Contact us: info@tenendo.com
SOC Detection Assessment
Is your SOC actually detecting threats?
2% of detection rules trigger during real attacks, on average
Most organisations assume their EDR and SIEM are protecting them. The data says otherwise: default configurations and generic rules miss 95%+ of sophisticated attack scenarios. We test your detection against real adversary techniques — then help you fix the gaps.
The hidden blind spots
Even mature security stacks leave gaps that adversaries exploit daily.
Expensive tooling doesn’t guarantee detection. These are the gaps we find in nearly every environment.
Generic detection rules
Vendor rulesets catch only basic Active Directory attacks — and miss environment-specific threats, sophisticated lateral movement, and modern C2 frameworks.
Default EDR configurations
Out-of-the-box settings give baseline cover but fall short against process injection, LSASS dumping, and cloud-native techniques.
Alerts without context
Your SIEM fires thousands of alerts, but analysts can’t correlate events, prioritise threats, or separate real attacks from noise.
No tailored detection logic
Critical assets, privileged accounts, and high-value services lack specific coverage — exactly where adversaries strike first.
Untested incident response
IR playbooks read well on paper, but have never been validated against real attack scenarios in your actual environment.
Unknown dwell-time risk
How long would an attacker stay undetected in your network? Without testing, that’s an assumption — not evidence.
Threat-informed testing
We don’t just scan — we simulate real adversaries, then help you close what they slip through.
PHASE 01
Realistic threat simulation
- Multi-stage killchains mapped to MITRE ATT&CK
- Initial access via credential abuse and phishing
- Lateral movement over WMI, PowerShell remoting, SMB
- Privilege escalation against service & admin accounts
- Persistence via scheduled tasks, WMI subs, registry
- Exfiltration over DNS, HTTPS, and cloud storage
- Modern C2 frameworks and custom tooling
PHASE 02
Detection gap analysis
- Which techniques alert vs. go completely unseen
- Alert quality, context, and correlation capability
- Coverage mapped to your threat model and assets
- EDR configuration weaknesses and telemetry gaps
- SOC triage efficiency and workflow effectiveness
PHASE 03
Purple team & custom rule development
- Environment-specific detection rules for your stack
- Custom logic for privileged accounts & lateral movement
- EDR configuration and logging fine-tuning
- Optimised SIEM correlation and alert thresholds
- Detection-engineering knowledge transfer
- Vendor collaboration where it helps
PHASE 04
Validation & continuous improvement
- Re-run attacks to confirm new rules fire correctly
- Ensure alerts carry enough context to act on
- Validate SIEM integration and workflow efficiency
- Document maturity gains and remaining gaps
- 30-day follow-up for ongoing optimisation
Proven across every engagement
We’ve never run an assessment without finding critical detection gaps.
100%
of assessments uncover blind spots in “mature” environments
95%+
of attack scenarios go undetected with default EDR configs
2%
average detection-rule trigger rate during purple-team exercises
47
undetected persistence mechanisms per assessment
We thought our EDR and SIEM had us covered. Tenendo’s testing showed 95% of their simulated attacks went completely undetected — then they helped us build custom rules that actually work.
— Head of Security, European financial institution
Case study · financial institution
A mature SOC with a leading EDR and SIEM wanted to validate detection ahead of DORA deadlines. What the simulation found:
21/23
initial access missed
33/34
lateral moves missed
47/47
persistence missed
5% → 87% coverage across tested killchains
What you receive
Actionable intelligence — not another report to file away.
/ 01
Executive summary
Business-focused view of detection gaps, risk exposure, and an improvement roadmap for the board and C-level.
/ 02
Technical assessment report
Every technique tested, how your EDR/SIEM responded, each gap found, and specific configuration fixes.
/ 03
Custom detection-rules catalogue
Environment-specific logic, SIEM queries, EDR configs, and correlation rules — MITRE ATT&CK mapped, ready to deploy.
/ 04
Purple team documentation
Full walkthrough of scenarios, defensive responses, collaboration outcomes, and knowledge-transfer sessions.
/ 05
Prioritised remediation roadmap
Risk-ranked plan: quick wins, medium-term improvements, and long-term strategic upgrades to your detection posture.
/ 06
30-day follow-up consultation
Support for rule tuning, false-positive reduction, and validation after rollout — remote or on-site.
Frequently asked
The questions security teams ask us first.
A pentest hunts for vulnerabilities to exploit. SOC effectiveness testing validates detection and response. We assume breach and check whether your SOC can actually see, respond to, and contain sophisticated attacks — purple-team focused, not just offensive red-team work.We already have EDR and SIEM.
A pentest hunts for vulnerabilities to exploit. SOC effectiveness testing validates detection and response. We assume breach and check whether your SOC can actually see, respond to, and contain sophisticated attacks — purple-team focused, not just offensive red-team work.We already have EDR and SIEM.
No. We coordinate closely and run tests safely within agreed windows, with full visibility and control. We can work in isolated environments or in production with appropriate safeguards.
Usually 2–5 weeks depending on scope: around 2 weeks for core testing and initial gap analysis, then 2–3 weeks for purple-team collaboration and custom rule development — plus 30-day follow-up support.
Yes. Our methodology aligns with DORA’s threat-led testing requirements and can be structured to support TIBER-EU, with documentation suitable for regulatory submissions.
That’s often exactly why teams need this. Our purple-team approach minimises the load on your analysts while maximising knowledge transfer — we collaborate efficiently rather than overwhelm.
Yes, when it helps. We’ve collaborated with major EDR vendors to improve detection — benefiting not just the client but their whole customer base.
Find out before an attacker does
See what your SOC would really catch.
135+ Detection Rules. One MITRE ATT&CK-Mapped Playbook.
Get the Tenendo Threat Hunting Detection Rules catalogue: MITRE ATT&CK-mapped detection rules spanning Windows, Linux, macOS, cloud, and container platforms.