Detection Surface & the role of Endpoint Telemetry

Alex Teixeira
4 min readMar 19

Anyone working in log-based Threat Detection knows this. Command-line telemetry is the Crème de la Crème of data sources.

And we don't need much effort to verify such statement. Simply check how many TTPs one is able to monitor from such rich telemetry:

Credit: Jose Luis Rodriguez & Roberto Rodriguez

In short, detection-wise, those logs do provide high benefit/cost ratio, especially in Windows…

Alex Teixeira

I design and build threat detection models and triage/hunting interfaces for Enterprise #SecOps teams #DetectionEngineering http://opstune.com