skip to content

What are the sources that reveal an intrusion your SOC never alerted on?

level: middleimportance: should knowfreq 52%

answer

  1. misses never come through the alert queue
  2. four doors, each with its own filter
  3. outside, exercise, hunt, later case
  4. each channel is blind to a different intrusion
  5. a small team usually has only two doors

basics

~20 s

Four channels: an outside party tells you, an authorised emulation exercise runs a behaviour and nothing fires, a hunt turns up unalerted activity, or a later investigation's back-timeline reaches earlier activity. Each finds a different class of miss.

solid answer

~50 s

Misses never arrive through the alert queue, so they come from four places. **Outside notification** — an ISAC, law enforcement, a partner, a customer, or an extortion demand — finds intrusions that produced a consequence visible from outside your estate. **Adversary emulation** finds misses of the behaviours someone chose to run. **Hunting** finds misses inside the data you retain and the hypotheses you chose to test. The **back-timeline of a later investigation** finds misses adjacent to an intrusion you eventually did catch. The critical point is that these are not four samples of the same population: each is blind to a different kind of intrusion, and an intrusion that is quiet, uses sanctioned tooling and never produces an outside consequence can slip past all four. A team with no emulation programme and no hunt cadence has only the first and fourth channels, so every miss it can count is one somebody else surfaced.

go deeper

for a junior

Be ready to name the ways a team learns about an intrusion it never alerted on, starting with the obvious one: somebody outside the organisation tells you.

for a middle

Explain what each channel can and cannot surface, and describe the intrusion shape that all of them miss at once — quiet, sanctioned tooling, no external consequence.

for a senior

Show that you record the discovery channel with every miss and read the pattern: if every known miss arrived from outside, your internal discovery machinery is producing nothing.

for a principal

Decide which discovery channel to fund first when you can only afford one, and be able to justify that choice against the intrusion profile your organisation actually faces.

## Misses do not arrive through the queue The alert queue only contains things that fired. An intrusion nobody detected is, by construction, absent from it, so learning about a miss always means learning it from somewhere else. There are four such channels, and knowing their individual blind spots matters more than being able to list them. ### 1. Outside notification Somebody external tells you: an information-sharing organisation, a national CERT or law-enforcement contact naming your data or your address ranges, an upstream or downstream partner, a customer who noticed something, a researcher, a hosting provider, or the intruder themselves via an extortion note or a leak-site posting. *What it finds:* intrusions with a consequence visible outside your estate — data that surfaced somewhere, infrastructure that appeared in someone else's telemetry, fraud that landed on a balance sheet. *What it is blind to:* everything that stayed quiet. An intrusion whose objective was long-term access, or whose stolen data was never published or resold visibly, produces no outside signal at all. ### 2. Authorised adversary emulation Someone executes chosen behaviours against the live estate under authorisation, and you observe whether telemetry appeared, whether a rule matched and whether a case was worked. *What it finds:* misses of the specific behaviours that were chosen, with an exact timestamp, which makes each one immediately actionable. *What it is blind to:* behaviours nobody chose. The technique list is written by your team from what your team already thinks about, which is precisely the population whose gaps you are trying to discover. ### 3. Hunting An analyst forms a hypothesis about activity that would be present if a particular kind of intruder were in the estate, and searches for it without an alert to start from. *What it finds:* activity that is present in your retained data and that someone thought to look for. *What it is blind to:* anything outside retention, anything in a source you never collected, and any hypothesis nobody formed. ### 4. The back-timeline of a later intrusion While scoping a confirmed intrusion you walk backwards through logs and find earlier activity — sometimes an alert that fired months ago and was closed as a false positive, sometimes activity that never alerted at all. *What it finds:* misses adjacent in host, account or technique to something you eventually caught. *What it is blind to:* misses that never led to anything you detected later. It is conditional on a subsequent success, which is exactly the wrong condition for measuring failure. ## The composite blind spot Put the four blind spots together and a specific shape of intrusion is invisible to all of them at once: slow, using tooling the estate already sanctions, producing no external consequence, not matching any behaviour on an emulation list, and never escalating into an incident that would be reconstructed later. The worked case is a months-long slow-drip exfiltration through the corporate file-sync client in a SaaS tenant. The client is approved and installed everywhere. The audit trail shows downloads and shares that are indistinguishable, record by record, from a busy salesperson. No rule fires because no rule describes it, no analyst opens a case, the volume never spikes, nothing leaves through a channel anyone watches, and the data is never published. All four channels return nothing — and would keep returning nothing indefinitely. ## The channel table | Channel | Finds | Blind to | | --- | --- | --- | | Outside notification | intrusions with an external consequence | quiet intrusions with no outside footprint | | Emulation | misses of the behaviours you chose | behaviours nobody put on the list | | Hunting | activity in retained data you thought to query | unretained sources, unformed hypotheses | | Back-timeline | misses adjacent to a caught intrusion | misses that never led to a later detection | ## What this means for a small team A one-analyst team with no emulation programme and no hunt cadence has channels 1 and 4 only. Both require the intrusion to eventually become consequential — someone outside notices, or it grows into an incident that gets reconstructed. So its recorded misses are not merely few; they are systematically shaped, containing only intrusions that ended loudly. When such a team reports its known misses, the correct caption is `these are the ones that became visible to somebody`, and the highest-value structural fix is to open a channel that does not depend on the intrusion becoming loud. ## A fifth case worth separating An alert that fired and was never worked — sitting unopened in a backlog — is also a miss, but it is the one kind that left a record. Keep it in a separate count: the detection succeeded and the process failed, and the remedy is queue capacity or routing, not new coverage. Blending it into the coverage numbers makes teams build rules to solve a staffing problem.

  • Your team runs no emulation and no hunts. What does that do to the shape of your miss count?
    It leaves outside notification and the back-timeline of a later case, both of which require the intrusion to eventually become consequential. A slow exfiltration through a sanctioned tool that is never published and never escalates is invisible to both. So the count is not just small, it is biased towards intrusions that ended loudly, and it can be zero in a genuinely compromised estate.
  • A SaaS vendor notifies you that your tenant was affected. Does that count as a miss for your SOC?
    Only if the activity was visible in telemetry you collect and nothing fired or nobody worked it. If the compromise happened entirely inside the provider's own estate and produced no record on your side, it is a collection gap rather than a detection miss. The distinction drives different fixes — obtain the tenant audit feed versus write a rule over a feed you already have — so classify it before you count it.
  • Why is a miss found by outside notification worth recording differently from one found by a hunt?
    Because the channel tells you something the miss itself does not. A hunt finding means your internal machinery works and reached something; an outside notification means the estate produced no internally usable signal until a third party intervened. Recording the channel with every miss turns a bare count into a statement about which of your discovery mechanisms are alive.

saying these in an interview costs you the question

  • Treats emulation results as a real-world miss rate
  • Thinks all four channels sample the same population
  • Assumes hunts can search data nobody retained
  • Counts only outsider-reported intrusions as real misses
  • Believes a zero miss count means the channels found nothing to find

context