flâneur — a map of the web's best reading

Anomaly-based detection workflow: leveraging the Novelty component using EDR log telemetry | by Alex Teixeira | Detect FYI

detect.fyi · 1,370 words · saved by 1 readers

This is a more technical post to exemplify how my workflow goes when designing and implementing a new detection while serving as follow-up from a previous post The role of ‘Novelty’ and ‘Behaviour’ in Computer Forensics & Detection Engineering. When you start following security researchers and their work, it’s truly fascinating the amount of detection use cases that can be derived from there. Let’s take as an example the great article written by John Dwyer (IBM X-Force) in which he highlights many detection aspects around another very common technique leveraged by attackers: DLL Side-Loading. securityintelligence.com There are of course multiple detection opportunities for monitoring such technique, some of them only feasible at the agent-level. That is, when defenders rely on a custom rule leveraging the EDR product, or when file or memory payloads are available for manipulation (ex.: Yara). But as always, here I focus on log-based telemetry monitoring. So what is left for those relyi

Anomaly-based detection workflow: leveraging the Novelty component using EDR log telemetry Alex Teixeira 6 min read · Aug 19, 2021 -- Listen Share This is a more technical post to exemplify how my workflow goes when designing and implementing a new detection while serving as follow-up from a previous post The role of ‘Novelty’ and ‘Behaviour’ in Computer Forensics & Detection Engineering . When you start following security researchers and their work, it’s truly fascinating the amount of detection use cases that can be derived from there. Let’s take as an example the great article written by Jo

Explore this link on the map →

related reading