Post-closure lessons learned
Each drills to the incident behind it
Finding: Beaconing ran 31 days before the periodicity analytic reached confidence.
Improvement: Lower the beaconing analytic's minimum observation window for Internet-facing tier-4+ assets.
Finding: T1572 Protocol Tunneling coverage is 52%.
Improvement: Add byte-ratio and session-duration analytics on egress from DMZ assets.
Finding: SMB signing remained disabled on the backup vault (VLN-3004).
Improvement: Enforce SMB signing across tier-5 assets and alert on regression.
Finding: The ETL service account held write access far beyond its function.
Improvement: Scope service-account permissions to the ETL landing path only.
Finding: Delegated-audit forwarding is a recurring benign pattern for Finance.
Improvement: Add a documented-delegation allowlist check before raising T1114.003 alerts for Finance mailboxes.
Proposed detection improvements
Derived from coverage gaps — proposals only, the agent cannot deploy detections
T1583 Acquire Infrastructure · 41%
Add or tune: Correlate newly registered domains resolving near the org's brand terms with outbound DNS.
T1547 Boot or Logon Autostart Execution · 58%
Add or tune: Registry Run-key writes and startup-folder drops from short-lived processes.
T1548 Abuse Elevation Control Mechanism · 49%
Add or tune: UAC bypass patterns and sudo misconfiguration usage in process telemetry.
T1087 Account Discovery · 55%
Add or tune: Directory enumeration volumes per principal above rolling baseline.
T1572 Protocol Tunneling · 52%
Add or tune: Long-lived encrypted sessions with abnormal byte ratios to rare destinations.
T1567 Exfiltration Over Web Service · 57%
Add or tune: Uploads to unsanctioned cloud storage from server-class assets.
T1498 Network Denial of Service · 45%
Add or tune: Edge throughput anomalies and upstream scrubbing-provider signals.
SOC KPI trend
Alert volume and incident count per week