Blog Post

What an AI Correlation Rule Cannot See

October 6, 2026

Table of Contents

A correlation rule can be tuned. The window can be widened, the join key improved, a source promoted from optional to required. Each of those is a parameter with a defensible setting.

‍

What remains after all of it is the residual, meaning the events that would produce a finding if a source existed for them, which is a form of residual risk expressed in detection terms. Naming it is the question an auditor asks after being shown a detection, and the answer is not a tuning exercise.

‍

What Is in the Residual?

‍

Six recognizable categories, and treating them as one list is why the remedy usually misses.

‍

  • Unobserved activity: Actions on systems no source covers, including unmanaged endpoints and resources nobody registered.
  • Encrypted payload: The contents inside a tunnel, where the rule sees timing, endpoints and volume.
  • Events outside the window: Activity deliberately spaced to fall between the boundaries a correlation requires.

‍

Three more concern interpretation rather than observation. Intent, since the rule sees a command and not why it ran. Legitimate tooling, since administrative utilities are used daily by the people they are meant to catch. Novel variation completes the set, since a rule matching a known pattern does not match a modified one.

‍

Which Half Responds to More Telemetry?

‍

The first three, and recognizing the split is what stops a budget going to the wrong remedy.

‍

Source coverage graph showing eight telemetry categories with four filled, indicating which carried this event and which contributed nothing
Which categories are connected and which carried an event is the picture a coverage residual can be read from, and it says nothing about the inference residual.

Unobserved activity, encrypted payload and windowing are all cases where the answer exists and nobody is watching. A new source, an endpoint agent, a decryption point or a wider window resolves each, so the residual shrinks by acquiring observation. These are coverage problems and they have prices.

‍

The Second Half Does Not

‍

Intent, legitimate tooling and novel variation are cases where the observation exists and does not determine the answer. A rule sees the administrator running the utility, and no additional source tells you whether they meant harm. Buying more telemetry does not help, because the missing thing is not an observation.

‍

What Addresses an Inference Residual?

‍

Constraint rather than detection, which is the only lever that operates where inference fails.

‍

If you cannot tell whether an administrative tool is being abused, reduce what the tool can reach. An abused instance then does less, and the residual stops mattering as much without becoming smaller. The control acts on consequence rather than on identification.

‍

Which Is Where the Two Halves Converge

‍

A coverage residual is closed by buying observation. An inference residual is bounded by narrowing authority. Both end up in the same investment conversation and they are not substitutes, so a program that only buys telemetry has addressed half the residual and reported all of it, and ranking by what each measure removes is where the two get compared.

‍

Why Is a Stated Residual a Credibility Asset?

‍

Because the alternative answer is not believable, which is the brief version of the auditor's whole line of questioning.

‍

Behavioral activity chart with an anomaly excursion above the expected envelope, alongside a panel showing four routine signals triangulating to one identity
A detection presented with the signals that carried it invites the next question, which is what would have carried an event these four did not.

Shown a detection, an auditor asks what it misses. An answer that nothing significant escapes it invites probing and usually rewards it. A stated residual, classified by whether each item is a coverage or an inference limit, demonstrates that the method was understood rather than deployed.

‍

Which Moves the Conversation

‍

From whether the detection is adequate, which is a technical argument nobody wins, to whether the residual is acceptable, which is a risk decision the organization is entitled to make and to document. It is a better conversation to be having, and the questions a telemetry claim has to survive is what it opens with.

‍

Can the Residual Be Enumerated?

‍

Not completely, and saying so is part of what makes the rest credible.

‍

Novel variation is unbounded by definition, since a technique nobody has seen cannot be listed. So a stated residual is a floor on what the method misses rather than a complete account, and presenting it as complete reintroduces the overclaim it was meant to fix.

‍

What Makes the Floor Useful Anyway?

‍

Every item on it is actionable and priced. An unlogged system can be instrumented, an inference limit can be bounded by narrowing authority, and a windowing limit can be widened at a stated cost in noise. A floor with prices against it is a plan, and an unbounded worry is not.

‍

Which Residual Item Is Most Often Missed?

‍

The windowing one, because it looks like a solved parameter rather than a permanent limit.

‍

Any correlation requiring events within an interval can be defeated by spacing them outside it. Widening the window catches slower activity and admits more coincidence, so the parameter trades one failure for the other rather than eliminating either. There is no setting at which the residual disappears.

‍

What Follows From That?

‍

Stating the interval and what falls outside it, rather than presenting the window as tuned. A detection correlating within five minutes is blind to a sequence spread across an afternoon, and whether that matters depends on the scenario rather than on the setting, which why a window is the width it is sets out from the parameter side.

‍

Who Owns Each Half?

‍

Different functions, which is why an undifferentiated residual list gets acted on by nobody.

‍

Coverage limits belong to whoever runs telemetry, since closing one means deploying an agent, onboarding a log source or extending a decryption point. Inference limits belong to whoever grants entitlements, because bounding one means reducing what an identity or a tool can reach. Neither function can act on the other's half.

‍

Which Explains a Common Stall

‍

A residual presented to a security operations team lists items half of which they cannot address, so the list returns as a request for budget they would not spend on telemetry. Splitting the list before circulating it sends each item to the function that can act, and an obligation split across functions is the failure mode when it is not split.

‍

What Should Be Reported Upward?

‍

Both counts separately, with the coverage half priced and the inference half expressed as the authority that would need narrowing. A single residual count invites a single answer, and the two halves do not have one.

‍

What Should Be Recorded Per Detection?

‍

Three things, and none takes long once the classification is understood.

‍

The residual items, split into coverage limits and inference limits, since the two have different remedies and different owners. The price of closing each coverage item, so the decision is a funding question rather than an open finding. Then the correlation interval and what falls outside it, stated rather than implied. An AI Interaction Data Fabric reduces the coverage half by joining sources that individually miss things, and it does nothing for the inference half, which is worth saying plainly.

‍

Half the Residual Is Not a Coverage Problem

‍

What a correlation rule cannot see divides into six recognizable categories, and those divide further into two classes with different remedies. Unobserved activity, encrypted payload and events outside the window are all cases where the answer exists and nobody is watching, so acquiring observation shrinks the residual and each item has a price. Intent, legitimate tooling and novel variation are cases where the observation exists and does not settle the question, so more telemetry contributes nothing and the lever is narrowing authority instead. A program that only buys sources has addressed half the residual and reported all of it. The residual also cannot be fully enumerated, which makes a stated floor with prices against each item the honest version. Kovrr's AI Security and Governance Platform reduces the coverage half and records which sources carried each finding.

‍

To see which sources carried each finding and which contributed nothing, book a demo mapped to your own estate.

Yakir Golan

CEO

Detection Residual FAQs

Speak to an Expert

What is detection coverage residual?

Can more telemetry close every detection blind spot?

How do you address an inference limit in detection?

Should you state a detection rule's blind spots to an auditor?

Can a detection residual be fully enumerated?

Why is the correlation window a permanent limit rather than a setting?