惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
Y
Y Combinator Blog
T
Tailwind CSS Blog
G
Google Developers Blog
博客园 - Franky
Google DeepMind News
Google DeepMind News
阮一峰的网络日志
阮一峰的网络日志
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 聂微东
爱范儿
爱范儿
博客园 - 【当耐特】
腾讯CDC
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
H
Help Net Security
C
Check Point Blog
大猫的无限游戏
大猫的无限游戏
M
MIT News - Artificial intelligence
博客园_首页
Stack Overflow Blog
Stack Overflow Blog
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

Unit 42

A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity Atomic macOS (AMOS) Stealer Activity Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Identity Abuse Through Trusted Communication Channels Kimwolf v7: An Evolution of the Kimwolf Botnet The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications Inside the Modern SOC: The Identity Front Door ChainDrop: Inside a Self-Propagating npm Worm Token Jacking: Cybercriminals Could Be Stealing Your AI Resources The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software Almost Half of Malware Samples Communicate Direct to IP Pass the Passkey: A Novel Attack Surface in Passwordless Authentication The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks Russian Global Webmail Espionage Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development No Manners Here: The Ruthless Rise of The Gentlemen Ransomware Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation How We Added WebAuthn to a Browser-Based RDP Client
Inside the Modern SOC: Defending the Cross-Environment Pivot
Sharon Maydar · 2026-09-18 · via Unit 42

The Cross-Environment Gap

Our series, Inside the Modern SOC: Trends and Insights from Unit 42 Managed Services, shares the operational patterns that Unit 42 experts observe, with today's challenge beginning after the initial foothold.

Across Unit 42 investigations, we continue to see adversaries move well beyond where an attack begins. They pivot across the enterprise, avoiding detection by exploiting the visibility gaps created by disconnected security tools.

According to the 2026 Unit 42 Global Incident Response Report, 43% of attacks involved activity across four or more attack surfaces, with some cases spanning as many as eight. As attacks move across cloud, endpoint, network, identity and software-as-a-service (SaaS) environments, analysts must connect activity across security domains before the complete attack path becomes clear.

Following the Attack Across Environments

The First Signal

An investigation may begin with what appears to be an isolated event. An endpoint generates an alert. A cloud administrator provisions a resource outside of normal activity. An unfamiliar application requests elevated permissions. On its own, none of these events necessarily signals a broader attack.

The Cross-Environment Pivot

As the attack progresses, related activity begins appearing elsewhere. Permissions may change within a SaaS application. Cloud resources may be provisioned or reconfigured. Sensitive data may be staged for exfiltration. New network connections may emerge between systems that rarely communicate.

When these signals are investigated separately, security teams can miss the connection between them and the larger attack taking shape across the environment.

Reconstructing the Attack Path

The complete picture often becomes clear only when activity across security domains is connected. AI-driven correlation connects signals that initially appear unrelated, helping analysts reconstruct how an adversary gained access, where they moved, what they accessed and what they were attempting to accomplish.

Because attackers don't operate within the boundaries monitored by individual security tools, security operations can't either. Defenders need to follow attacker activity across the enterprise and investigate the intrusion as one connected attack. Doing this consistently requires continuous monitoring and response, along with ongoing optimization of detections, correlation rules and workflows as threats and environments evolve.

How SOC Leaders Can Defend Across Attack Surfaces

Use AI to Investigate the Attack, Not the Alert

As attackers move across security domains, security leaders should evaluate whether their operations can reconstruct a complete attack path rather than respond to isolated alerts. The goal is to use AI-driven correlation to reveal how seemingly unrelated activity connects before an adversary reaches their objective.

Connect Evidence Across the Attack Path

To track adversarial behavior from the first signal across every stage of the attack lifecycle, organizations must connect evidence across their security environment through lateral movement, persistence and impact. True visibility requires cross-domain correlation, while threat hunting should test for attacker behaviors that may not yet have generated an alert. SOC leaders should ensure their platforms automatically correlate activity into unified incident storylines, giving analysts the context to investigate and respond without manually pivoting between tools or teams.

Continuously Test and Evolve Security Operations

Treat every investigation as an opportunity to improve the next one. Review where analysts lost context, where detections or correlation rules could be improved and which response steps created delays. Use those findings to refine detection logic, correlation rules, automation and response playbooks as attacker techniques and the environment evolve.

How Unit 42 Managed Services Applies These Principles

As attacks increasingly span multiple environments, AI-driven correlation and behavioral analytics in the Cortex SecOps platform bring related signals together into a unified investigation. Unit 42 analysts apply frontline expertise and threat intelligence to validate the attack path, investigate coordinated activity and accelerate response.

Our Managed Detection and Response (MDR) analysts continuously investigate suspicious activity while our threat hunters combine AI-powered insights with Unit 42 expertise to proactively search for attacker behaviors that may not yet have generated an alert. Insights from investigations and hunts help strengthen detections, refine correlation rules and improve response workflows across customer environments.

Organizations using Managed XSIAM extend this approach through continuous SOC engineering delivered by Unit 42 experts. Our teams continuously optimize:

  • Data integrations
  • Detection logic
  • Custom correlation rules
  • Automated response playbooks
  • Investigation workflows

Continuous SOC engineering helps reduce investigation and response time by optimizing the detections, correlation rules, automation and workflows that power AI-driven security operations.

The Unit 42 Managed Services Edge

Unit 42 combines expert-led MDR, Managed Threat Hunting and Managed XSIAM to help organizations investigate attacks as one connected incident. Powered by AI-driven capabilities in the Cortex SecOps platform, our experts apply insights from thousands of investigations, threat hunts and incident response engagements to accelerate response and continuously improve security operations.

Learn more about Unit 42 Managed Services.