# Enterprise Security's Blind Spot: Why One Missed Threat Per Week Is the New Normal


A sweeping analysis of 25 million security alerts reveals a troubling truth: defenders are systematically ignoring the very threats that are actively compromising their networks. The gap isn't in detection—it's in triage discipline, EDR reliability, and the fundamental assumptions that have shaped modern security operations.


## The Threat


Organizations face a relentless, invisible problem: approximately one confirmed breach per week originates from alerts that security teams never investigate. This isn't hyperbole. It's the finding of a comprehensive threat analysis spanning 10 million monitored endpoints and identities, 82,000 forensic investigations with live memory scans, and telemetry from over 7 million IP addresses.


The threat is bifurcated. First, defenders are deprioritizing low-severity and informational alerts to the point that real compromises slip through. Second, and more alarming, the endpoint detection and response (EDR) platforms that organizations rely on as their safety net are declaring endpoints "clean" when active malware—including Mimikatz, Cobalt Strike, and Meterpreter—is still running in memory.


## Background and Context


The report examined 25 million security alerts across live enterprise environments, creating one of the most comprehensive datasets ever released on the gap between detection and response. The underlying telemetry includes:


  • 10 million endpoints and identities under continuous monitoring
  • 82,000 forensic endpoint investigations including live memory scans
  • 180 million files analyzed for indicators of compromise
  • 550,000+ phishing emails examined and classified
  • Telemetry from 7 million IP addresses, 3 million domains and URLs

  • This scale matters. It moves the findings beyond anecdote into evidence of systemic failure in how enterprises approach alert fatigue and triage economics.


    The root cause is well understood: SOCs and MDR providers cannot investigate every alert. The volume is mathematically impossible. In response, the industry has adopted a severity-based model where low-severity and informational alerts are routinely ignored. This creates a predictable gap that threat actors exploit methodically.


    ## Technical Details


    ### The 1% Problem That Adds Up


    Of the 25 million alerts analyzed, nearly 1% originated from incidents initially classified as low-severity or informational. On endpoints specifically, the figure climbed to nearly 2%.


    To understand the scale: the average enterprise generates approximately 450,000 alerts per year. One percent of that figure represents roughly 54 real threats annually—approximately one per week—that never receive investigation under a traditional SOC or MDR model.


    | Metric | Finding |

    |--------|---------|

    | Total alerts analyzed | 25 million |

    | Confirmed incidents from low-severity alerts | ~1% |

    | On endpoints only | ~2% |

    | Average org's annual alerts | 450,000 |

    | Missed threats per org annually | ~54 (1 per week) |

    | Endpoints with active infections marked "mitigated" | 51% |


    ### EDR "Mitigated" Does Not Mean Clean


    The most damning finding concerns the reliability of EDR remediation. Of the 82,000 alerts that underwent forensic investigation with live memory scans:


  • 2,600 endpoints had confirmed active infections
  • 51% were already marked "mitigated" by the EDR vendor
  • Malware remained active in memory despite EDR's claim of remediation

  • The malware families found running in memory include:


  • Mimikatz – credential extraction framework
  • Cobalt Strike – adversary emulation and post-exploitation platform
  • Meterpreter – reverse shell and payload delivery system
  • StrelaStealer – information stealer targeting credentials and sensitive data

  • These are not obscure proof-of-concepts. They are the operational standards of criminal syndicates and nation-state actors. The fact that EDR systems are reporting clean on machines actively running these tools represents a critical gap in endpoint protection.


    ### Phishing: The Email Gateway Is No Longer the Perimeter


    The phishing analysis reveals a fundamental shift in attacker methodology that most email security architectures are not designed to detect:


    Attachment-based phishing is declining:

  • Less than 6% of confirmed malicious phishing emails contained attachments
  • Most relied on links and social engineering
  • Attackers have abandoned traditional vector-based email security controls

  • Trusted infrastructure has become attack infrastructure:


    Attackers have migrated their phishing infrastructure onto platforms trusted by default:

  • Vercel (frontend hosting)
  • CodePen (code sandbox platform)
  • OneDrive (Microsoft cloud storage)
  • PayPal's legitimate invoicing system

  • One documented campaign exploits PayPal's payment request infrastructure directly, embedding callback numbers in payment notes and using Unicode homoglyphs to defeat signature-based detection. The sending domain passes every standard authentication check (SPF, DKIM, DMARC) because the email genuinely originates from PayPal's infrastructure.


    CAPTCHA as a malicious signal:

  • Cloudflare Turnstile CAPTCHA correlated strongly with phishing pages
  • Google reCAPTCHA correlated with legitimate infrastructure
  • This inversion challenges the assumption that CAPTCHAs indicate legitimacy

  • ## Implications


    The findings expose three critical vulnerabilities in modern security operations:


    ### 1. Triage Discipline Cannot Scale


    The severity-based alert model assumes that low-severity alerts contain low-value threats. The data proves this assumption wrong. At enterprise scale, 1% of a million alerts is ten thousand real threats. Organizations cannot afford to ignore any alert category if it consistently produces confirmed compromises.


    ### 2. Endpoint Detection Is Incomplete Without Memory Forensics


    EDR systems are effective at detecting file-based malware and behavioral anomalies, but they are not comprehensive at identifying and remediating in-memory infections. A 51% false-clean rate on forensically validated compromises suggests that EDR should not be the sole source of truth for endpoint health. Memory forensics, behavioral post-exploitation detection, and lateral movement monitoring must complement traditional EDR.


    ### 3. Email Security Must Evolve Beyond the Gateway


    Phishing campaigns are now delivered through legitimate infrastructure, authenticated with valid credentials, and transmitted via links rather than attachments. Traditional email gateway filters cannot catch threats originating from PayPal, Microsoft, or Vercel without blocking legitimate traffic. Detection must shift toward behavioral analysis of user interaction with links and post-delivery sandbox detonation.


    ## Recommendations


    For Enterprise Security Teams:


  • Revisit alert thresholds – Do not automatically dismiss informational and low-severity alerts. Conduct a retrospective analysis on your own environment to determine if low-severity categories contain real threats.

  • Implement memory-level forensics – Supplement EDR with periodic memory imaging and forensic analysis, particularly on endpoints with confirmed malware activity or suspicious indicators.

  • Decouple email security from gateway scanning – Assume attackers will use legitimate infrastructure. Implement post-delivery detection, user awareness training focused on behavioral verification, and sandboxing of links.

  • Correlate EDR remediation with forensic validation – Before closing a ticket marked "mitigated," confirm that forensic evidence supports the claim. Do not trust EDR reports at face value.

  • For Managed Detection and Response (MDR) Providers:


  • Raise investigation thresholds incrementally rather than drawing hard lines at severity levels.
  • Include memory forensics as part of incident response, not as an add-on.
  • Publish transparency reports on false-positive rates for "mitigated" claims.

  • ---


    ## HackWire Analysis


    This report exposes a dangerous myth: that automation and severity-based triage can replace human investigation. The cybersecurity industry has sold organizations a false economy—the idea that filtering out low-severity alerts improves efficiency. Instead, it creates a predictable gap that adversaries exploit weekly.


    The most significant finding is not the 1% figure itself, but what it reveals about the nature of modern attacks. Threat actors are not launching sophisticated zero-days against well-defended networks. They are systematically exploiting the known constraints of security operations: alert fatigue, triage bottlenecks, and the gap between detection and response. They know defenders can't investigate everything. So they craft attacks designed to trigger low-severity alerts and hide in memory after EDR declares victory.


    The phishing evolution is equally telling. Attackers have moved away from trying to bypass email gateways—a losing battle against modern email security. Instead, they are using the gateways' own trust assumptions against them. PayPal's payment system is trusted because it *is* legitimate. Vercel's infrastructure is trusted because developers use it. This represents a fundamental shift from "evade the perimeter" to "use the perimeter against itself."


    For defenders, the implications are sobering but actionable. You cannot engineer your way out of alert fatigue with a more sophisticated SOAR or a better correlation engine. You must change the triage model itself. That means accepting that some low-severity alerts need investigation, that EDR reports require validation, and that email security requires post-delivery analysis, not just gateway filtering. The cost of missed investigation is one breach per week. The cost of changing how you triage is worth far more.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)