Could security tooling have missed the activity?¶
Yes. Security tooling can miss relevant or malicious activity.
Avoid the dangerous assumption¶
The dangerous assumption is that a well-equipped organisation has a complete record of everything that happened.
It does not.
Security visibility depends on configuration, coverage, licensing, retention, integration and the methods used by the offender.
Activity may be missed where a device was unmanaged, a sensor was offline, logs were not collected, cloud auditing was limited, the attacker used valid credentials, legitimate administrative tools were abused, traffic was encrypted, security controls were disabled, the activity occurred before the product was installed, the event was not covered by a detection rule or the alert was overlooked or suppressed.
An attacker may also deliberately avoid known detection methods or act slowly enough to remain below thresholds.
Investigators should identify what the tooling was capable of seeing at the relevant time.
Ask which products were deployed, which systems they covered, which data sources were connected, whether sensors were healthy, how long records were retained, what exclusions applied, whether alerts were reviewed and whether configuration changed during the incident.
Use other evidence sources to fill gaps. These may include native operating-system logs, identity-provider records, cloud audit logs, network devices, application logs, email records, backups, forensic artefacts and witness accounts.
A missed detection does not necessarily mean the security team acted unreasonably. The question is what evidence exists and what limitations affected visibility.
Equally, do not assume compromise simply because tooling had gaps. Missing visibility creates uncertainty, not proof.
Operational takeaway¶
Map the coverage and limitations of the security environment, then test other evidence sources before concluding that activity did or did not occur.