What is MTTD (Mean Time to Detect)?
Mean Time to Detect is the average elapsed time between when a security incident begins and when the SOC first identifies it. Lower MTTD means threats are caught faster, reducing attacker dwell time and potential damage.
Definition
- MTTD (Mean Time to Detect)
- Mean Time to Detect is the average elapsed time between when a security incident begins and when the SOC first identifies it. Lower MTTD means threats are caught faster, reducing attacker dwell time and potential damage.
How MTTD (Mean Time to Detect) Works
MTTD starts when the initial compromise or malicious activity actually occurs and ends when the SOC generates an alert or an analyst first identifies the activity. In practice this is measured from a handful of timestamps: the estimated incident-start time, reconstructed from forensic artifacts like file creation times, process start times, or attacker-controlled infrastructure registration dates, the event_time recorded in the log source, and the alert_time when a correlation rule fires or an analyst flags the activity during a hunt. Averaging that gap across all incidents in a measurement period gives the MTTD figure, and it encompasses the full detection pipeline: log ingestion latency, how long between an event occurring and it landing in the SIEM, detection rule evaluation, alert enrichment, and initial triage before the alert is confirmed as a genuine finding.
Industry benchmarks vary dramatically by maturity level. Well-tuned SOCs with strong SIEM and XDR coverage can achieve MTTD under ten minutes for known attack patterns matched by existing rules, while attacks relying on novel techniques or living-off-the-land binaries with no matching signature can go undetected for weeks or months, contributing to the long dwell times reported in industry breach studies. The gap between these outcomes is almost entirely a function of detection coverage, not analyst speed: an attack with no corresponding rule or behavioral baseline simply does not generate an alert, no matter how fast the analysts on shift are.
Factors that reduce MTTD include comprehensive log collection across endpoints, network, and identity, well-tuned correlation rules with low false-positive rates so analysts trust and act on alerts quickly, 24/7 monitoring coverage, active threat hunting that surfaces activity before automated rules catch up, and fast threat intelligence integration that lets new IOCs get matched against historical logs immediately. Factors that increase it include log source gaps, such as an unmonitored server or a cloud service without forwarding configured, alert fatigue from high false-positive rates, limited monitoring hours, and no hunting program to catch what rules miss. MTTD is tracked per incident and per alert type, and a sudden increase after an infrastructure change, a new cloud service, a network re-architecture, a log forwarder outage, is a strong early signal of a coverage gap that needs immediate attention.
MTTD (Mean Time to Detect) in SOC Operations
MTTD is a core SOC performance metric displayed on every analyst dashboard, and it directly measures how quickly the team spots threats before they escalate. During a shift, your personal MTTD reflects how rapidly you recognize and begin investigating alerts once they land in your queue, a function of both search skill and how well you prioritize by severity and asset criticality. Improving MTTD is one of the primary goals of detection engineering programs, and it is one of the clearest ways to show measurable impact as an analyst: closing a log coverage gap or tuning a rule to fire earlier in the kill chain directly moves the number. SOCSimulator tracks response times within scenarios so you can benchmark your personal triage speed against realistic targets and identify where your workflow is slower than it should be, whether that is slow pivoting between tools or spending too long confirming alerts that turn out to be low-risk.
Practice MTTD (Mean Time to Detect) in a Real SOC
SOCSimulator provides hands-on training with realistic SIEM, XDR, and Firewall interfaces. Build real analyst skills investigating mttd (mean time to detect) scenarios with zero consequences, free.
Related Terms
Mean Time to Respond (MTTR) is the average elapsed time between when a security incident is detected...
Security Information and Event Management (SIEM) is a platform that aggregates, normalizes, and corr...
Extended Detection and Response (XDR) is a security platform that unifies telemetry from endpoints, ...
Alert triage is the structured process of reviewing, prioritizing, and investigating security alerts...
Threat hunting is the proactive, human-led process of searching through security telemetry to find h...
Incident response (IR) is the structured, repeatable process an organization follows before, during,...
More Concepts Terms
Related SOC Training Resources
SOC Analyst (Tier 1) Career Guide: Salary & Skills
Tier 1 SOC Analysts are the front line. You monitor alert queues, triage incoming detections, classify them as true or f…
Read more Career PathDetection Engineer Career Guide: Salary & Skills
Detection Engineers build the rules, analytics, and automated workflows that determine what the SOC can see. You transla…
Read more Career PathSecurity Engineer Career Guide: Salary & Skills
Security Engineers build and maintain the infrastructure that SOC analysts depend on. You deploy SIEMs, configure firewa…
Read more ComparisonSOCSimulator vs LetsDefend: Comparison
SOCSimulator wins on operational realism. You get multi-tool shift simulation with SLA pressure, noise injection, and al…
Read more ComparisonSOCSimulator vs CyberDefenders: Comparison
SOCSimulator trains the operational workflow: alert triage, correlation, and response under pressure. CyberDefenders tra…
Read more ToolSIEM Training Console: SOCSimulator
The SIEM console in SOCSimulator replicates the workflow of enterprise platforms like Splunk Enterprise Security, Micros…
Read more ToolXDR Training Console: SOCSimulator
The XDR console in SOCSimulator replicates the investigation workflow of platforms like CrowdStrike Falcon, Microsoft De…
Read more TechniqueMITRE ATT&CK® Techniques: Detection Training Library
Browse all MITRE ATT&CK® techniques with detection strategies and example alerts.
Read more Career PathCybersecurity Career Paths: 2026 Guide
Explore SOC analyst career paths with salary data, required skills, and certification roadmaps.
Read more PlaybookSOC Investigation Playbooks: Step-by-Step Guides
Practitioner investigation playbooks with decision trees and real SIEM queries.
Read more FeatureShift Mode: Real-Time SOC Simulation
Practice alert triage under realistic time pressure with SLA timers and noise injection.
Read more FeatureOperations: Guided Training Operations
Structured CTF-style investigation operations covering real-world attack scenarios.
Read more