
from Sila Ozeren Hadjioglusecurity research engineer at Picus Security.
The prevent result tells you what the control detects. It doesn’t tell you what stops this control.
Now in its fourth year, the Blue Report 2026 from Picus Labs measures how corporate prevention and detection are actually done in productionin more than 338 million attack simulations run in real customer environments from January to June 2026.
The title is a true restoration, with a caveat: yes, prevention effectiveness increased from 62% to 69%back to its peak in 2024.
But that number is a stack-wide average and masks a softer, more vulnerable interior.
The same controls that block a well-known attack tool allow a quieter version of the same technique to slip right past your defenses. What decides the outcome is not the product in place, but how recognizable the attacker’s method is and whether anyone has tested for the silent variant.
Security tests based on IOC and TTP measure different things
Whether a defense is sustained depends on which of the two questions you ask it.
IOC-based testing asks if the control recognizes a known error. Malware samples circulating in the wild are delivered as download attempts, and perimeter controls such as firewalls, web proxies, and secure email gateways either block them or not.
For this layer, this is the right tool: stopping known-bad content at the edge is what these controls are for.
Behavioral TTP-based testing asks whether a control stops an action in a random way. Not “do you catch Mimics?” but “can a process on this host even get credential?”
That’s the question endpoint and intrusion detection controls must answer, because by the time they’re turned on, the adversary is almost always already executing.
Artifacts are cheap to modify; behavior is not.

Yes, you need both. And yes, you have to challenge the finance people who will say you don’t.
The asymmetry is structural and intentional.
Unfortunately, the edge is also slipping away.

In this year’s data, The IOC-based prevention rate for malware downloads fell to 50% in customer environments, from 60% last year and 71% in 2024..
Even the layer that signatures cover best is giving way. And the passing result here says nothing about the behavior underneath, which is where the Mimikatz result comes in. Here’s a review: not good.
Your controls stop the version of the attack they recognize. Take the same behavior in a quieter way and it passes while your last test still says it’s covered.
See what’s really stopping your stack in Blue Report 2026 and test the behavior instead of the procedure.
Change the way Mimikatz dumps credentials, and prevention drops from 94% to 3%
with Picus Standalone Penetration Testcustomer environments worked with the same tool, Mimikatz, for the same purpose in three ways. The results for prevention were shocking and could not have been more different.
-
Dump credentials from LSASS process memory, the classic and heavily signed trailwas blocked 94% from trials. good
-
Downloading RDP credentials from other memory locations with the same tool: 17%. it’s not good
-
Reading LSA Secrets from local registry: 3%. Terrifying.
All three are siblings under the technique of one parent, Dump OS Credentials (T1003)all three end with the attacker holding your valuable credentials.
The only variable was how noticeable the route was. In this case, Mr. Spock’s classic “live long and prosper” has become “sneak in quietly and prosper.”

The mechanics explain the spread.
The LSASS path is appropriately strong: a process opens an lsass.exe handler and reads its memory, in other words, an event that vendors have instrumented for years. Reading LSA Secrets never affects lsass; runs as SYSTEM and reads a hive from a registry indistinguishable from normal privileged activity. A control built around the first event has nothing to trigger for the second.
And even that 94% is thinner than it looks. It was measured against a known build of an open source tool whose recognizability depends on how it’s compiled, not what it does.
-
Rename the signature key strings or recompile it and the hash and signal tokens become new.
-
Load it reflectively and the code never hits disk to be caught.
-
Or skip this build and do the same dump with a Microsoft-signed utility like ProcDump or comsvcs.dll, then analyze it offline.
Everyone ends up the same way, an attacker with your credentials in hand. Behavior never changes. Only what the signature looks for does.
In the environment, prevention drops to 37%
Mimikatz is a behavior; the same division runs throughout the interior. The overall prevention rate of 69% measures how well the controls stop attacks at the border. Standalone penetration testing measures something more difficult: what an attacker can actually accomplish after getting inside as an “authenticated user.” In the full set of them actions after a compromise, only 37% are blocked.
Perimeter stops two attacks in three; once inside, that drops to just one in three.

Noisy actions caught: lateral traffic is detected about 90% of the time, UAC bypass about 85%, credential reuse and Active Directory abuse about 63%.
Then, unfortunately, the floor falls out.
Identity material read passively from memory and registry: 22%, with secret retrieval from local registry blocked? Less than 1%. Detection and Collection: 10%, SharpHound’s domain enumeration and local file collection are almost completely unopposed.
This 22% is the register variant in scale, and 10% is the same profile: p nothing for the indicator to bind to, it’s full, unrestricted progress toward the attacker’s goal.
Closing the gap
Play both and read what each measures.
Known-bad testing is the basis for perimeter control: firewalls, web proxies, WAFs, secure email gateways. They deliver known malicious samples like download attempts and check if the edge blocks them, which tells you the perimeter is holding, but nothing about the behavior underneath and what’s going on inside.
Behavior validation is the other half and belongs to the endpoint and discovery layer: EDR, IDS, SIEM content. Proving that credential access is covered means testing every route to it: LSASS memory, registry, alternate memory locations, native tools, recompiled builds.
Validate only the known procedure and you are closing an item that is actually still open, the most dangerous misjudgment a validation program can produce.
Doing this by hand doesn’t scale, which is where Picus Royak enter: the orchestration layer that manages the many behavioral variations of an attack in your environment and validates each against the controls you’ve implemented so coverage is proven by behavior, not by a procedure that the signature already recognizes.
Are you finally ready for some good news? None of this requires a bigger stack. This requires knowing which controls you already have will break the chain, so each disclosure becomes a decision you can defend: Patch, Mitigate, Monitor, or Accept with Evidence.
Read the full report
The findings above represent only one thread The Blue Report 2026Picus Labs’ fourth annual survey of how enterprise prevention and detection is taking hold in production, not in the lab.
There’s much more inside:
-
how your industry and region actually scored this year.
-
The year most exploited vulnerabilitiesmost stop at less than 25% of attempts.
-
The threat groups and ransomware prevention lost the most ground.
-
The detection errors behind a 58% log score and 14% warning rate.
Download the Blue Report 2026 to see how your industry is valued and where to focus first.
Sponsored and written by Peak security.
