SOC

MTTD

Mean Time to Detect (MTTD) is the average time from the start of an attack to its detection.

Mean Time to Detect (MTTD) is the average time from an attack's start to its detection. It shows how long an attacker can operate unnoticed within an environment.

How it works

For each confirmed incident, the first malicious activity's time is determined retrospectively. This time is then compared with the time of the first Alert. The average across all incidents gives the MTTD. The exact start time can often only be set after the investigation.

For example, an investigation shows an attacker gained access on Monday at 14:00 using a stolen password. The first Alert occurred on Tuesday at 09:30 when they launched an admin tool. The time to detection is therefore around 19.5 hours. A rule for unusual logins would have spotted the entry sooner.

What to look out for

  • Coverage: The MTTD heavily depends on which log sources are connected.
  • Measurement method: Some providers measure from log ingestion time. This makes the figure look better than it is.
  • Testing: Purple team exercises show if detection rules are effective in practice.
  • Gaps: Techniques that are repeatedly detected late indicate missing detection rules.

Relationship with MTTR

A low MTTD is of little use if no one intervenes afterwards. Therefore, MTTD and MTTR should always be reported together.

How to reduce MTTD

The most important step is complete coverage of critical log sources. This includes identity, email, endpoints and cloud consoles. Rules for early attack phases, like unusual logins or new admin rights, can also help. Threat hunting can also find attacks that do not trigger any rules. After each incident, analyse which signal could have triggered an earlier Alert. Then, enhance your detection capabilities accordingly.

How we implement it

You can see metrics for detection and response in our SOC KPI Reporting. Findings from incidents are incorporated into our detection engineering.