# Enterprise Security's Blind Spot: Why One Missed Threat Per Week Is the New Normal
A sweeping analysis of 25 million security alerts reveals a troubling truth: defenders are systematically ignoring the very threats that are actively compromising their networks. The gap isn't in detection—it's in triage discipline, EDR reliability, and the fundamental assumptions that have shaped modern security operations.
## The Threat
Organizations face a relentless, invisible problem: approximately one confirmed breach per week originates from alerts that security teams never investigate. This isn't hyperbole. It's the finding of a comprehensive threat analysis spanning 10 million monitored endpoints and identities, 82,000 forensic investigations with live memory scans, and telemetry from over 7 million IP addresses.
The threat is bifurcated. First, defenders are deprioritizing low-severity and informational alerts to the point that real compromises slip through. Second, and more alarming, the endpoint detection and response (EDR) platforms that organizations rely on as their safety net are declaring endpoints "clean" when active malware—including Mimikatz, Cobalt Strike, and Meterpreter—is still running in memory.
## Background and Context
The report examined 25 million security alerts across live enterprise environments, creating one of the most comprehensive datasets ever released on the gap between detection and response. The underlying telemetry includes:
This scale matters. It moves the findings beyond anecdote into evidence of systemic failure in how enterprises approach alert fatigue and triage economics.
The root cause is well understood: SOCs and MDR providers cannot investigate every alert. The volume is mathematically impossible. In response, the industry has adopted a severity-based model where low-severity and informational alerts are routinely ignored. This creates a predictable gap that threat actors exploit methodically.
## Technical Details
### The 1% Problem That Adds Up
Of the 25 million alerts analyzed, nearly 1% originated from incidents initially classified as low-severity or informational. On endpoints specifically, the figure climbed to nearly 2%.
To understand the scale: the average enterprise generates approximately 450,000 alerts per year. One percent of that figure represents roughly 54 real threats annually—approximately one per week—that never receive investigation under a traditional SOC or MDR model.
| Metric | Finding |
|--------|---------|
| Total alerts analyzed | 25 million |
| Confirmed incidents from low-severity alerts | ~1% |
| On endpoints only | ~2% |
| Average org's annual alerts | 450,000 |
| Missed threats per org annually | ~54 (1 per week) |
| Endpoints with active infections marked "mitigated" | 51% |
### EDR "Mitigated" Does Not Mean Clean
The most damning finding concerns the reliability of EDR remediation. Of the 82,000 alerts that underwent forensic investigation with live memory scans:
The malware families found running in memory include:
These are not obscure proof-of-concepts. They are the operational standards of criminal syndicates and nation-state actors. The fact that EDR systems are reporting clean on machines actively running these tools represents a critical gap in endpoint protection.
### Phishing: The Email Gateway Is No Longer the Perimeter
The phishing analysis reveals a fundamental shift in attacker methodology that most email security architectures are not designed to detect:
Attachment-based phishing is declining:
Trusted infrastructure has become attack infrastructure:
Attackers have migrated their phishing infrastructure onto platforms trusted by default:
One documented campaign exploits PayPal's payment request infrastructure directly, embedding callback numbers in payment notes and using Unicode homoglyphs to defeat signature-based detection. The sending domain passes every standard authentication check (SPF, DKIM, DMARC) because the email genuinely originates from PayPal's infrastructure.
CAPTCHA as a malicious signal:
## Implications
The findings expose three critical vulnerabilities in modern security operations:
### 1. Triage Discipline Cannot Scale
The severity-based alert model assumes that low-severity alerts contain low-value threats. The data proves this assumption wrong. At enterprise scale, 1% of a million alerts is ten thousand real threats. Organizations cannot afford to ignore any alert category if it consistently produces confirmed compromises.
### 2. Endpoint Detection Is Incomplete Without Memory Forensics
EDR systems are effective at detecting file-based malware and behavioral anomalies, but they are not comprehensive at identifying and remediating in-memory infections. A 51% false-clean rate on forensically validated compromises suggests that EDR should not be the sole source of truth for endpoint health. Memory forensics, behavioral post-exploitation detection, and lateral movement monitoring must complement traditional EDR.
### 3. Email Security Must Evolve Beyond the Gateway
Phishing campaigns are now delivered through legitimate infrastructure, authenticated with valid credentials, and transmitted via links rather than attachments. Traditional email gateway filters cannot catch threats originating from PayPal, Microsoft, or Vercel without blocking legitimate traffic. Detection must shift toward behavioral analysis of user interaction with links and post-delivery sandbox detonation.
## Recommendations
For Enterprise Security Teams:
For Managed Detection and Response (MDR) Providers:
---
## HackWire Analysis
This report exposes a dangerous myth: that automation and severity-based triage can replace human investigation. The cybersecurity industry has sold organizations a false economy—the idea that filtering out low-severity alerts improves efficiency. Instead, it creates a predictable gap that adversaries exploit weekly.
The most significant finding is not the 1% figure itself, but what it reveals about the nature of modern attacks. Threat actors are not launching sophisticated zero-days against well-defended networks. They are systematically exploiting the known constraints of security operations: alert fatigue, triage bottlenecks, and the gap between detection and response. They know defenders can't investigate everything. So they craft attacks designed to trigger low-severity alerts and hide in memory after EDR declares victory.
The phishing evolution is equally telling. Attackers have moved away from trying to bypass email gateways—a losing battle against modern email security. Instead, they are using the gateways' own trust assumptions against them. PayPal's payment system is trusted because it *is* legitimate. Vercel's infrastructure is trusted because developers use it. This represents a fundamental shift from "evade the perimeter" to "use the perimeter against itself."
For defenders, the implications are sobering but actionable. You cannot engineer your way out of alert fatigue with a more sophisticated SOAR or a better correlation engine. You must change the triage model itself. That means accepting that some low-severity alerts need investigation, that EDR reports require validation, and that email security requires post-delivery analysis, not just gateway filtering. The cost of missed investigation is one breach per week. The cost of changing how you triage is worth far more.
— *HackWire Editorial*
---
## Related Coverage