Skip to content
CardinalOps
  • Platform

    Platform

    • Threat Coverage Platform
    • Agentic Fleet
  • Use Cases

    Use Cases

    • Map all your detections to MITRE ATT&CK
    • Gain new detections to address critical gaps
    • Identify and fix broken detection rules
    • Pinpoint root causes of noisy rules
    • Continuous Threat Exposure Management (CTEM)
    • Operationalize threat intelligence
    • Measure the depth of ATT&CK coverage
    • Assess and improve your detection posture
    • Embed Detection Engineering into AI SOC
    • Manage detection posture across multiple SIEMs
  • Integrations
  • ROI & Pricing
  • Company

    Company

    • Who we are

      Meet the leadership team, advisors, investors, and mission that drive us forward.

    • Why work here

      Big challenges need big thinkers. Are you up to it?

    • Careers

      Your opportunity to make a difference … for our customers, the world, and yourself.

    • Security & Compliance

      We value the privacy and security of your data.

  • Resources

    Resources

    • Blog
    • Newsroom
    • Webinars & Events
    • White Papers
    • Videos
  • Contact Us
  • Book a Demo
HOME Resources
  • Blog
  • Newsroom
  • Webinars & Events
  • White Papers
  • Videos
  • Enterprises Missing Detections for Around Three-Quarters of all Adversary Techniques

    Enterprises Missing Detections for Around Three-Quarters of all Adversary Techniques

    CardinalOps recently released the Third Annual Report on the State of SIEM Detection Risk which found enterprise SIEMs are missing detections for around three-quarters of all techniques that adversaries use to execute cyberattacks.

  • Enterprises Unprepared to Defend Against MITRE ATT&CK Techniques

    Enterprises Unprepared to Defend Against MITRE ATT&CK Techniques

    Enterprises lack detections for more than three-quarters of all MITRE ATT&CK techniques, while 12% of SIEM rules are broken and will never fire due to data quality issues including misconfigured data sources and missing fields.

  • Study Reveals Alarming Gap in SIEM Detection of Adversary Techniques

    Study Reveals Alarming Gap in SIEM Detection of Adversary Techniques

    The CardinalOps’ 2023 Report on State of SIEM Detection Risk showed that SIEMs can only detect 24% of the techniques listed in MITRE ATT&CK, leaving organizations vulnerable to ransomware attacks, data breaches and other cyber threats.

  • CardinalOps Report Finds Broken Rules in SIEM Systems Increase Cyberattack Risks

    CardinalOps Report Finds Broken Rules in SIEM Systems Increase Cyberattack Risks

    “These findings illustrate a simple truth: Most organizations don’t have good visibility into their MITRE ATT&CK coverage and are struggling to get the most from their existing SIEMs,” said CardinalOps co-founder and CEO Michael Mumcuoglu.

  • Most Enterprise SIEMs Blind to MITRE ATT&CK Tactics

    Most Enterprise SIEMs Blind to MITRE ATT&CK Tactics

    Researchers from CardinalOps analyzed data from production SIEM platforms from companies such as Splunk, Microsoft Sentinel, IBM QRadar, and Sumo Logic, and found that they have detections for just 24% of all MITRE ATT&CK techniques.

  • 2023 Report on State of SIEM Detection Risk

    2023 Report on State of SIEM Detection Risk

    In our third annual report, CardinalOps set out to gain visibility into the current state of use case development and threat detection coverage in enterprise SOCs. We analyzed, aggregated and anonymized data from production SIEM

  • SANS 2023 SOC Survey

    SANS 2023 SOC Survey

    Download the 2023 SOC Survey from the SANS Institute to gain insights from active SOC managers and analysts around best practices for running a SOC.

  • Cybersecurity Summer Reading: 11 Books to Boost Your Career

    Cybersecurity Summer Reading: 11 Books to Boost Your Career

    Phil Neray, VP of Cyber Defense Strategy at CardinalOps suggests adding “Cybersecurity First Principles: A Reboot of Strategy and Tactics” by Rick Howard to your summer reading list. You’ll get a practitioner’s point-of-view on security principles.

  • SOC Meets Cloud: What Changes and What Stays the Same?

    SOC Meets Cloud: What Changes and What Stays the Same?

    Michael Mumcuoglu, CEO & co-founder of CardinalOps, explores critical questions facing security operations center (SOC) leaders charged with supporting their organization’s migration to a cloud operation model and their digital transformation initiatives.

  • Leading Financial Services Organization Uses CardinalOps to Continuously Audit and Remediate Detection Coverage Gaps

    Leading Financial Services Organization Uses CardinalOps to Continuously Audit and Remediate Detection Coverage Gaps

    Tel Aviv Stock Exchange has deployed the CardinalOps platform to identify and remediate missing, broken, and noisy detections, enabling a proactive, threat-informed defense tied to the risks most relevant to them.

  • The Future of Risk-Based Detection

    The Future of Risk-Based Detection

    Join us on June 20 at 3:30 pm EDT for this SANS webinar. SecOps experts discuss major challenges for the modern Security Operations Center and how to operationalize MITRE ATT&CK to build a threat-informed defense.

  • CardinalOps Updates Techniques in MITRE ATT&CK v13 Describing New Adversary Methods for Hijacking Corporate Email Systems

    CardinalOps Updates Techniques in MITRE ATT&CK v13 Describing New Adversary Methods for Hijacking Corporate Email Systems

    The CardinalOps security research team collaborates with MITRE to strengthen ATT&CK, describing new ways in which adversary groups like LAPSUS$ hijack corporate email systems such as Office 365, Microsoft Exchange, and Google Workspace.

Previous Page
1 2 3 4 5
Next Page

Never Miss Another Threat

CardinalOps’ Agentic Detection Engineering represents a fundamental shift in how detection engineering operates. Instead of relying solely on manual effort, it introduces a coordinated system of specialized AI agents that optimize the entire detection lifecycle and fly alongside human detection engineers.

Detection teams can scale without adding headcount. Alert fatigue gives way to signal clarity. Detection lifecycle management becomes streamlined instead of sprawling. Feedback from the SOC finally closes the loop to create better detections over time. 

See it for yourself.

Book a Demo
CardinalOps

Optimize your cyber defense with AI-powered detection engineering.

  • Use Cases
  • Integrations
  • Company
  • Resources

© 2026 CardinalOps

Privacy Policy | Terms & Conditions | Security & Compliance