2026.08.09 · Red Team

What Six Months of Red Team Debriefs Taught Us About Alert Fatigue

Across a run of red team engagements this year, the pattern that stood out wasn’t which techniques evaded detection — it was which ones got caught immediately versus which ones got noticed, logged, and never escalated.

SOC teams facing high alert volume develop a triage instinct that’s necessary for survival but occasionally dangerous: a familiar-looking alert gets deprioritized because it usually turns out to be nothing. We found several cases where our activity was logged correctly but never actioned, because it resembled noise the team had learned to dismiss.

The fix isn’t more alerts — it’s better tuning, and testing detection logic against real adversary behavior often enough to catch when ‘usually nothing’ stops being true.

← back to insights