You Cannot Escape Me: Detecting Evasions of SIEM Rules in Enterprise Networks | USENIX
Many organizations rely on Security Information and Event Management (SIEM) systems to discover intruders in their network from security-related events such as host and firewall logs. However, our work shows that adversaries can easily evade a large fraction of popular SIEM detection rules that aim to detect malicious command executions on Windows systems. To mitigate these detection blind spots, we introduce a novel concept called adaptive misuse detection, which utilizes supervised machine learning to discover potential rule evasions while keeping false alerts to a minimum. Finally, we present our open-source proof-of-concept implementation of adaptive misuse detection, AMIDES, and demonstrate its fitness for application in large enterprise networks. Cyberattacks have grown into a major risk for organizations. Attackers often succeed to break into target systems despite elaborate preventive measures, with common consequences being data theft or sabotage. In this case, intruders shoul
February 5, 2024 Research Authors: Louis Hackländer-Jansen , Marco Herzog , Rafael Uetz Article shepherded by: Rik Farrow Many organizations rely on Security Information and Event Management (SIEM) systems to discover intruders in their network from security-related events such as host and firewall logs. However, our work shows that adversaries can easily evade a large fraction of popular SIEM detection rules that aim to detect malicious command executions on Windows systems. To mitigate these detection blind spots, we introduce a novel concept called adaptive misuse detection, which utilizes
Explore this link on the map →related reading
- Why Detection Rules Fail: Causes, Effects, and Corrective Actionspicussecurity.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- Evolving Your SIEM Detection Rules: A Journey from Simple to Sophisticated | Databricks Blogdatabricks.com
- Intrusion Detection | Computer Securitytextbook.cs161.org
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- Risk-Based Alerting: The New Frontier for SIEM | Splunksplunk.com
- Best practices for creating custom detection rules with Datadog Cloud SIEM | Datadogdatadoghq.com
- What is Detection Engineering and Why do I Need it?cyberseccafe.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- Creating Cost-Effective, Scalable Detectionsrippling.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Exposing and shutting down an inbox heist in actionredcanary.com