Skip to content

Security1 publisher3 min readPublished

Prevention back to 69%, and a 91-point gap inside one technique

Picus says its 338-million-simulation dataset shows prevention recovering. The same dataset shows one credential-dumping tool blocked 94% of the time by one route and 3% by another.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • The Blue Report 2026 from Picus Labs, now in its fourth year, measures how enterprise prevention and detection perform in production across more than 338 million attack simulations run in real customer environments from January through June 2026.
  • Prevention effectiveness rose from 62% to 69%, back to its 2024 peak; the figure is a stack-wide average that masks a softer, more vulnerable interior.
  • The IOC-based prevention rate for malware downloads fell to 50% across customer environments, from 60% last year and 71% in 2024.
  • Dumping credentials from LSASS process memory with Mimikatz, described as the classic and heavily signatured path, was blocked in 94% of attempts.
  • Pulling RDP credentials from other memory locations with the same tool was blocked in 17% of attempts.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Picus Labs has published the fourth edition of its Blue Report, drawing on more than 338 million attack simulations run in live customer environments from January through June 2026, and says prevention effectiveness across the stack rose from 62% to 69%, back to its 2024 peak [1][2]. In the same dataset, one credential-dumping tool aimed at one objective was blocked in 94% of attempts by its loudest route and 3% by its quietest, which is a strong hint that the stack-wide number is scoring recognizability rather than protection [5][7].

The three-way test is the part worth keeping. Using Picus Autonomous Penetration Testing, customer environments ran the same tool, Mimikatz, at the same objective by three paths [20]. Dumping credentials from LSASS process memory was blocked in 94% of attempts; pulling RDP credentials from other memory locations, 17%; reading LSA Secrets from the local registry, 3% [5][6][7]. All three are siblings under OS Credential Dumping (T1003), and all three end with the attacker holding credential material [8]. The spread between best and worst is 91 percentage points for one outcome [18].

The mechanics are not mysterious, and Picus spells them out. The LSASS path produces a matchable event: a process opens a handle to lsass.exe and reads its memory, something vendors have instrumented for years [9]. The LSA Secrets path never touches lsass, runs as SYSTEM and reads a registry hive, and is difficult to separate from ordinary privileged activity, so a control built around the first event has nothing to fire on for the second [10].

Even the 94% is thinner than it reads. According to the author, it was measured against one known build of an open-source tool, whose recognizability lives in how it was compiled rather than in what it does [11]. Rename the strings a signature keys on or recompile, and the hash and markers are new; load it reflectively and nothing lands on disk; or skip that build entirely and take the same dump with a Microsoft-signed utility such as ProcDump or comsvcs.dll, then parse it offline [12].

The perimeter number moves the same way. Picus puts the IOC-based prevention rate for malware downloads at 50% this year, down from 60% last year and 71% in 2024 [4], a 21-point slide over two years in the layer that signatures cover best [19].

The distinction the report is built on is worth restating plainly, because it decides what your last test actually proved. IOC-based testing asks whether a control recognizes known bad: samples are delivered as download attempts and firewalls, web proxies and secure email gateways either block them or do not [13]. TTP-based testing asks whether the action can be completed by any route, which is the only question that matters once the adversary is already executing [14]. Artifacts are cheap to change; behavior is not [15].

Read the provenance too. The piece is bylined by Sila Ozeren Hacioglu, a security research engineer at Picus Security, the numbers come from the company's own simulation tooling in its own customers' environments, and the article closes by asking you to download the report [16][20].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories