Anomaly-based detection workflow: leveraging the Novelty component using EDR log telemetry | by Alex Teixeira | Detect FYI
This is a more technical post to exemplify how my workflow goes when designing and implementing a new detection while serving as follow-up from a previous post The role of ‘Novelty’ and ‘Behaviour’ in Computer Forensics & Detection Engineering. When you start following security researchers and their work, it’s truly fascinating the amount of detection use cases that can be derived from there. Let’s take as an example the great article written by John Dwyer (IBM X-Force) in which he highlights many detection aspects around another very common technique leveraged by attackers: DLL Side-Loading. securityintelligence.com There are of course multiple detection opportunities for monitoring such technique, some of them only feasible at the agent-level. That is, when defenders rely on a custom rule leveraging the EDR product, or when file or memory payloads are available for manipulation (ex.: Yara). But as always, here I focus on log-based telemetry monitoring. So what is left for those relyi
Anomaly-based detection workflow: leveraging the Novelty component using EDR log telemetry Alex Teixeira 6 min read · Aug 19, 2021 -- Listen Share This is a more technical post to exemplify how my workflow goes when designing and implementing a new detection while serving as follow-up from a previous post The role of ‘Novelty’ and ‘Behaviour’ in Computer Forensics & Detection Engineering . When you start following security researchers and their work, it’s truly fascinating the amount of detection use cases that can be derived from there. Let’s take as an example the great article written by Jo
Explore this link on the map →related reading
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Mediumdetect.fyi
- Use customizable anomalies to detect threats in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Mediumdetect.fyi
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- Intrusion Detection | Computer Securitytextbook.cs161.org
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Dealing with Noisy Behavioral Analytics in Detection Engineering | CMU Software Engineering Instituteinsights.sei.cmu.edu
- Build for Detection Engineering, and Alerting Will Improve (Part 3) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com