The Picus Blue Report 2026, based on over 338 million attack simulations in production environments, reveals a split in enterprise defense effectiveness. While perimeter prevention improved from 62% to 69%, post-compromise prevention remains critically weak at 37%. The report highlights that quiet techniques like reconnaissance and credential theft are rarely blocked, with domain mapping stopped only 10% of the time and registry-based credential theft under 1%. Even Mimikatz, a well-known credential-dumping tool, is blocked 94% of the time when targeting LSASS memory but almost never when reading from the registry. Detection is also lagging: logging reached 58%, but alerting stayed at 14%. The report emphasizes that signature-based controls fail against stealthy behavior and calls for behavioral testing, detection engineering, and continuous validation.
Malware: Mimikatz, Play ransomware
Companies: Picus Security, VirusTotal
Products: Picus Blue Report 2026, Picus Red Report 2026
Original source: thehackernews.com