compromise blocking drops to 37%. AMA.
Picus Labs analyzed 338 million attack simulations in production environments, finding that perimeter defenses block 69% of attacks, while post-compromise blocking effectiveness drops to 37%. The research highlights challenges in detecting quiet discovery and collection actions, with only 10% blocked, and low alerting rates despite high logging. Different attack tools show varying detection rates depending on the method used. This data provides insights into the effectiveness of perimeter and post-compromise defenses and detection engineering.
AI Analysis
Technical Summary
The Picus Labs Blue Report 2026 analyzed over 338 million attack simulations run in production environments from January to June 2026, mapped to the MITRE ATT&CK framework. The study found that perimeter defenses block 69% of attacks, matching the 2024 peak. However, post-compromise blocking effectiveness is significantly lower at 37%, indicating attackers' actions after gaining authenticated access are less likely to be stopped. Quiet discovery and credential collection actions are blocked only 10% of the time, allowing attackers to operate stealthily. Logging of attacks is at a four-year high with 58% of attacks logged, but only 14% trigger alerts, suggesting detection engineering gaps. The detection rates vary by attack method; for example, Mimikatz is blocked 94% of the time when targeting LSASS memory but only 3% when targeting the registry, indicating defenses rely on signature detection rather than behavioral analysis.
Potential Impact
The findings indicate that while perimeter defenses are relatively effective at blocking attacks, post-compromise detection and blocking are substantially weaker, allowing attackers to perform actions with less chance of being stopped. Low alerting rates despite high logging mean that many attacks go unnoticed in real time, increasing risk of prolonged attacker presence and data compromise. The variability in detection effectiveness by attack method suggests that current defenses may miss novel or stealthy techniques, increasing the likelihood of successful post-compromise activities.
Mitigation Recommendations
This report does not describe a specific vulnerability or exploit but provides empirical data on defense effectiveness. Organizations should focus on improving post-compromise detection capabilities, enhancing alerting mechanisms to convert logged events into actionable detections, and adopting behavioral detection methods rather than relying solely on signature-based defenses. No specific patches or fixes apply. The data underscores the importance of detection engineering and continuous improvement of security monitoring.
We analyzed 338 million attack simulations in production. Perimeter defense blocks 69% of attacks, but post-compromise blocking drops to 37%. AMA.
Description
Picus Labs analyzed 338 million attack simulations in production environments, finding that perimeter defenses block 69% of attacks, while post-compromise blocking effectiveness drops to 37%. The research highlights challenges in detecting quiet discovery and collection actions, with only 10% blocked, and low alerting rates despite high logging. Different attack tools show varying detection rates depending on the method used. This data provides insights into the effectiveness of perimeter and post-compromise defenses and detection engineering.
Reddit Discussion
Hi r/cybersecurity! We're the Picus Labs Research Team, and we're here for an AMA.
For the Blue Report 2026, we analyzed more than 338 million attack simulations run in production environments between January and June 2026, mapped to the MITRE ATT&CK® framework.
The headline finding for 2026: prevention recovered to 69% at the perimeter, its 2024 peak. But for the first time, we measured what happens after an attacker gains authenticated access, and only 37% of their actions get blocked.
Key findings from the research:
- Quiet discovery and collection actions get blocked one time in ten. Attackers who stay quiet can collect credentials almost undetected.
- 58% of attacks get logged, but only 14% trigger an alert. Logging is at a four-year high, which means the evidence is sitting in your SIEM, nobody's turning it into detections.
- Same tool, wildly different outcomes: Mimikatz is blocked 94% of the time against LSASS memory, but just 3% against the registry. Defenses recognize the signature method, not the behaviour itself.
We're here to talk about perimeter and post-compromise defense, detection engineering, stealth techniques, where defenders should focus first, or anything else the 338M data points can answer.
Ask us anything!
Participants:
- Dr. Suleyman Ozarslan, Co-founder and VP of Picus Labs (u/malware_bender)
- Sila Ozeren Hacioglu, Security Research Engineer (u/sila-ozeren)
- Umut Bayram, Associate Security Research Engineer (u/umut_bayram_picus)
We'll be here on September 22, 2026, answering your questions.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Picus Labs Blue Report 2026 analyzed over 338 million attack simulations run in production environments from January to June 2026, mapped to the MITRE ATT&CK framework. The study found that perimeter defenses block 69% of attacks, matching the 2024 peak. However, post-compromise blocking effectiveness is significantly lower at 37%, indicating attackers' actions after gaining authenticated access are less likely to be stopped. Quiet discovery and credential collection actions are blocked only 10% of the time, allowing attackers to operate stealthily. Logging of attacks is at a four-year high with 58% of attacks logged, but only 14% trigger alerts, suggesting detection engineering gaps. The detection rates vary by attack method; for example, Mimikatz is blocked 94% of the time when targeting LSASS memory but only 3% when targeting the registry, indicating defenses rely on signature detection rather than behavioral analysis.
Potential Impact
The findings indicate that while perimeter defenses are relatively effective at blocking attacks, post-compromise detection and blocking are substantially weaker, allowing attackers to perform actions with less chance of being stopped. Low alerting rates despite high logging mean that many attacks go unnoticed in real time, increasing risk of prolonged attacker presence and data compromise. The variability in detection effectiveness by attack method suggests that current defenses may miss novel or stealthy techniques, increasing the likelihood of successful post-compromise activities.
Defensive Guidance
This report does not describe a specific vulnerability or exploit but provides empirical data on defense effectiveness. Organizations should focus on improving post-compromise detection capabilities, enhancing alerting mechanisms to convert logged events into actionable detections, and adopting behavioral detection methods rather than relying solely on signature-based defenses. No specific patches or fixes apply. The data underscores the importance of detection engineering and continuous improvement of security monitoring.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
- Has External Source
- false
- Trusted Domain
- false
Threat ID: 6ab28375f7a7c54106389f3b
Added to database: 09/22/2026, 13:32:37 UTC
Last enriched: 09/22/2026, 13:32:42 UTC
Last updated: 09/22/2026, 16:17:33 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.