Skip to main content

We analyzed 338 million attack simulations in production. Perimeter defense blocks 69% of attacks, but post-compromise blocking drops to 37%. AMA.

0
Medium
Published: 09/22/2026 (09/22/2026, 13:28:46 UTC)
Source: Reddit Cybersecurity

Description

Picus Labs analyzed 338 million attack simulations in production environments, finding that perimeter defenses block 69% of attacks, while post-compromise blocking effectiveness drops to 37%. The research highlights challenges in detecting quiet discovery and collection actions, with only 10% blocked, and low alerting rates despite high logging. Different attack tools show varying detection rates depending on the method used. This data provides insights into the effectiveness of perimeter and post-compromise defenses and detection engineering.

Reddit Discussion

r/cybersecurity·posted by u/sila-ozeren
00

Hi r/cybersecurity! We're the Picus Labs Research Team, and we're here for an AMA.
For the Blue Report 2026, we analyzed more than 338 million attack simulations run in production environments between January and June 2026, mapped to the MITRE ATT&CK® framework.

The headline finding for 2026: prevention recovered to 69% at the perimeter, its 2024 peak. But for the first time, we measured what happens after an attacker gains authenticated access, and only 37% of their actions get blocked.

Key findings from the research:

  • Quiet discovery and collection actions get blocked one time in ten. Attackers who stay quiet can collect credentials almost undetected.
  • 58% of attacks get logged, but only 14% trigger an alert. Logging is at a four-year high, which means the evidence is sitting in your SIEM, nobody's turning it into detections.
  • Same tool, wildly different outcomes: Mimikatz is blocked 94% of the time against LSASS memory, but just 3% against the registry. Defenses recognize the signature method, not the behaviour itself.

We're here to talk about perimeter and post-compromise defense, detection engineering, stealth techniques, where defenders should focus first, or anything else the 338M data points can answer.

Ask us anything!

Participants:

Proof Photos

We'll be here on September 22, 2026, answering your questions.

Blue Report 2026

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 13:32:42 UTC

Technical Analysis

The Picus Labs Blue Report 2026 analyzed over 338 million attack simulations run in production environments from January to June 2026, mapped to the MITRE ATT&CK framework. The study found that perimeter defenses block 69% of attacks, matching the 2024 peak. However, post-compromise blocking effectiveness is significantly lower at 37%, indicating attackers' actions after gaining authenticated access are less likely to be stopped. Quiet discovery and credential collection actions are blocked only 10% of the time, allowing attackers to operate stealthily. Logging of attacks is at a four-year high with 58% of attacks logged, but only 14% trigger alerts, suggesting detection engineering gaps. The detection rates vary by attack method; for example, Mimikatz is blocked 94% of the time when targeting LSASS memory but only 3% when targeting the registry, indicating defenses rely on signature detection rather than behavioral analysis.

Potential Impact

The findings indicate that while perimeter defenses are relatively effective at blocking attacks, post-compromise detection and blocking are substantially weaker, allowing attackers to perform actions with less chance of being stopped. Low alerting rates despite high logging mean that many attacks go unnoticed in real time, increasing risk of prolonged attacker presence and data compromise. The variability in detection effectiveness by attack method suggests that current defenses may miss novel or stealthy techniques, increasing the likelihood of successful post-compromise activities.

Defensive Guidance

This report does not describe a specific vulnerability or exploit but provides empirical data on defense effectiveness. Organizations should focus on improving post-compromise detection capabilities, enhancing alerting mechanisms to convert logged events into actionable detections, and adopting behavioral detection methods rather than relying solely on signature-based defenses. No specific patches or fixes apply. The data underscores the importance of detection engineering and continuous improvement of security monitoring.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
Has External Source
false
Trusted Domain
false

Threat ID: 6ab28375f7a7c54106389f3b

Added to database: 09/22/2026, 13:32:37 UTC

Last enriched: 09/22/2026, 13:32:42 UTC

Last updated: 09/22/2026, 16:17:33 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses