Your tools see side effects. A targeted attack has none.
A WAF waits for a request that fails validation. EDR waits for a file opened out of pattern. A SIEM waits for a log line that reads wrong. ADR watches one process, and only its surface. A precise attack gives none of them anything until it is over, because it moves as permitted calls across services. Odigos reads the calls.