A new study from Conifers, assessing 14,652 detections across its customer base, reveals that threat detection dashboards often mask serious coverage gaps. The research found that 47% of detections in an average organization require attention, yet all of them still show as deployed on dashboards. Failures fall into five categories: logic bugs that prevent firing, missing telemetry, queries against wrong tables, duplicated detections, and noisy detections that analysts learn to ignore.

The study also measured coverage against each organization's own threat intelligence, finding that on average only 63% of relevant threats have matching detections or hunts. When measured against MITRE ATT&CK techniques, average protection stood at 64%, leaving one in three techniques without reliable detection. The gap stems from the slow, manual process of converting intelligence into detection logic.

Rutger de Boer, CTO at DTX, said the research validates what his company sees daily, noting that telemetry changes make detections stale without anyone realizing. Tom Findling, CEO of Conifers, emphasized that "deployed is not the same as protected." The researchers argue that closing these gaps requires AI to automate the loop from threat intelligence to detections and hunts, while human engineers direct strategy and make judgment calls. However, the source does not provide independent verification of these claims, and the article notes that vendor-controlled detections remain a significant challenge, as teams cannot edit their logic and must choose between suppression or accepting alert flooding.