With CrowdStrike reporting that in 2024, 79% of the detections they observed were malware-free, we can expect a whole lot of pain coming right up. And it’s even more worrisome given that back in 2021, that number was 62%.

CrowdStrike’s 2025 Global Threat Report is always an eye-opener. And sadly for your current SIEM, it could also be ringing its death knell. All because of the rise of hands-on-keyboard attacks.

When CrowdStrike says ‘malware-free’, what they mean is that cybercriminals have turned to hands-on-keyboard techniques. These techniques blend seamlessly with your users’ legitimate workday activities – making them harder to detect. And they’re far more deadly than good old (we can spot you pretty easily if we try) malware.

What are hands-on-keyboard attacks?

Hands-on-keyboard, aka HOK attacks, interactive intrusions, or human-operated attacks, involve a human on a keyboard (no prizes for guessing that) actively controlling a compromised system in real-time.

Unlike other attacks, they don’t use pre-written scripts. Instead, the bad actor manually navigates their way through your networks, looking for and exploiting any vulnerabilities and executing commands directly.

There are a couple of things that make HOK attacks so dangerous. The first is that the attacker is there in your system, so they can adjust their approach based on the environment at hand. This allows them to evade detection more effectively while also spotting weaknesses that an automated attack might overlook. And the other is that they’re much harder to spot as they enter your systems using stolen credentials (such as compromised account passwords) and then leverage legitimate tools and software.

But what about good old malware?

Sorry, but that’s old news. While in the past, malware may have got all the big headlines, it’s been truly superseded by the activity of these hands-on-keyboard adversaries as they evade traditional security solutions and present new detection challenges.

(The irony is that we all thought the threat was coming from AI attacks, not actual humans sitting at real keyboards. But more on AI later!)

How’s that 79% stat going to impact you?

That’s a fair question – and an important one.

Unlike traditional malware, HOK methods bypass ‘traditional’ (note: that word is a big hint) security measures by mimicking normal users or administrators executing commands using business-as-usual software. Everything looks plausible and normal. This, of course, makes it damned hard for ‘traditional’ security solutions (including your current SIEM) to spot. There are no malware downloads to be intercepted, and the software tools don’t raise alarms. Everything looks legit.

So when these ROK attacks are spotted, it’s often too late – the damage is done, the data breached, and the show almost over.

How quickly, you ask? The CrowdStrike 2022 Global Threat Report reports that “an [HOK] adversary takes an average of 1 hour and 38 minutes to move laterally from the moment of initial access to the moment they can infect additional critical endpoints.”

Looks like a duck, quacks like a duck

With your average HOK attack looking and acting like a genuine user, and making all the right moves, you’d almost forgive your current cybersecurity systems for not spotting that, in fact, your duck is a dragon.

That is, if the consequences weren’t so potentially devastating.

So, how can you face this new future? It’s going to be a case of modernisation. Your existing detection and response strategies will need an overhaul. And if you have an older SIEM (Security Information and Event Management) system, you’d be justified in feeling anxious.

A traditional SIEM primarily focuses on collecting and analysing logs from various sources, and issuing alerts when it spots actions that defy predefined rules or patterns. Chances also are that it may lack the capabilities to analyse the complex, real-time interactions of an HOK attack.

In short, relying on your old SIEM to protect your organisation is like duck shooting with a fishing rod.

What does a next-gen SIEM look like, then?

Next-gen SIEM leverages AI and Machine Learning to provide real-time intelligence as your HOK attacker stalks through your systems. It’s only through real-time intelligence that you can stay informed about emerging threats, anticipate attacks, and prioritise critical security efforts.

A good example is CrowdStrike’s Falcon Next-Gen SIEM, which CrowdStrike says “Empowers you to stop breaches and streamline your SOC by unifying industry-best detection, world-class threat intelligence, blazing-fast search, and AI-led investigation in one platform.”

So, what are the key differences in how traditional SIEMs handle hands-on-keyboard attacks, vs next-gen?

  1. Smarter spotting

Traditional SIEMs are built around static rules and signatures, so they usually only notice a HOK attack is underway if an existing rule is broken.

Meanwhile, next-gen platforms can proactively spot odd behaviour (instead of waiting for a rule to be broken). For example, if an adversary tries something brand-new – say, running an unusual PowerShell command at 2 a.m., when all your team should be in bed, it knows that things are amiss and bad actors are on the prowl. How? Well, they stream data from cloud services, endpoints, and identity systems, and layer machine-learning UEBA – that’s User / Entity Behaviour Analytics – on top. So they KNOW that your users don’t work at 2 a.m., even if they often use PowerShell.

  1. Speedier spotting!

At a time when every second counts, traditional and next-gen SIEMs handle speed and context quite differently. Older SIEMs batch-process logs, meaning your analyst may not see the puzzle pieces for minutes or even hours. Once they spot that all is not well, they must stitch the story together by hand. By comparison, a next-gen SIEM analyses events as they happen, automatically compiles a timeline of the attacker’s steps, and flags their lateral movement or privilege-escalation attempts (in near real-time). So you have one heck of a head start when it comes to responding!

  1. Stopped on the spot

Finally, the response and scale differences between old and new SIEMS are like night and day. With a traditional SIEM, an alert typically ends up in a ticket queue. From there, your analysts must jump into other consoles to kill a session or disable an account (yeah, manually). Whereas a next-gen SIEM can quickly jump into action as they have a baked-in SOAR (Security Orchestration, Automation and Response) playbook. So all the things that an analyst would normally do – like isolating a workstation, revoking a token, or blocking a command-and-control domain will happen the moment a HOK attack is confirmed. And as next-gen SIEMs are cloud-based, elastic cloud back-end resources absorb the surge of logs generated by an active breach.

Does that all mean a next-gen SIEM is the answer?

Nope. While a next-gen SIEM is an important component, you also need other independent layers as security safeguards. So if one fails or is bypassed, you’ve still got other lines of defence laid in place – just in case.

You can think of this layered security approach as a series of concentric rings around your data, applications and users. Each ring consists of different countermeasures that complement rather than duplicate one another. So your organisation is well and truly ringfenced to keep the bad actors out.

These layers can include basic physical actions such as locking your server room, comprehensive security policies, and securing your network perimeter, endpoints and devices.

If you’re not feeling suitably layered up to ward off hands-on-keyboard attacks, let’s talk.

Published On: May 22nd, 2025 / Categories: Security /

Leave A Comment

Subscribe to Receive the Latest Updates

Get our latest recommendations, advice and offers direct to your inbox.

We won’t share your details – but you can read more in our Privacy Policy.