Tuesday, November 12, 2024
HomeCyber Security NewsMost Enterprise SIEMs Fail Against MITRE ATT&CK Tactics

Most Enterprise SIEMs Fail Against MITRE ATT&CK Tactics

Published on

Malware protection

SIEM (Security Incident and Event Management) tools are being used in most organizations for monitoring, analyzing, and preventing threat actors.

Organizations are trying to build more and more in terms of security to protect against ransomware attacks, data breaches, and many other types of cybercriminal activities.

However, Security is a continuous process. These SIEM tools can help prevent threat actors only to a certain extent.

- Advertisement - SIEM as a Service

The detection mechanisms of SIEMs are far less when compared to the sophisticated attacks that threat actors use to infiltrate organizations.

MITRE ATT&CK & SIEMs

MITRE has nearly 194 techniques in its framework, which are taken as a baseline for building SIEM tools.

According to report from Cardinalops, Enterprise SIEMs are covering only 24% of detections of the overall MITRE attack techniques.

Image: Enterprise security. Source: CardinalOps

Enterprise SIEMs currently have enough data to cover these techniques, which accounts for nearly 94% of all the MITRE ATT&CK techniques that only need a scale-up for detecting much faster and more efficiently.

The report also indicated that 12% of all the SIEM rules that are currently built are broken due to misconfigured data sources and missing field elements.

According to RedHat reports, Organisations using containers account for more than 68%. However, container security lags a lot, with only 32% in detection.

Common Security Layers

Most of the common security layers covered by SIEM are,

  1. Windows – 96%
  2. Network – 96%
  3. IAM – 96%
  4. Linux/Mac – 87%
  5. Cloud – 83%
  6. Email – 78%
  7. Productivity Suites – 63%
  8. Container – 32%
layers
Image: Most Common Security layers. Source: CardinalOps

The most commonly used SIEMs were Splunk, IBM QRadar, Sentinel, and Sumologic. Analyzing these tools provided over 4000 rules in SIEMs, with the largest SIEM having more than 600 rules. 

The analyzed sectors include financial services, banking, insurance, energy, media and telecommunications, professional & legal services, and MSSP(Managed Security Service Provider) / MDR (Managed Detection and Response).

Recommendations for SIEM

Organizations are advised to review the current SIEM process and check for threats and techniques or behaviors that it is currently missing.

The ad-hoc combination of use case management must include manual pentesting, red teaming, breach and attack simulation tools (BAS), threat intelligence, and much more.

Measure and improve the SIEM with various detecting engineering process approaches in terms of IT management, DevOps, SOC, and other quality metrics that contribute to the security side of the organizations.

With increasing threats day by day, it is necessary for organizations to effectively manage and monitor the threats in every aspect of security. A single loophole can bring the entire organization down.

Hence, Security professionals are advised to take necessary security measures to protect against threat actors.

“AI-based email security measures Protect your business From Email Threats!” – .

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

10 Best DNS Management Tools – 2025

Best DNS Management Tools play a crucial role in efficiently managing domain names and...

Sweet Security Announces Availability of its Cloud Native Detection & Response Platform on the AWS Marketplace

Customers can now easily integrate Sweet’s runtime detection and response platform into their AWS...

Researchers Detailed Credential Abuse Cycle

Cybercriminals exploit leaked credentials, obtained through various means, to compromise systems and data, enabling...

New Android Malware SpyAgent Taking Screenshots Of User’s Devices

SpyAgent, a newly discovered Android malware, leverages OCR technology to extract cryptocurrency recovery phrases...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Researchers Detailed Credential Abuse Cycle

Cybercriminals exploit leaked credentials, obtained through various means, to compromise systems and data, enabling...

New Android Malware SpyAgent Taking Screenshots Of User’s Devices

SpyAgent, a newly discovered Android malware, leverages OCR technology to extract cryptocurrency recovery phrases...

Tor Network Suffers IP Spoofing Attack Via Non-Exit Relays

In late October 2024, a coordinated IP spoofing attack targeted the Tor network, prompting...