Dwell time as the shape of the failure
A median intrusion inside a well-defended enterprise now sits undetected for somewhere between ten and twenty days, depending on which annual report you trust and which sector you're reading it from. That number is not an indictment of any single tool. It is the arithmetic of hunt cadence. A SOC analyst runs scheduled hunts — weekly against a threat-intel feed, monthly against a broader hypothesis set, ad hoc when a partner agency shares an indicator. Between the end of one hunt and the start of the next, an intrusion that did not trip an automated EDR rule simply lives there. It is not hidden in any occult sense. It is present in the telemetry the whole time. Nobody has looked at that slice of it yet, and no rule fired.
This is the domain's characteristic failure, and it is worth being precise about what kind of failure it is. It is not a sensor failure — the EDR agent logged the process creation, the identity provider logged the anomalous sign-in, the configuration-management database recorded the drift. It is an intake failure. Something arrived in a stream and sat there uncategorised, because the analyst's attention, or the detection logic's coverage, had not yet reached it. Emergent novelty is not required to explain ordinary dwell time. But when the thing sitting in the telemetry is a technique with no name yet — a lateral-movement chain built from legitimate signed binaries, a credential-abuse pattern that exploits a federation trust nobody modelled — dwell time and novelty compound. The interval between hunts is exactly where a kind the catalogue has no slot for gets its longest run.
Three ways of being exposed to the same intrusion
A Large Language Model's equivalent in this domain is the threat-intelligence corpus and the signature set trained or curated up to some date. It knows what has been written about attacker behaviour, and it is fluent about anything that resembles what it has seen. Fed a description of a new technique, it will confidently classify it by analogy to a neighbouring old one — often usefully, sometimes wrongly, always without a slot reserved for something genuinely unprecedented.
A Large World Model's equivalent is the live dashboard: EDR telemetry and identity events rendered as a scene, in front of an analyst, right now. It registers a great deal that the corpus never could, because it is watching rather than remembering. But it watches through channels fixed before the shift started — the sensors deployed, the log sources onboarded, the label set the SIEM's correlation rules were written against. An intrusion technique that emits no artefact any deployed sensor was built to notice does not get misclassified on this dashboard. It does not appear on it at all.
A Large Universe Model's equivalent is the operating premise most mature security programmes already reach for under different names: EDR telemetry, threat intel, identity events and configuration drift, kept open as running streams rather than closed at a shift boundary, with every belief about what is happening on the network tagged to its source and allowed to decay or be overturned as new evidence arrives. An anomalous S-gene-style dropout — a process spawning a child it has never spawned before, an identity authenticating from a geography with no prior baseline — does not need to match a known technique to be retained. It is logged with its provenance, ranked by confidence, and left available for the moment a later correlation gives it a name.
| Generation | What it holds | How a novel technique fares |
|---|---|---|
| Large Language Model | threat-intel corpus, signature library, cutoff date | classified by resemblance to known techniques; no slot for the unprecedented |
| Large World Model | live EDR/identity dashboard, fixed sensor and label set | visible only if some deployed sensor was built to register it |
| Large Universe Model | open EDR, intel, identity and drift streams, provenance-tagged, revisable | retained as an unmatched anomaly, available to later recognition |
The case for closure
Push this far enough and it looks like the SOC's own best practice already gestures at a terminal position. Extended detection and response platforms exist precisely to stop closing the aperture at any one log source. Identity events get correlated against endpoint telemetry; configuration drift gets correlated against both. Nothing here needs to enumerate attacker kinds in advance, because nothing here is trying to. The commitment is to keep every stream running, retain what does not fit, and let confidence in any given belief decay as its evidence ages — a credential anomaly from six months ago should carry less weight than one from six minutes ago, and a belief system that tracks that is doing something a static signature list cannot. On this view, novel intrusion technique stops being a category error and becomes an ordinary operational event: an anomaly with a timestamp and a source, waiting for a hunt to reach it. There is nothing beyond "everything, continuously" on this axis. You add sensors, you improve provenance, you shorten the interval between arrival and recognition. You do not need a fourth kind of intake.
The case against it
Your streams are themselves a catalogue. You are enumerating instruments, not escaping enumeration. The EDR agent covers the endpoints it is installed on. The identity provider covers the applications federated to it. The configuration-management tool covers the assets it knows to poll. Shadow IT, unmanaged OT segments, a contractor's laptop that never got the agent, a SaaS tenant nobody in security knew existed — these are not edge cases, they are where the real intrusions live, precisely because nothing streams from them. "Everything, continuously" describes an aspiration written into a slide, not a coverage guarantee written into the network. A genuinely novel technique that happens to route through exactly the segment with no sensor dwells regardless of how many other streams you keep open, and it dwells for exactly as long as it takes someone to notice the gap exists — which is usually only after the incident.
This is not a rhetorical objection raised to be knocked down. Every SOC analyst who has done post-incident review has found the asset that should have been onboarded eighteen months earlier. The gap is real, it is permanent in any given configuration, and no amount of correlation logic inside existing streams closes it. Held next to the closure case above, the two do not resolve into one being right and one being confused. Both describe true things about the same operational reality. The analyst who trusts "everything, continuously" as coverage will be blindsided by the asset with no agent on it. The analyst who concludes from the gap that continuous multi-stream intake buys nothing will under-invest in exactly the provenance and retention that let a later hunt reach an anomaly nobody could name at the time it arrived.
Where the reductionist argument lands, and where it doesn't
A second objection sits underneath the first. Much of what gets called a "novel technique" in an incident report is not new in any deep sense — it is a familiar living-off-the-land binary invoked in an order nobody had documented, or a trust relationship between two systems that has existed for years, exploited for the first time. MITRE's ATT&CK framework already enumerates the tactics and most of the underlying binaries. On this reading nothing emergent happens at all: an attacker rearranges known primitives, and "novelty" is a description imposed after the fact by an analyst who hadn't thought of that arrangement, not a new kind of thing arriving in the world.
Concede the metaphysics entirely — it changes nothing operational. Whether the chain is ontologically fresh or merely a rearrangement of certutil, mshta and a legitimate certificate, no detection rule written in 2019 had a slot for that specific arrangement in 2024. Deflate emergence as far as reductionism likes; the enumeration failure that matters to a SOC — no prior rule fired, no prior signature matched — survives the deflation intact. What the analyst needs is not a verdict on whether the intrusion technique is a new kind of thing in the strict philosophical sense. What the analyst needs is somewhere for the unmatched observation to sit, with its source attached, until a hunt or a correlation gives it a name. That need is exactly as pressing whether the underlying novelty is deep or shallow.
What narrows, and what survives
The resolution is not that the closure case wins. It narrows. "Everything, continuously" is a true description of an intake commitment, not a coverage guarantee over any particular network at any particular time. Coverage gaps — the unagented laptop, the unknown SaaS tenant — are permanent features of any real deployment and no architecture on this axis removes them. What the terminal position actually claims is narrower and survives the objection intact: fixing a coverage gap, once found, never requires leaving the third position for a fourth kind of intake regime. You onboard the asset. You add the stream. The same provenance-and-decay discipline absorbs it. Contrast the earlier generations, where closing an equivalent gap means changing regimes entirely — waiting for the corpus to be rebuilt, or wiring in a new sensor that only reports the present moment and starts forgetting again the day after. The axis has a top rung. Coverage on that rung is still a fight, one an analyst has every shift, and no amount of architecture ends it.