Forefront IT Security Services
BlogThreat Exposure
Threat Exposure

Closing the Detection Gap: Validating Your Defences with AETOS

June 2026Forefront IT Security Services3 min read

You have a SIEM, an EDR and a SOC. The only question that matters is whether any of it would actually fire during a real attack, and “I think so” is not an answer you want to give after a breach.

Here is the audit question nobody enjoys. An assessor turns to your SOC lead and asks: “if an attacker dumped credentials from that finance server tomorrow, would you see it?” More often than it should be, the honest answer is “I think so.” “I think so” is not a great thing to be saying after an incident.

Detection is usually assumed, not proven. You buy the SIEM, enable the rule pack, the dashboard goes green, everyone moves on. But between an attacker's action and an analyst being alerted sits a long, fragile chain: the right log source, shipping the right fields, with synchronised clocks, matched by a rule that is written, enabled, and routed to a human with the context to act. Break any single link and the attack happens in silence.

A green dashboard proves your tooling is running. It does not prove your tooling would catch an attacker.

We find the same broken links again and again: a critical log source that stopped shipping months ago and nobody noticed; rules written for a technique the business retired years back while newer ones go uncovered; alerts firing into a queue no one triages; clocks skewed across the estate so correlation silently never matches.

Proving it, technique by technique

Detection-gap analysis swaps the assumption for evidence. We safely replay real attacker techniques, initial access, execution, persistence, credential access, lateral movement, exfiltration, against your environment, every action mapped to MITRE ATT&CK, and watch what your defences actually do. Each technique lands in one of four honest verdicts:

  • Detected it generated an alert your SOC would act on. Good.
  • Gap it was logged, but nothing fired. The evidence exists; the detection to act on it doesn't. Cheapest, highest-value wins on the list.
  • Blind spot no usable telemetry at all. You need new logging or a new sensor before any rule could ever catch it.
  • Pending awaiting evaluation against your SIEM data before a verdict is assigned.

The line between a gap and a blind spot is the whole game. A gap is usually a rule you can write this week against logs you already hold. A blind spot means you never collected the evidence in the first place, a bigger, more expensive problem, and the one most maturity assessments quietly skip over.

A loop, not a report

Because Forefront runs this through AETOS, the exposure-management platform we supply, the same validation re-runs after every rule change, tooling upgrade or SOC hand-over. The output isn't a maturity score or a colour on a heat-map; it is a prioritised list of specific, reproducible gaps, each tied to the technique that exposed it and the control that should have caught it. Run the techniques, find the gaps, tune the rules, re-run to prove the fix. After a few cycles, coverage stops being an article of faith and becomes something you can put in front of an auditor.

A penetration test tells you where you are vulnerable. Detection-gap validation tells you whether you'd even notice. You want both: one measures your defences, the other measures whether you can see them being tested.

Security Front Door

Find the right level of security for your business.

One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.

Forefront
UK Penetration Testing & Red Team Operations
Loading...