Inside the Modern SOC: Defending the Cross-Environment Pivot

Imported from official source

Cybersecurity Classified by Officially

Our series, Inside the Modern SOC: Trends and Insights from Unit 42 Managed Services, shares the operational patterns that Unit 42 experts observe, with today's challenge beginning after the initial foothold.

Across Unit 42 investigations, we continue to see adversaries move well beyond where an attack begins. They pivot across the enterprise, avoiding detection by exploiting the visibility gaps created by disconnected security tools.

According to the 2026 Unit 42 Global Incident Response Report, 43% of attacks involved activity across four or more attack surfaces, with some cases spanning as many as eight. As attacks move across cloud, endpoint, network, identity and software-as-a-service (SaaS) environments, analysts must connect activity across security domains before the complete attack path becomes clear.

Following the Attack Across Environments

An investigation may begin with what appears to be an isolated event. An endpoint generates an alert. A cloud administrator provisions a resource outside of normal activity. An unfamiliar application requests elevated permissions. On its own, none of these events necessarily signals a broader attack.

As the attack progresses, related activity begins appearing elsewhere. Permissions may change within a SaaS application. Cloud resources may be provisioned or reconfigured. Sensitive data may be staged for exfiltration. New network connections may emerge between systems that rarely communicate.

When these signals are investigated separately, security teams can miss the connection between them and the larger attack taking shape across the environment.

The complete picture often becomes clear only when activity across security domains is connected. AI-driven correlation connects signals that initially appear unrelated, helping analysts reconstruct how an adversary gained access, where they moved, what they accessed and what they were attempting to accomplish.

This is an extract. The publication continues at the source.

Read the original at the source: https://unit42.paloaltonetworks.com/soc-cross-environment-pivot/

Officially imported this from Palo Alto Networks Unit 42’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Palo Alto Networks Unit 42 — imported from official source
Official source
https://unit42.paloaltonetworks.com/feed/ RSS
Imported
September 18, 2026 11:34
Versions
1 recorded
Identity
https://unit42.paloaltonetworks.com/?p=187343

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.