Skip to main content
ConceptsSIEMXDR

What is MTTD (Mean Time to Detect)?

Mean Time to Detect is the average elapsed time between when a security incident begins and when the SOC first identifies it. Lower MTTD means threats are caught faster, reducing attacker dwell time and potential damage.

Definition

MTTD (Mean Time to Detect)
Mean Time to Detect is the average elapsed time between when a security incident begins and when the SOC first identifies it. Lower MTTD means threats are caught faster, reducing attacker dwell time and potential damage.

How MTTD (Mean Time to Detect) Works

MTTD starts when the initial compromise or malicious activity actually occurs and ends when the SOC generates an alert or an analyst first identifies the activity. In practice this is measured from a handful of timestamps: the estimated incident-start time, reconstructed from forensic artifacts like file creation times, process start times, or attacker-controlled infrastructure registration dates, the event_time recorded in the log source, and the alert_time when a correlation rule fires or an analyst flags the activity during a hunt. Averaging that gap across all incidents in a measurement period gives the MTTD figure, and it encompasses the full detection pipeline: log ingestion latency, how long between an event occurring and it landing in the SIEM, detection rule evaluation, alert enrichment, and initial triage before the alert is confirmed as a genuine finding.

Industry benchmarks vary dramatically by maturity level. Well-tuned SOCs with strong SIEM and XDR coverage can achieve MTTD under ten minutes for known attack patterns matched by existing rules, while attacks relying on novel techniques or living-off-the-land binaries with no matching signature can go undetected for weeks or months, contributing to the long dwell times reported in industry breach studies. The gap between these outcomes is almost entirely a function of detection coverage, not analyst speed: an attack with no corresponding rule or behavioral baseline simply does not generate an alert, no matter how fast the analysts on shift are.

Factors that reduce MTTD include comprehensive log collection across endpoints, network, and identity, well-tuned correlation rules with low false-positive rates so analysts trust and act on alerts quickly, 24/7 monitoring coverage, active threat hunting that surfaces activity before automated rules catch up, and fast threat intelligence integration that lets new IOCs get matched against historical logs immediately. Factors that increase it include log source gaps, such as an unmonitored server or a cloud service without forwarding configured, alert fatigue from high false-positive rates, limited monitoring hours, and no hunting program to catch what rules miss. MTTD is tracked per incident and per alert type, and a sudden increase after an infrastructure change, a new cloud service, a network re-architecture, a log forwarder outage, is a strong early signal of a coverage gap that needs immediate attention.

MTTD (Mean Time to Detect) in SOC Operations

MTTD is a core SOC performance metric displayed on every analyst dashboard, and it directly measures how quickly the team spots threats before they escalate. During a shift, your personal MTTD reflects how rapidly you recognize and begin investigating alerts once they land in your queue, a function of both search skill and how well you prioritize by severity and asset criticality. Improving MTTD is one of the primary goals of detection engineering programs, and it is one of the clearest ways to show measurable impact as an analyst: closing a log coverage gap or tuning a rule to fire earlier in the kill chain directly moves the number. SOCSimulator tracks response times within scenarios so you can benchmark your personal triage speed against realistic targets and identify where your workflow is slower than it should be, whether that is slow pivoting between tools or spending too long confirming alerts that turn out to be low-risk.

Free

Practice MTTD (Mean Time to Detect) in a Real SOC

SOCSimulator provides hands-on training with realistic SIEM, XDR, and Firewall interfaces. Build real analyst skills investigating mttd (mean time to detect) scenarios with zero consequences, free.

More Concepts Terms

Career Path

SOC Analyst (Tier 1) Career Guide: Salary & Skills

Tier 1 SOC Analysts are the front line. You monitor alert queues, triage incoming detections, classify them as true or f…

Read more
Career Path

Detection Engineer Career Guide: Salary & Skills

Detection Engineers build the rules, analytics, and automated workflows that determine what the SOC can see. You transla…

Read more
Career Path

Security Engineer Career Guide: Salary & Skills

Security Engineers build and maintain the infrastructure that SOC analysts depend on. You deploy SIEMs, configure firewa…

Read more
Comparison

SOCSimulator vs LetsDefend: Comparison

SOCSimulator wins on operational realism. You get multi-tool shift simulation with SLA pressure, noise injection, and al…

Read more
Comparison

SOCSimulator vs CyberDefenders: Comparison

SOCSimulator trains the operational workflow: alert triage, correlation, and response under pressure. CyberDefenders tra…

Read more
Tool

SIEM Training Console: SOCSimulator

The SIEM console in SOCSimulator replicates the workflow of enterprise platforms like Splunk Enterprise Security, Micros…

Read more
Tool

XDR Training Console: SOCSimulator

The XDR console in SOCSimulator replicates the investigation workflow of platforms like CrowdStrike Falcon, Microsoft De…

Read more
Technique

MITRE ATT&CK® Techniques: Detection Training Library

Browse all MITRE ATT&CK® techniques with detection strategies and example alerts.

Read more
Career Path

Cybersecurity Career Paths: 2026 Guide

Explore SOC analyst career paths with salary data, required skills, and certification roadmaps.

Read more
Playbook

SOC Investigation Playbooks: Step-by-Step Guides

Practitioner investigation playbooks with decision trees and real SIEM queries.

Read more
Feature

Shift Mode: Real-Time SOC Simulation

Practice alert triage under realistic time pressure with SLA timers and noise injection.

Read more
Feature

Operations: Guided Training Operations

Structured CTF-style investigation operations covering real-world attack scenarios.

Read more