Skip to content

Remediating Gaps

Intermediate users need to address telemetry gaps by enhancing logging and configuring SIEM systems to detect adversarial activity. This section provides actionable strategies for closing gaps in detection coverage, with a focus on practical implementation.


Strategies for Closing Telemetry Gaps

1. Enhance Log Sources and Granularity

Expand telemetry coverage by enabling verbose logging on critical systems and applications. Prioritize sources that capture process execution, network activity, and user behavior.
Example: Enable Windows Event Log auditing for process creation:

# Enable detailed process creation logging on Windows
auditpol /set /subcategory:"Process Creation" /state:Enabled
Example: Configure Syslog for application-specific logs:
# On Linux, modify /etc/rsyslog.conf to include:
*.info;mail.none;authpriv.none;cron.none    /var/log/messages
authpriv.*                          /var/log/secure

2. Normalize and Centralize Logs

Ensure logs from disparate sources are structured consistently (e.g., JSON format) for SIEM ingestion. Use log shippers like Filebeat or Fluentd to standardize metadata.
Example: Configure Filebeat to parse JSON logs:

# filebeat.yml
processors:
  - json:
      field: "message"
      target: "parsed"

3. Configure SIEM Correlation Rules

Create rules to detect patterns indicative of adversarial behavior, such as lateral movement or privilege escalation. Use threshold-based alerts to reduce noise.
Example: SIEM query for suspicious process execution:

# Generic EQL query for SIEM (e.g., Elastic)
process where event.type == "start" and process.name != "explorer.exe" and process.parent.name != "svchost.exe" and event.duration > 1000

4. Implement Real-Time Monitoring and Alerting

Set up dashboards and alerts for high-priority telemetry streams. Use time-based thresholds (e.g., 5 failed login attempts in 10 minutes) to trigger investigations.
Example: SIEM alert rule for brute-force login attempts:

# Example using Splunk's search syntax
index=auth sourcetype=login | stats count by source, user | where count > 5 | where _time > relative_time(now(), "-10m")

5. Validate and Iterate

Regularly test detection rules against red team artifacts (e.g., from Atomic Red Team) to ensure gaps are closed. Use telemetry analysis to refine rules and expand coverage.


Key takeaways

  • Expand logging to critical systems and normalize data for SIEM ingestion.
  • Configure correlation rules to detect adversarial patterns while minimizing false positives.
  • Monitor in real-time with actionable alerts and validate rules against known threats.
  • Iterate based on telemetry analysis to close gaps and improve detection maturity.
  • Balance coverage with operational overhead to avoid alert fatigue.