Skip to content

Telemetry Gaps

Detecting and mitigating telemetry gaps is a foundational task for Blue Teams, as these gaps directly influence the ability to detect adversarial activity. Prioritizing critical telemetry gaps requires a structured approach that balances the attack surface of an environment with the potential impact on detection capabilities. This section outlines techniques to evaluate and prioritize telemetry gaps based on these factors, ensuring resources are allocated to areas with the highest risk.


Assessing Attack Surface Exposure

Telemetry gaps are most critical when they occur in systems or processes that form the core of an organization’s attack surface. To identify these gaps:

1. Map Critical Assets and Attack Vectors

  • Technique: Use asset inventory tools (e.g., PowerShell for Windows hosts, nmap for network devices) to catalog systems, services, and data stores.
  • Example:

    Get-EventLog -LogName System | Where-Object { $_.Source -like "*Security*" }
    
    This command checks for missing Security event logs, which are critical for detecting credential theft or privilege escalation.

  • Prioritization Rule: Focus on telemetry gaps in systems handling sensitive data, external-facing services, or privileged accounts.

2. Evaluate Log Coverage for Common Attack Stages

  • Technique: Cross-reference MITRE ATT&CK techniques with available telemetry. For example, gaps in Process Creation or Network Connection telemetry can hinder detection of execution or exfiltration.
  • Example:
    # Check if sysmon logs capture process creation events  
    grep "EventID=1" /var/log/syslog | wc -l
    
    Missing EventID=1 entries indicates a gap in process monitoring.

Evaluating Detection Impact

A telemetry gap’s severity depends on its impact on existing detection rules and incident response workflows.

1. Quantify Coverage Gaps in Detection Rules

  • Technique: Analyze how many detection rules (e.g., SIEM alerts, EDR policies) rely on the missing telemetry.
  • Example:
    -- SQL query to find rules dependent on "Process Creation" telemetry  
    SELECT COUNT(*) FROM detection_rules WHERE telemetry_type = 'Process Creation';
    
    If 30% of rules depend on this telemetry, the gap is high-priority.

2. Simulate Adversarial Behavior

  • Technique: Use tools like Atomic Red Team to test how adversarial actions (e.g., Command and Scripting Interpreter, Persistence) evade existing telemetry.
  • Example:
    # Test if a process injection bypasses telemetry  
    Invoke-AtomicTest T1059.001
    
    This simulates a process injection attack and validates whether telemetry captures the activity.

Prioritization Frameworks

Combine attack surface and detection impact into a prioritization model:

1. Risk Matrix

  • Axes: X-axis = Attack Surface (High/Low), Y-axis = Detection Impact (High/Low).
  • Example: A gap in a high-attack-surface system with high detection impact (e.g., missing network traffic logs on a DMZ server) is a critical priority.

2. Cost-Benefit Analysis

  • Technique: Estimate the cost of implementing telemetry (e.g., sensors, log collectors) versus the potential reduction in risk.
  • Example: Deploying a lightweight EDR agent on a critical server may cost $500 but prevent a $1M breach.

Case Study: Prioritizing a Telemetry Gap

Scenario: A Blue Team identifies a gap in Registry Key Modification telemetry on a domain controller.
- Attack Surface: Domain controllers are high-value targets for lateral movement.
- Detection Impact: Missing registry telemetry could allow adversaries to persist undetected.
- Action: Deploy a registry monitoring tool (e.g., Sysmon with EventID=12 enabled) and update detection rules to flag suspicious modifications.


Key takeaways

  • Prioritize telemetry gaps in systems with high attack surface (e.g., external-facing servers, privileged hosts).
  • Quantify the impact of gaps on detection rules and incident response workflows.
  • Use frameworks like risk matrices or cost-benefit analysis to balance resource allocation.
  • Validate gaps through adversarial testing and real-world scenario simulation.