
Blog Post
What an AI Correlation Rule Cannot See
October 6, 2026
A correlation rule can be tuned. The window can be widened, the join key improved, a source promoted from optional to required. Each of those is a parameter with a defensible setting.
What remains after all of it is the residual, meaning the events that would produce a finding if a source existed for them, which is a form of residual risk expressed in detection terms. Naming it is the question an auditor asks after being shown a detection, and the answer is not a tuning exercise.
What Is in the Residual?
Six recognizable categories, and treating them as one list is why the remedy usually misses.
- Unobserved activity: Actions on systems no source covers, including unmanaged endpoints and resources nobody registered.
- Encrypted payload: The contents inside a tunnel, where the rule sees timing, endpoints and volume.
- Events outside the window: Activity deliberately spaced to fall between the boundaries a correlation requires.
Three more concern interpretation rather than observation. Intent, since the rule sees a command and not why it ran. Legitimate tooling, since administrative utilities are used daily by the people they are meant to catch. Novel variation completes the set, since a rule matching a known pattern does not match a modified one.
Which Half Responds to More Telemetry?
The first three, and recognizing the split is what stops a budget going to the wrong remedy.

Unobserved activity, encrypted payload and windowing are all cases where the answer exists and nobody is watching. A new source, an endpoint agent, a decryption point or a wider window resolves each, so the residual shrinks by acquiring observation. These are coverage problems and they have prices.
The Second Half Does Not
Intent, legitimate tooling and novel variation are cases where the observation exists and does not determine the answer. A rule sees the administrator running the utility, and no additional source tells you whether they meant harm. Buying more telemetry does not help, because the missing thing is not an observation.
What Addresses an Inference Residual?
Constraint rather than detection, which is the only lever that operates where inference fails.
If you cannot tell whether an administrative tool is being abused, reduce what the tool can reach. An abused instance then does less, and the residual stops mattering as much without becoming smaller. The control acts on consequence rather than on identification.
Which Is Where the Two Halves Converge
A coverage residual is closed by buying observation. An inference residual is bounded by narrowing authority. Both end up in the same investment conversation and they are not substitutes, so a program that only buys telemetry has addressed half the residual and reported all of it, and ranking by what each measure removes is where the two get compared.
Why Is a Stated Residual a Credibility Asset?
Because the alternative answer is not believable, which is the brief version of the auditor's whole line of questioning.

Shown a detection, an auditor asks what it misses. An answer that nothing significant escapes it invites probing and usually rewards it. A stated residual, classified by whether each item is a coverage or an inference limit, demonstrates that the method was understood rather than deployed.
Which Moves the Conversation
From whether the detection is adequate, which is a technical argument nobody wins, to whether the residual is acceptable, which is a risk decision the organization is entitled to make and to document. It is a better conversation to be having, and the questions a telemetry claim has to survive is what it opens with.
Can the Residual Be Enumerated?
Not completely, and saying so is part of what makes the rest credible.
Novel variation is unbounded by definition, since a technique nobody has seen cannot be listed. So a stated residual is a floor on what the method misses rather than a complete account, and presenting it as complete reintroduces the overclaim it was meant to fix.
What Makes the Floor Useful Anyway?
Every item on it is actionable and priced. An unlogged system can be instrumented, an inference limit can be bounded by narrowing authority, and a windowing limit can be widened at a stated cost in noise. A floor with prices against it is a plan, and an unbounded worry is not.
Which Residual Item Is Most Often Missed?
The windowing one, because it looks like a solved parameter rather than a permanent limit.
Any correlation requiring events within an interval can be defeated by spacing them outside it. Widening the window catches slower activity and admits more coincidence, so the parameter trades one failure for the other rather than eliminating either. There is no setting at which the residual disappears.
What Follows From That?
Stating the interval and what falls outside it, rather than presenting the window as tuned. A detection correlating within five minutes is blind to a sequence spread across an afternoon, and whether that matters depends on the scenario rather than on the setting, which why a window is the width it is sets out from the parameter side.
Who Owns Each Half?
Different functions, which is why an undifferentiated residual list gets acted on by nobody.
Coverage limits belong to whoever runs telemetry, since closing one means deploying an agent, onboarding a log source or extending a decryption point. Inference limits belong to whoever grants entitlements, because bounding one means reducing what an identity or a tool can reach. Neither function can act on the other's half.
Which Explains a Common Stall
A residual presented to a security operations team lists items half of which they cannot address, so the list returns as a request for budget they would not spend on telemetry. Splitting the list before circulating it sends each item to the function that can act, and an obligation split across functions is the failure mode when it is not split.
What Should Be Reported Upward?
Both counts separately, with the coverage half priced and the inference half expressed as the authority that would need narrowing. A single residual count invites a single answer, and the two halves do not have one.
What Should Be Recorded Per Detection?
Three things, and none takes long once the classification is understood.
The residual items, split into coverage limits and inference limits, since the two have different remedies and different owners. The price of closing each coverage item, so the decision is a funding question rather than an open finding. Then the correlation interval and what falls outside it, stated rather than implied. An AI Interaction Data Fabric reduces the coverage half by joining sources that individually miss things, and it does nothing for the inference half, which is worth saying plainly.
Half the Residual Is Not a Coverage Problem
What a correlation rule cannot see divides into six recognizable categories, and those divide further into two classes with different remedies. Unobserved activity, encrypted payload and events outside the window are all cases where the answer exists and nobody is watching, so acquiring observation shrinks the residual and each item has a price. Intent, legitimate tooling and novel variation are cases where the observation exists and does not settle the question, so more telemetry contributes nothing and the lever is narrowing authority instead. A program that only buys sources has addressed half the residual and reported all of it. The residual also cannot be fully enumerated, which makes a stated floor with prices against each item the honest version. Kovrr's AI Security and Governance Platform reduces the coverage half and records which sources carried each finding.
To see which sources carried each finding and which contributed nothing, book a demo mapped to your own estate.
Detection Residual FAQs
Speak to an ExpertWhat is detection coverage residual?
The set of events that would produce a finding if a source existed for them, meaning what remains uncovered after a correlation rule is fully tuned. It divides into six recognizable categories, being unobserved activity on systems no source covers, encrypted payload contents, events spaced outside the correlation window, intent behind an observed command, abuse of legitimate administrative tooling, and novel variations a pattern-matching rule does not match.
Can more telemetry close every detection blind spot?
No, only about half of them. Unobserved activity, encrypted payload and windowing are cases where the answer exists and nobody is watching, so a new source, an endpoint agent, a decryption point or a wider window resolves each. Intent, legitimate tooling and novel variation are cases where the observation exists and does not determine the answer, so buying more telemetry contributes nothing because the missing thing is not an observation.
How do you address an inference limit in detection?
By constraint rather than detection. If you cannot tell whether an administrative tool is being abused, reduce what the tool can reach, so an abused instance does less and the residual stops mattering as much without becoming smaller. The control acts on consequence rather than on identification, which is the only lever available where the observation exists but does not settle the question.
Should you state a detection rule's blind spots to an auditor?
Yes, because the alternative answer is not believable. Shown a detection, an auditor asks what it misses, and an answer that nothing significant escapes it invites probing and usually rewards it. A stated residual classified by whether each item is a coverage or inference limit demonstrates the method was understood, and moves the conversation from whether the detection is adequate to whether the residual is acceptable.
Can a detection residual be fully enumerated?
No. Novel variation is unbounded by definition, since a technique nobody has seen cannot be listed, so a stated residual is a floor on what the method misses rather than a complete account. Presenting it as complete reintroduces the overclaim it was meant to fix. The floor is useful anyway because every item on it is actionable and priced, which makes it a plan rather than a worry.
Why is the correlation window a permanent limit rather than a setting?
Because any correlation requiring events within an interval can be defeated by spacing them outside it, and widening the window catches slower activity while admitting more coincidence. The parameter trades one failure for the other rather than eliminating either, so there is no setting at which the residual disappears, which argues for stating the interval and what falls outside it.




