Contact us: info@tenendo.com

SOC Detection Assessment

Is your SOC actually detecting threats?

2% of detection rules trigger during real attacks, on average

Most organisations assume their EDR and SIEM are protecting them. The data says otherwise: default configurations and generic rules miss 95%+ of sophisticated attack scenarios. We test your detection against real adversary techniques — then help you fix the gaps.

Detection coverage
5% killchain detected
Initial access9%
Lateral movement3%
Privilege escalation5%
Persistence0%
Data exfiltration4%
detected undetected
200+ engagements delivered
In-house tooling & payloads
PCI QSA & ISO 27001 LA

The hidden blind spots

Even mature security stacks leave gaps that adversaries exploit daily.

Expensive tooling doesn’t guarantee detection. These are the gaps we find in nearly every environment.

Generic detection rules

Vendor rulesets catch only basic Active Directory attacks — and miss environment-specific threats, sophisticated lateral movement, and modern C2 frameworks.

Default EDR configurations

Out-of-the-box settings give baseline cover but fall short against process injection, LSASS dumping, and cloud-native techniques.

Alerts without context

Your SIEM fires thousands of alerts, but analysts can’t correlate events, prioritise threats, or separate real attacks from noise.

No tailored detection logic

Critical assets, privileged accounts, and high-value services lack specific coverage — exactly where adversaries strike first.

Untested incident response

IR playbooks read well on paper, but have never been validated against real attack scenarios in your actual environment.

Unknown dwell-time risk

How long would an attacker stay undetected in your network? Without testing, that’s an assumption — not evidence.

Threat-informed testing

We don’t just scan — we simulate real adversaries, then help you close what they slip through.

PHASE 01

Realistic threat simulation

  • Multi-stage killchains mapped to MITRE ATT&CK
  • Initial access via credential abuse and phishing
  • Lateral movement over WMI, PowerShell remoting, SMB
  • Privilege escalation against service & admin accounts
  • Persistence via scheduled tasks, WMI subs, registry
  • Exfiltration over DNS, HTTPS, and cloud storage
  • Modern C2 frameworks and custom tooling

PHASE 02

Detection gap analysis

  • Which techniques alert vs. go completely unseen
  • Alert quality, context, and correlation capability
  • Coverage mapped to your threat model and assets
  • EDR configuration weaknesses and telemetry gaps
  • SOC triage efficiency and workflow effectiveness

PHASE 03

Purple team & custom rule development

  • Environment-specific detection rules for your stack
  • Custom logic for privileged accounts & lateral movement
  • EDR configuration and logging fine-tuning
  • Optimised SIEM correlation and alert thresholds
  • Detection-engineering knowledge transfer
  • Vendor collaboration where it helps

PHASE 04

Validation & continuous improvement

  • Re-run attacks to confirm new rules fire correctly
  • Ensure alerts carry enough context to act on
  • Validate SIEM integration and workflow efficiency
  • Document maturity gains and remaining gaps
  • 30-day follow-up for ongoing optimisation

Proven across every engagement

We’ve never run an assessment without finding critical detection gaps.

100%

of assessments uncover blind spots in “mature” environments

95%+

of attack scenarios go undetected with default EDR configs

2%

average detection-rule trigger rate during purple-team exercises

47

undetected persistence mechanisms per assessment

We thought our EDR and SIEM had us covered. Tenendo’s testing showed 95% of their simulated attacks went completely undetected — then they helped us build custom rules that actually work.

— Head of Security, European financial institution

Case study · financial institution

A mature SOC with a leading EDR and SIEM wanted to validate detection ahead of DORA deadlines. What the simulation found:

21/23

initial access missed

33/34

lateral moves missed

47/47

persistence missed

5% → 87% coverage across tested killchains

What you receive

Actionable intelligence — not another report to file away.

/ 01

Executive summary

Business-focused view of detection gaps, risk exposure, and an improvement roadmap for the board and C-level.

/ 02

Technical assessment report

Every technique tested, how your EDR/SIEM responded, each gap found, and specific configuration fixes.

/ 03

Custom detection-rules catalogue

Environment-specific logic, SIEM queries, EDR configs, and correlation rules — MITRE ATT&CK mapped, ready to deploy.

/ 04

Purple team documentation

Full walkthrough of scenarios, defensive responses, collaboration outcomes, and knowledge-transfer sessions.

/ 05

Prioritised remediation roadmap

Risk-ranked plan: quick wins, medium-term improvements, and long-term strategic upgrades to your detection posture.

/ 06

30-day follow-up consultation

Support for rule tuning, false-positive reduction, and validation after rollout — remote or on-site.

Frequently asked

The questions security teams ask us first.

A pentest hunts for vulnerabilities to exploit. SOC effectiveness testing validates detection and response. We assume breach and check whether your SOC can actually see, respond to, and contain sophisticated attacks — purple-team focused, not just offensive red-team work.We already have EDR and SIEM.

A pentest hunts for vulnerabilities to exploit. SOC effectiveness testing validates detection and response. We assume breach and check whether your SOC can actually see, respond to, and contain sophisticated attacks — purple-team focused, not just offensive red-team work.We already have EDR and SIEM.

No. We coordinate closely and run tests safely within agreed windows, with full visibility and control. We can work in isolated environments or in production with appropriate safeguards.

Usually 2–5 weeks depending on scope: around 2 weeks for core testing and initial gap analysis, then 2–3 weeks for purple-team collaboration and custom rule development — plus 30-day follow-up support.

Yes. Our methodology aligns with DORA’s threat-led testing requirements and can be structured to support TIBER-EU, with documentation suitable for regulatory submissions.


That’s often exactly why teams need this. Our purple-team approach minimises the load on your analysts while maximising knowledge transfer — we collaborate efficiently rather than overwhelm.

Yes, when it helps. We’ve collaborated with major EDR vendors to improve detection — benefiting not just the client but their whole customer base.

Find out before an attacker does

See what your SOC would really catch.

135+ Detection Rules. One MITRE ATT&CK-Mapped Playbook.

Get the Tenendo Threat Hunting Detection Rules catalogue: MITRE ATT&CK-mapped detection rules spanning Windows, Linux, macOS, cloud, and container platforms.