Telemetry Gaps
Detecting and mitigating telemetry gaps is a foundational task for Blue Teams, as these gaps directly influence the ability to detect adversarial activity. Prioritizing critical telemetry gaps requires a structured approach that balances the attack surface of an environment with the potential impact on detection capabilities. This section outlines techniques to evaluate and prioritize telemetry gaps based on these factors, ensuring resources are allocated to areas with the highest risk.
Assessing Attack Surface Exposure¶
Telemetry gaps are most critical when they occur in systems or processes that form the core of an organization’s attack surface. To identify these gaps:
1. Map Critical Assets and Attack Vectors¶
- Technique: Use asset inventory tools (e.g.,
PowerShellfor Windows hosts,nmapfor network devices) to catalog systems, services, and data stores. -
Example:
This command checks for missing Security event logs, which are critical for detecting credential theft or privilege escalation.
-
Prioritization Rule: Focus on telemetry gaps in systems handling sensitive data, external-facing services, or privileged accounts.
2. Evaluate Log Coverage for Common Attack Stages¶
- Technique: Cross-reference MITRE ATT&CK techniques with available telemetry. For example, gaps in
Process CreationorNetwork Connectiontelemetry can hinder detection of execution or exfiltration. - Example:
MissingEventID=1entries indicates a gap in process monitoring.
Evaluating Detection Impact¶
A telemetry gap’s severity depends on its impact on existing detection rules and incident response workflows.
1. Quantify Coverage Gaps in Detection Rules¶
- Technique: Analyze how many detection rules (e.g., SIEM alerts, EDR policies) rely on the missing telemetry.
- Example:
If 30% of rules depend on this telemetry, the gap is high-priority.
2. Simulate Adversarial Behavior¶
- Technique: Use tools like Atomic Red Team to test how adversarial actions (e.g.,
Command and Scripting Interpreter,Persistence) evade existing telemetry. - Example:
This simulates a process injection attack and validates whether telemetry captures the activity.
Prioritization Frameworks¶
Combine attack surface and detection impact into a prioritization model:
1. Risk Matrix¶
- Axes: X-axis = Attack Surface (High/Low), Y-axis = Detection Impact (High/Low).
- Example: A gap in a high-attack-surface system with high detection impact (e.g., missing network traffic logs on a DMZ server) is a critical priority.
2. Cost-Benefit Analysis¶
- Technique: Estimate the cost of implementing telemetry (e.g., sensors, log collectors) versus the potential reduction in risk.
- Example: Deploying a lightweight EDR agent on a critical server may cost $500 but prevent a $1M breach.
Case Study: Prioritizing a Telemetry Gap¶
Scenario: A Blue Team identifies a gap in Registry Key Modification telemetry on a domain controller.
- Attack Surface: Domain controllers are high-value targets for lateral movement.
- Detection Impact: Missing registry telemetry could allow adversaries to persist undetected.
- Action: Deploy a registry monitoring tool (e.g., Sysmon with EventID=12 enabled) and update detection rules to flag suspicious modifications.
Key takeaways¶
- Prioritize telemetry gaps in systems with high attack surface (e.g., external-facing servers, privileged hosts).
- Quantify the impact of gaps on detection rules and incident response workflows.
- Use frameworks like risk matrices or cost-benefit analysis to balance resource allocation.
- Validate gaps through adversarial testing and real-world scenario simulation.