
WE PREDICTED (Jan 2026)
<10-15% of cases need malware RE 90%+ attribution from identity, cloud and infrastructure telemetry Malware becomes disposable loader logic
79% of detections are malware-free ~90% of IR cases involve identity loopholes Investigations hinge on identity/cloud logs Telemetry gaps doubled year over year
79% of detections are malware-free, up from 40% in 2019
~90% of Unit 42 IR cases involved identity loopholes
67% of incidents began with identity compromise, not malware 2x
2x increase in telemetry gaps missing logs now #2 IR factor
OUR UPDATED POSITION
On track. Investigations have shifted decisively to identity, cloud and infrastructure telemetry, while binaries are increasingly disposable. Log retention, API/audit visibility and infrastructure correlation are now the core of attribution. Treat identity and cloud telemetry as tier-1 forensic evidence and extend retention well beyond default windows.



Reverse engineering required in ~50%+ of high-severity incidents

Between 2024-2025~20-30% of incidents involve a recoverable malicious binary

In 2026 and beyond <10-15% of cases will require malware reverse engineering


