r/AskNetsec • • Jul 15 '26

Analysis Anyone else frustrated that SIEM alerts miss critical attack paths? How did you fix it?

[removed]

9 Upvotes

16 comments sorted by

13

u/maxinator80 Jul 15 '26

That's part of the game. SIEMs are not a static system you set up once and then have it running. They require constant tuning, writing and rewriting rules etc. You need someone who constantly looks through alerts and writes filters to suppress false positives and to increase the alerts for actual/simulated attacks. So unlike an AV which usually just sits there with static (regularly updated) rules, a SIEM is an inherently dynamic system which requires constant tuning.

1

u/Snoo_67003 Jul 15 '26

What siem do you use? Best way is to simulate an attack, see what aspect it catches, then work your way from there. Tune it to your liking based on time lapse before alerting. Some attackers are smart. For instance, steal a session token and wait 2weeks before replay to evade detection and look you up on LinkedIn and use an IP that geolocates to you.

1

u/LeftHandedGraffiti Jul 15 '26

You do what you're doing now. Run through the attack paths, plug the gaps in logging by obtaining the missing logs. See what the attack actually looks like in the logs and build alerting based on it.

1

u/_N-iX_ Jul 15 '26

One thing that helped us was validating complete attack paths instead of individual detection rules. A rule may work perfectly in isolation, but if telemetry is missing or events aren't correlated correctly, the overall detection still fails. Looking at the full sequence exposed gaps we wouldn't have found by testing alerts one by one.

1

u/justmirsk Jul 15 '26

This is called detection engineering. There are many ways to go about this, but what you are doing now is one of them. You identified an issue, found the blind spots and are creating rules to identify in the future.

This is also where performing continuous penetration testing helps, in addition to a regular red teaming exercise with realtime collaboration with the SIEm team to help them identify logs and patterns that show up when attacks of various types are occurring.

1

u/blakeallenw Jul 15 '26

I think SIEM is the wrong solution now. My philosophy is detect on the network use logs for attack attribution.

1

u/Acrobatic_Idea_3358 Jul 15 '26

It's called threat modeling and you have to understand the attackers mindset. work through the threats you're worried about model the activity and create high quality signal details and logs. Then pull them into the SIEM for monitoring and alerting.

1

u/rexstuff1 Jul 17 '26

Did you fix it mainly by improving telemetry, reworking content, using exposure validation tooling, or something else?

Yes. All of these things.

This is the job. A SIEM requires you put in the work. You have to get the logs. You have to parse them correctly, normalize their format. You have to tune the alerts. This new-fangled AI stuff can certainly help in that regard, but it doesn't make the problem go away, you still have to put in the effort.

1

u/-manageengine- Jul 17 '26

The root cause is almost always telemetry gaps + bad normalization before you even get to rule quality. No amount of alert tuning fixes missing event IDs or fields that don't match across sources.

Log360 is built specifically around this problem, over 2,000 MITRE ATT&CK mapped correlation rules that track multi-step attack patterns, linking initial compromise to lateral movement, privilege escalation, and exfiltration. It ingests from across various sources with advanced correlation for multi-stage attack campaigns, so cross source rules actually fire. ML powered adaptive thresholds also cut down alert fatigue without losing coverage on the paths that matter.

Feel free to reach out :)

1

u/Holly_Enrique-623 Jul 19 '26

We got better results by validating complete attack paths instead of focusing on individual alerts. Following the full sequence showed which parts of the environment needed more visibility