Practical security engineering: Stateful detection
ID: a43de5a9-1705-5acb-aac9-e1917c2db5a4
STIX ID: report--a43de5a9-1705-5acb-aac9-e1917c2db5a4
Feed Name: Elastic Security Labs
This blog introduces Elastic’s stateful detection approach for building resilient detections across the creation, runtime, and cleanup states. Using MITRE ATT&CK T1015 (Accessibility Features) and IFEO Debugger abuse (e.g., osk.exe, utilman.exe, winlogon.exe) as a case study, it shows how to baseline normal behavior, identify hijack opportunities, hunt runtime anomalies, and translate findings into EQL rules with supporting Sysmon telemetry. It concludes with guidance on refining rules and proactively monitoring unusual child processes to expand coverage for persistence, defense evasion, and command-and-control techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
