Warden
Incident → Learning → Better detection → Better response
Data as of 21 Aug 2026 16:40 UTC
Lessons captured
5
SourcesTicketing / SOAR
Coverage gaps
7
SourcesSIEMEDR / XDR
Analyst overrides
2
Agent recommendation modified or denied
SourcesTicketing / SOAR
Benign-closed rate
16%
SourcesTicketing / SOAR

Post-closure lessons learned

Each drills to the incident behind it

Detection latency

Finding: Beaconing ran 31 days before the periodicity analytic reached confidence.

Improvement: Lower the beaconing analytic's minimum observation window for Internet-facing tier-4+ assets.

Coverage gap

Finding: T1572 Protocol Tunneling coverage is 52%.

Improvement: Add byte-ratio and session-duration analytics on egress from DMZ assets.

Control effectiveness

Finding: SMB signing remained disabled on the backup vault (VLN-3004).

Improvement: Enforce SMB signing across tier-5 assets and alert on regression.

Identity hygiene

Finding: The ETL service account held write access far beyond its function.

Improvement: Scope service-account permissions to the ETL landing path only.

False positive

Finding: Delegated-audit forwarding is a recurring benign pattern for Finance.

Improvement: Add a documented-delegation allowlist check before raising T1114.003 alerts for Finance mailboxes.

Proposed detection improvements

Derived from coverage gaps — proposals only, the agent cannot deploy detections

T1583 Acquire Infrastructure · 41%

Add or tune: Correlate newly registered domains resolving near the org's brand terms with outbound DNS.

T1547 Boot or Logon Autostart Execution · 58%

Add or tune: Registry Run-key writes and startup-folder drops from short-lived processes.

T1548 Abuse Elevation Control Mechanism · 49%

Add or tune: UAC bypass patterns and sudo misconfiguration usage in process telemetry.

T1087 Account Discovery · 55%

Add or tune: Directory enumeration volumes per principal above rolling baseline.

T1572 Protocol Tunneling · 52%

Add or tune: Long-lived encrypted sessions with abnormal byte ratios to rare destinations.

T1567 Exfiltration Over Web Service · 57%

Add or tune: Uploads to unsanctioned cloud storage from server-class assets.

T1498 Network Denial of Service · 45%

Add or tune: Edge throughput anomalies and upstream scrubbing-provider signals.

SOC KPI trend

Alert volume and incident count per week