Skip to content

Time-Series Analysis

Analyzing temporal relationships between security events is critical for identifying stealthy attack behaviors that evade traditional detection methods. Attackers often employ time-based tactics, such as delayed exfiltration, multi-stage compromises, or periodic reconnaissance, which require defenders to examine event sequences across extended timeframes. Time-series analysis in Microsoft Sentinel leverages KQL (Kusto Query Language) to uncover these patterns by correlating events based on their timing, frequency, and sequence.


Key Concepts in Time-Series Analysis

  1. Temporal Context: Events that occur within specific time windows (e.g., hours, days, or weeks) may indicate coordinated attacks. For example, a phishing click followed by lateral movement after several days could signal a multi-stage breach.
  2. Anomaly Detection: Unusual gaps or bursts in event timing (e.g., sudden spikes in failed logins or irregular process creation) may reveal reconnaissance or exfiltration activities.
  3. Sequence Correlation: Attackers often follow predictable but subtle patterns (e.g., credential theft followed by privilege escalation). Time-series analysis helps identify these sequences by aligning events across systems.

Common Attack Patterns to Detect

  • Delayed Exfiltration: Data is transferred over extended periods to avoid detection (e.g., small, frequent data transfers).
  • Lateral Movement: Attackers move between systems with irregular intervals, mimicking legitimate traffic.
  • Reconnaissance: Passive scanning or enumeration activities spaced over hours or days.
  • Scheduled Tasks: Malicious scripts or processes executed at specific times (e.g., during off-peak hours).

KQL Techniques for Time-Series Analysis

Use KQL functions to analyze temporal relationships:
- datetime: Convert string timestamps to datetime objects.
- ago: Filter events within a relative time window (e.g., datetime() - 7d).
- between: Define a time range for event correlation.
- bin: Aggregate events into time intervals (e.g., bin(TimeGenerated, 1h)).
- summarize: Calculate metrics like count, average interval, or duration between events.

Example 1: Detecting Delayed Exfiltration

SecurityEvent
| where EventID == 4663 // Logon attempt
| where Account == "domain\\compromised_user"
| where TimeGenerated between (datetime() - 7d .. datetime())
| summarize count() by bin(TimeGenerated, 1h)
| where count_ > 5 // Filter for unusual activity

Example 2: Identifying Irregular Process Creation

Process
| where ProcessName == "cmd.exe" and InitiatingProcess != "explorer.exe"
| where TimeGenerated between (datetime() - 30d .. datetime())
| summarize avg(DurationInSeconds) by bin(TimeGenerated, 1h)
| where avg_DurationInSeconds < 10 // Flag short, frequent executions


Challenges and Mitigations

  • Noise in Data: Legitimate activities (e.g., scheduled jobs) may mimic attack patterns. Use contextual filters (e.g., IP ranges, user roles) to reduce false positives.
  • Time Zone Variability: Ensure timestamps are normalized to a consistent time zone.
  • Event Granularity: High-frequency events (e.g., registry changes) may require aggregation to avoid overwhelming results.

Key takeaways

  • Time-series analysis reveals attack patterns that evade signature-based detection.
  • Use KQL to correlate events across time windows and identify anomalies.
  • Focus on irregular intervals, sequence timing, and contextual filters to reduce noise.
  • Combine temporal analysis with other correlation techniques (e.g., user behavior analytics) for comprehensive threat detection.