Detection & logging
Without logs there’s no detection, and without detection an attacker operates unseen for months (the “dwell time”). This card covers what to log, how to turn logs into detections, and the frameworks (MITRE ATT&CK, pyramid of pain) that guide an effective detection strategy.
What to log (key sources)
Section titled “What to log (key sources)”Endpoint Sysmon (see def-sysmon), EDR, OS logs (Security/4688, PowerShell 4104)Network firewall, proxy, DNS, NetFlow, IDS/NDR (see def-red)Identity authentications (4624/4625/4768), AD, IdP/SSO, VPNApplication web servers, databases, WAF, business appsCloud CloudTrail/Activity logs, IAM, managed services (see cloud)Rule of thumb: log what lets you answer “who did what, where, when, and from where”.
From log to detection
Section titled “From log to detection”1. visibility secure the source (if 4688/4104 isn't logged, there's nothing to detect)2. normalization common fields (user, host, process, hash, IP) in the SIEM (def-siem)3. rule/analytic Sigma -> translatable to any SIEM; event correlation4. triage alert -> investigate -> escalate/close (see def-soc)MITRE ATT&CK as a compass
Section titled “MITRE ATT&CK as a compass”- map detections to techniques (T####) to measure COVERAGE, not count loose rules- DeTT&CT / ATT&CK Navigator: visualize which techniques are covered and the gaps- prioritize by techniques used by relevant adversaries (see cti-attack)Pyramid of pain (which IOC hurts the attacker most)
Section titled “Pyramid of pain (which IOC hurts the attacker most)”Hash trivial for the attacker to change (little pain)IP/Domain easy to rotateArtifacts/tools costs moreTTPs (behavior) MAXIMUM pain: changing how they operate is expensive-> detect BEHAVIOR (TTPs) > chase hashes/IPsDetection quality
Section titled “Detection quality”- reduce false positives (alert fatigue kills the SOC) with context and tuning- document each detection: what it detects, why, how to respond (detection-as-code)- test detections with emulation (Atomic Red Team, see def-hunting) -> validate real coverageBlue Team / operation
Section titled “Blue Team / operation”- Treat detections as code: versioned, reviewed, tested (Sigma rule repos).
- Measure MTTD/MTTR and ATT&CK coverage; close gaps prioritizing by real threat.
- Send everything to the SIEM (SIEM) with enough retention for retrospective hunting and IR (dfir).
- Protect the logs themselves (integrity, immediate forwarding) against attacker deletion (anti-forensics).
Real-world cases
Section titled “Real-world cases”- Breaches with months of dwell time from lack of logging/detection (Mandiant M-Trends reports).
- SolarWinds (2020): late detection; drove investment in telemetry and behavioral detection.
- Ransomware that deletes logs and Shadow Copies before encrypting → log and forward off-host.
Testing checklist
Section titled “Testing checklist”- Inventory of log sources (endpoint/network/identity/app/cloud)
- Verify key events are logged (4688, 4104, Sysmon)
- Detections mapped to MITRE ATT&CK (measure coverage)
- Sigma rules versioned and tested (Atomic Red Team)
- Centralization in the SIEM with adequate retention
- False-positive tuning and MTTD/MTTR metrics
- Log integrity protection and forwarding