Skip to main content
CybersecurityNetwork Security

Enterprise Defenses Exposed to Quiet Attacks Within Network Perimeters

Technicians walk through rows of server racks and networking equipment in a dimly lit data center with a large window in…

"The recovery is real. The bad news: It's taking place almost exclusively at the perimeter." — Sıla Özeren Hacıoğlu, Picus Security, Blue Report 2026.

Scale of the measurement: 338 million simulations in H1 2026

Picus Labs' Blue Report 2026 measured more than 338 million real attack simulations across actual client production environments in the first half of 2026. The headline numbers show meaningful improvement at the edge: average prevention effectiveness climbed from 62% to 69%, matching its 2024 peak, and logging rose to a four‑year high of 58%.

Post‑compromise reality: a 37% prevention rate inside the network

For the first time Picus measured post‑compromise prevention — what actually breaks the attack chain once an adversary operates inside the network as an authenticated user — and the result is stark: the Post‑Compromise Prevention Rate was 37%. In short, perimeter controls now block roughly two out of three attacks; inside, defenses stop barely one in three.

That failure is not uniform. Actions that are loud — running code or jumping between machines — are blocked most of the time. Lateral movement through service execution techniques such as Sharp‑ServiceExec and SMBExec was stopped around 90% of the time, and UAC‑bypass privilege escalation about 85%.

By contrast, low‑noise activity succeeds almost unchecked: reconnaissance and mapping of domains, shares, and sessions were prevented only about 10% of the time; quiet credential reads from memory were stopped around 22%; and one variant that pulls secrets straight from the registry was blocked in less than 1% of attempts.

Mimikatz, signatures, and the limits of indicator checks

The report demonstrates how detection built around conspicuous artifacts consistently misses stealthier paths to the same goal. Picus ran the credential‑theft tool Mimikatz against the same objective three different ways and saw widely divergent prevention scores. Dumping credentials from LSASS memory — a route long watched by signatures — was blocked almost every time (the report highlights a 94% prevention finding in that experiment). But memory reads that avoid LSASS or registry reads that never touch LSASS were mostly unopposed.

Picus warns that a prevention score tied to signatures measures how well you catch what you've already seen, not whether you stop the underlying behavior. The report emphasizes that small changes — renaming signature strings, loading a build only in memory, or using a signed utility already present on the host — can bypass signature‑dependent controls while still yielding the same credential material to an attacker.

That pattern reaches beyond one tool. The IOC‑Based Prevention Rate — how often controls block known‑malicious files delivered as downloads — fell to 50% in 2026, down from 60% in 2025 and 71% in 2024, underscoring the erosion of signature‑only defenses as repacking and volume of new files accelerate.

Telemetry without action: 58% logging, 14% alerting

Logging is up — Picus recorded a four‑year high of 58% — but alerts remain frozen at 14%. Fewer than one in seven simulated attacks produced an alert. The Blue Report frames that gap as a detection‑engineering problem: teams are collecting more telemetry than ever but converting almost none of it into actionable alerts.

The behavioral gap matters because the poorest‑prevented techniques are the quiet ones attackers have been moving toward. The report highlights the single least‑prevented technique in the dataset — hiding command history — which was stopped just 1% of the time.

What this means for technologists, procurement leaders, and adversaries

  • Technologists and security teams: the data shows validation matters. Picus found that prevention climbed because organizations re‑tested controls and fixed what the tests exposed; defenses that went untested regressed. The report urges testing interior controls for discovery, share/session enumeration, and passive credential access with the same rigor applied to lateral movement.
  • Procurement and enterprise leaders: strong performance is temporary if it rests on signatures alone. The report shows last year's leaders can slip and last year's laggards can improve quickly; one sector (education) fell 30 points to become the least‑protected industry. Purchasers should demand proof of behavioral coverage, not just an inventory of signatures.
  • Adversaries and threat actors: Picus notes attackers are shifting toward stealth and that the shift is effective. Prevention fell against nine of the ten hardest‑to‑stop threat groups, and every top ransomware family was blocked less than 38% of the time; the Play family collapsed from 50% prevention to 13%.

The lesson Picus offers is practical rather than exotic: validate exposure, not inventory; harden the interior against quiet actions; and treat detection rules as engineering — write them against current behavior, confirm they fire, tune noise out, and re‑validate as conditions change. The recovery at the perimeter is real, the interior remains fragile, and the quiet moves before a breach — reconnaissance and credential reads that rarely trip signatures or alerts — are where attackers are currently winning.

Read the Blue Report 2026 coverage on The Hacker News