Telemetry Coverage
The goal of analyzing telemetry coverage is to evaluate the completeness and effectiveness of your organization’s data sources in detecting adversarial activity. By systematically testing telemetry gaps using Atomic Red Team (ART) scenarios, defenders can identify missing data, validate detection rules, and prioritize hardening efforts. This process ensures that telemetry pipelines are robust against evasion techniques and provide actionable insights for incident response.
Understanding Telemetry Gaps¶
Telemetry gaps occur when critical data sources (e.g., event logs, process records, network traffic) are missing, incomplete, or insufficient to detect adversarial behavior. These gaps allow attackers to evade detection by exploiting unmonitored system activities. For example, if process creation events are not logged, an attacker could execute persistence mechanisms without triggering alerts.
To identify gaps, defenders must:
1. Inventory active telemetry sources (e.g., Windows Event Logs, Sysmon, WMI, network sensors).
2. Map attack patterns to required data (e.g., lateral movement requires process creation and network telemetry).
3. Validate coverage by simulating adversarial actions and checking if telemetry captures the behavior.
Atomic Red Team as a Testing Framework¶
Atomic Red Team provides pre-validated attack simulations that align with MITRE ATT&CK frameworks. Each test is designed to mimic a specific technique (e.g., T1059.001 – PowerShell execution) and relies on telemetry to detect the activity. By running these tests, defenders can:
- Confirm whether their telemetry sources capture the technique.
- Identify missing data sources (e.g., missing process creation logs).
- Validate detection rules and alerts.
For example, the T1059.001 test executes PowerShell code. If process creation events are not logged, the test may evade detection, revealing a telemetry gap.
Methodology for Assessing Coverage¶
1. Inventory Telemetry Sources¶
Use commands like Get-WindowsEvent -ListLog (Windows) or journalctl --list-boots (Linux) to identify active data sources. For example:
Microsoft-Windows-Sysmon/Operational) are enabled.
2. Execute Atomic Tests¶
Run ART tests that target specific MITRE techniques. For example:
3. Analyze Coverage¶
Compare test outcomes with expected telemetry. For instance:
- If a test creates a new process but no ProcessCreation event is logged, the telemetry pipeline lacks coverage for this technique.
- Use tools like Splunk, ELK, or native log analyzers to search for relevant events.
4. Prioritize Gaps¶
Rank gaps based on risk (e.g., high-impact techniques like T1027 – indicator removal) and feasibility of remediation.
Common Telemetry Gaps¶
| Technique | Missing Data | Example Scenario |
|---|---|---|
| T1059.001 | Process creation logs | Attacker executes PowerShell without logging |
| T1027 | File system telemetry | Attacker deletes logs or artifacts |
| T1071 | Network traffic monitoring | Attacker exfiltrates data without network alerts |
| T1052 | Registry telemetry | Attacker modifies registry keys without detection |
Mitigation Strategies¶
- Enable missing data sources:
- For Windows, enable
SysmonorMicrosoft-Windows-Sysmon/Operationallogs. -
For Linux, configure
auditdto monitor critical files. -
Implement correlation rules:
-
Use SIEM tools to correlate events (e.g., process creation + network connection).
-
Continuous testing:
- Schedule regular ART test runs to validate telemetry coverage over time.
Key takeaways¶
- Telemetry gaps enable attackers to evade detection; systematic analysis is critical.
- Atomic Red Team tests provide a structured way to validate coverage against MITRE techniques.
- Prioritize gaps based on risk and remediation feasibility.
- Regularly update telemetry pipelines and correlation rules to adapt to evolving threats.
- Combine technical testing with log analysis to ensure comprehensive visibility.