Threat reportThreat IntelligenceTL-2026-1983
Picus Blue Report 2026: Security Controls Block Only 37% of Post-Compromise Attacker Actions Despite 69% Perimeter Prevention
Picus Blue Report 2026 (TL-2026-1983), also tracked as Blue Report 2026, is a medium-severity tracked intrusion set, first published 2026-08-11. It has no confirmed attribution, affects Cross-Industry Enterprise security control stacks (EDR/XDR, SIEM, maps to 15 MITRE ATT&CK techniques (T1003, T1027, T1033), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-1983
- Threat ID
- TL-2026-1983
- Also known as
- Blue Report 2026, Picus Blue Report 2026
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- transport, education, cross-industry
- Target regions
- South Asia, North America, Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Picus Blue Report 2026
Malware and tooling: BlackByte, BlackByte Ransomware - S1180, BlackKingdom, Hive, LockBit, Magniber, Maori, PLAY Ransomware, Playcrypt - S1162, Rorschach Ransomware, Sodinokibi/REvil, faust
How Picus Blue Report 2026 works
Picus Security's Blue Report 2026, analyzing 338+ million attack simulations run in production customer environments between January and June 2026, finds perimeter prevention effectiveness recovered to 69% (its 2024 peak) while post-compromise attacker actions are blocked only 37% of the time. Organizations logged 58% of simulated attacks but generated alerts for just 14%, and log-tampering evasion techniques such as Impair Command History Logging (T1562.003) and System Script Proxy Execution (T1216) were blocked in only 1% and 9% of simulations respectively.
Picus Security published the Blue Report 2026 on August 11, 2026, its fourth annual benchmark of real-world security-control effectiveness built from telemetry generated by the Picus Security Validation Platform, a breach-and-attack-simulation (BAS) product. Picus Labs and the Picus Data Science team analyzed more than 338 million attack simulations executed inside live production customer environments between January and June 2026 — up from 160 million simulations in the 2025 edition and 136 million in the 2024 edition — making it the largest dataset in the report's history.
The headline finding is a widening gap between perimeter and post-compromise defense. Overall prevention effectiveness recovered to 69%, matching the 2024 peak after falling to 62% in the 2025 edition, and endpoint prevention reached 83%. But once a simulated attacker gained a foothold, defenses blocked only 37% of subsequent actions, and IOC-based prevention (blocking on known-bad indicators) sat at 50%. The report attributes the gap to a detection-and-alerting bottleneck rather than a logging bottleneck: organizations logged 58% of simulated attacks, yet only 14% of those attacks (fewer than one in seven) generated an alert, and detection-rule performance/tuning problems accounted for 49% of identified detection-rule issues, up sharply from 24% the prior year.
Technique-level results show the weakest coverage concentrated in the Stealth and Defense Impairment tactics (the current MITRE ATT&CK v19 successors to what was previously the single 'Defense Evasion' tactic) and stealthy post-compromise discovery/collection activity. Impair Command History Logging (T1562.003) was blocked in just 1% of simulations and System Script Proxy Execution (T1216) in just 9%, the two lowest technique-level prevention scores in the report; overall Stealth-tactic prevention averaged only about 10%. Quiet discovery-and-collection actions — enumerating domains (Domain Trust Discovery, T1482), identifying file shares (Network Share Discovery, T1135), discovering active sessions (System Owner/User Discovery, T1033), and collecting credential material (OS Credential Dumping, T1003) — were blocked in only about one in ten attempts. Malware-download prevention (Ingress Tool Transfer, T1105) fell to 50%, down 21 points over the two years since the 2024 edition, and prevention against the Stealth tactic weakened from 53% to 47% year over year. By contrast, conspicuous activity was well defended: Privilege Escalation prevention rose 24 points to 79% (the largest tactic-level gain of the year), and certain lateral movement and privilege escalation techniques were among the best-blocked behaviors overall.
A companion analysis published alongside the report, 'The Tradecraft Behind 2026's Least-Prevented Ransomware Families,' names the ten ransomware strains the Blue Report 2026 dataset found hardest to stop: Play (13% prevention, the lowest of any strain), BlackByte (25%), LockBit (30%), BabLock (31%), Magniber (35%), FAUST (35%), Sodinokibi/REvil (36%), Hive (38%), BlackKingdom (38%), and Maori (38%) — all ten scored 38% or below. The analysis maps each family's evasion tradecraft to specific MITRE ATT&CK techniques within the Stealth and Defense Impairment tactics: Sodinokibi and BlackKingdom rely on Obfuscated Files or Information (T1027); BabLock and LockBit on Disable or Modify Tools (T1685); Magniber on Process Injection (T1055), Reflective Code Loading (T1620), and System Binary Proxy Execution (T1218); BlackByte and BlackKingdom on Indicator Removal (T1070); Play and BlackByte on Masquerading (T1036); Sodinokibi on Modify Registry (T1112); BabLock on Hide Artifacts (T1564); and LockBit and BabLock on Execution Guardrails (T1480). LockBit 5.0 specifically was reported to interfere with Event Tracing for Windows (ETW) to reduce available telemetry.
Sector and regional performance varied sharply year over year: Transportation gained 29 points to reach 79%, while Education lost 30 points to fall to 40%. South Asia moved from last place to a share of first at 71%, while North America recorded the lowest regional prevention score at 60%. Picus co-founder and Picus Labs VP Dr. Süleyman Ozarslan summarized the core takeaway: organizations have gotten much better at stopping attacker activity that creates obvious signals, but 'the problem is what happens before those signals appear' — attackers can quietly map an environment, locate valuable systems, and gather credentials while many defenses remain inactive. Picus recommends validating complete attack paths (not just initial access), with particular emphasis on low-noise post-compromise activity, and shifting detection engineering toward behavioral analytics to reduce reliance on signatures that miss quiet discovery, collection, and ransomware-evasion techniques.
MITRE ATT&CK techniques used in TL-2026-1983
Credential Access
Stealth
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1216 System Script Proxy Execution; T1218 System Binary Proxy Execution; T1480 Execution Guardrails; T1564 Hide Artifacts; T1620 Reflective Code Loading
Discovery
T1033 System Owner/User Discovery; T1135 Network Share Discovery; T1482 Domain Trust Discovery
Defense Impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
defense-impairment
Affected products and versions in Picus Blue Report 2026
- Cross-Industry — Enterprise security control stacks (EDR/XDR, SIEM, NGFW/IPS, log-management pipelines) as deployed in live production environments
Vulnerable versions: Production security-control deployments assessed January-June 2026 across the Picus customer base
Remediation for Picus Blue Report 2026
Immediate actions
- Validate complete attack paths post-compromise — not just perimeter/initial-access controls — using continuous breach-and-attack-simulation testing against production environments
- Prioritize detection engineering for the two lowest-blocked techniques in the dataset: T1562.003 (Impair Command History Logging, 1% blocked) and T1216 (System Script Proxy Execution, 9% blocked)
- Audit SIEM/EDR alerting pipelines where logging coverage (58%) far exceeds alert generation (14%) to close the detection-to-alert conversion gap
- Harden against the top evasion techniques driving 2026's ten least-prevented ransomware families — obfuscated payloads (T1027), tool/log tampering (T1685), process injection (T1055), indicator removal (T1070), masquerading (T1036), registry modification (T1112), reflective code loading (T1620), hidden artifacts (T1564), signed-binary proxy execution (T1218), and execution guardrails (T1480) — since Play (13%), BlackByte (25%), and LockBit (30%) remain the hardest strains to stop
Longer-term hardening
- Shift detection engineering from signature-based rules toward behavioral analytics to catch low-noise discovery/collection activity (domain enumeration, file-share discovery, active-session discovery, credential collection) that current controls miss roughly 90% of the time
- Address the 49% share of detection-rule issues attributable to performance/tuning problems (up from 24% the prior year) through regular rule-health and detection-content reviews
- Re-baseline malware-download (Ingress Tool Transfer) prevention controls, which declined 21 points over two years to 50%
- Re-evaluate sector- and region-specific control posture given large year-over-year swings (Education -30 points, Transportation +29 points, North America lowest of any region at 60%)
- Monitor for Event Tracing for Windows (ETW) tampering and similar telemetry-impairment behavior, reported specifically in LockBit 5.0, as an early indicator of Stealth/Defense-Impairment tradecraft
Timeline of Picus Blue Report 2026
- Picus Security publishes the Blue Report 2024 (136M+ simulations, Jan-Jun 2024), recording prevention effectiveness at 69% -- the peak the Blue Report 2026 later says it 'recovered to.'
- Picus Security publishes the Blue Report 2025 (160M+ simulations, Jan-Jun 2025), showing prevention effectiveness declining to 62% and alert generation at just 14% of simulated attacks.
- The Blue Report 2026 data-collection window opens; Picus customers begin running production attack simulations on the Picus Security Validation Platform that are later aggregated into the report.
- The Blue Report 2026 data-collection window closes; Picus Labs and the Picus Data Science team have compiled more than 338 million attack simulations executed in production environments between January and June 2026.
- Picus Security publishes a companion blog post, 'The Tradecraft Behind 2026's Least-Prevented Ransomware Families,' detailing Blue Report 2026 prevention scores and MITRE ATT&CK technique mappings for the ten least-prevented ransomware strains, led by Play ransomware at 13% prevention.
- Cyber Press publishes coverage of the Blue Report 2026 Play-ransomware findings ('Play Ransomware Scores Just 13% Prevention as Evasion Techniques Bypass Security Controls'), extending distribution of the ransomware-tradecraft findings a day ahead of the full report's press release.
- The Blue Report 2026 press release is syndicated via wire services (e.g., finanznachrichten.de), extending distribution of the findings to international financial/business news outlets.
- Picus Security publishes the Blue Report 2026 and press release 'Picus Research Finds Defenses Block Only 37% of Post-Compromise Attacker Actions,' reporting 69% perimeter prevention but only 37% post-compromise action blocking, 58% logging vs. 14% alerting, and technique-level lows of 1% (T1562.003) and 9% (T1216).
Sources cited for Picus Blue Report 2026
- Picus Research Finds Defenses Block Only 37% of Post-Compromise Attacker Actions
- The Blue Report 2026
- Blue Report (landing page)
- The Tradecraft Behind 2026's Least-Prevented Ransomware Families
- Play Ransomware Scores Just 13% Prevention as Evasion Techniques Bypass Security Controls
- Picus Security: Picus Research Finds Defenses Block Only 37% of Post-Compromise Attacker Actions (wire syndication)
- Picus Security Finds 46% of Enterprise Passwords Vulnerable to Cracking — 2X Increase From 2024 (Blue Report 2025 launch)
- The Blue Report 2025
- The Blue Report 2024
- 40% of Environments are Vulnerable to Full Take Over, New Picus Security Report Unveils
- The Blue Report 2024 by Picus Found 40% of Environments Vulnerable to Full Takeover
- Picus Security (company background)
- Picus Security Leadership
Detection coverage for TL-2026-1983
As of 2026-08-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1983 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.