Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

Could security tooling have missed the activity?

Yes.

Security tooling has blind spots. Coverage depends on which systems were monitored, what data was collected, which rules existed, how healthy the sensors were and how long records were retained.

A missed alert is therefore entirely possible even in a well-run environment.

Map the visibility boundary

Useful questions include:

  • Was the device managed?
  • Was the security sensor installed and healthy?
  • Were the relevant logs enabled?
  • Did the product have the right integration?
  • Was traffic encrypted?
  • Was a legitimate admin tool used?
  • Were exclusions configured?
  • Did the event pre-date deployment?
  • Had telemetry expired?

A quick visibility map can make the gap obvious:

CoveredCorporate Windows endpointsEDR healthy and process telemetry retained.
GapPersonal laptop / SaaS auditNo EDR; limited cloud logging at the time.

If the disputed activity happened in the gap, absence of an endpoint alert tells you very little.

Use independent sources to fill the gap

Look elsewhere:

  • native operating-system records;
  • identity provider;
  • cloud/service audit;
  • network records;
  • email;
  • backups;
  • forensic examination;
  • witnesses or operational records.

Different systems may have observed the same activity from another angle.

A visibility gap is uncertainty, not proof

Poor monitoring does not prove an attack happened.

It also does not prove the environment was safe.

Record the blind spot honestly and investigate through the sources that were available.

The practical point is: map what the security tooling could actually see at the relevant time, then use other evidence to investigate beyond that boundary.

Reference: CIM-028Cyber Incidents & Offender Methods