Skip to content

Detection & logging

Without logs there’s no detection, and without detection an attacker operates unseen for months (the “dwell time”). This card covers what to log, how to turn logs into detections, and the frameworks (MITRE ATT&CK, pyramid of pain) that guide an effective detection strategy.

Endpoint Sysmon (see def-sysmon), EDR, OS logs (Security/4688, PowerShell 4104)
Network firewall, proxy, DNS, NetFlow, IDS/NDR (see def-red)
Identity authentications (4624/4625/4768), AD, IdP/SSO, VPN
Application web servers, databases, WAF, business apps
Cloud CloudTrail/Activity logs, IAM, managed services (see cloud)

Rule of thumb: log what lets you answer “who did what, where, when, and from where”.

1. visibility secure the source (if 4688/4104 isn't logged, there's nothing to detect)
2. normalization common fields (user, host, process, hash, IP) in the SIEM (def-siem)
3. rule/analytic Sigma -> translatable to any SIEM; event correlation
4. triage alert -> investigate -> escalate/close (see def-soc)
- map detections to techniques (T####) to measure COVERAGE, not count loose rules
- DeTT&CT / ATT&CK Navigator: visualize which techniques are covered and the gaps
- prioritize by techniques used by relevant adversaries (see cti-attack)

Pyramid of pain (which IOC hurts the attacker most)

Section titled “Pyramid of pain (which IOC hurts the attacker most)”
Hash trivial for the attacker to change (little pain)
IP/Domain easy to rotate
Artifacts/tools costs more
TTPs (behavior) MAXIMUM pain: changing how they operate is expensive
-> detect BEHAVIOR (TTPs) > chase hashes/IPs
- reduce false positives (alert fatigue kills the SOC) with context and tuning
- document each detection: what it detects, why, how to respond (detection-as-code)
- test detections with emulation (Atomic Red Team, see def-hunting) -> validate real coverage
  • Treat detections as code: versioned, reviewed, tested (Sigma rule repos).
  • Measure MTTD/MTTR and ATT&CK coverage; close gaps prioritizing by real threat.
  • Send everything to the SIEM (SIEM) with enough retention for retrospective hunting and IR (dfir).
  • Protect the logs themselves (integrity, immediate forwarding) against attacker deletion (anti-forensics).
  • Breaches with months of dwell time from lack of logging/detection (Mandiant M-Trends reports).
  • SolarWinds (2020): late detection; drove investment in telemetry and behavioral detection.
  • Ransomware that deletes logs and Shadow Copies before encrypting → log and forward off-host.
  • Inventory of log sources (endpoint/network/identity/app/cloud)
  • Verify key events are logged (4688, 4104, Sysmon)
  • Detections mapped to MITRE ATT&CK (measure coverage)
  • Sigma rules versioned and tested (Atomic Red Team)
  • Centralization in the SIEM with adequate retention
  • False-positive tuning and MTTD/MTTR metrics
  • Log integrity protection and forwarding