← CYBERNETICSINTERN.COMCYBERNETIC INTERN
Detection EngineeringFOUNDATION

Your rule matches strings, not intent

Case, encoding and path variation break literal matches without any help from an attacker. The rule did what you asked, not what you meant.

You write a rule for powershell.exe. It matches powershell.exe. It does not match PowerShell.EXE, or the same command arriving base64 encoded, or a copy of the binary renamed to p.exe.

The rule did exactly what you asked. You asked for the wrong thing.

Three mismatches cause most of it. Case, because some backends fold case and some do not, and the same query behaves differently after a platform migration. Encoding, because a command line can be percent encoded, base64 wrapped, or split with quoting that means nothing to the shell and everything to your contains test. Path, because matching a full path misses the same binary launched from somewhere else, while matching a bare filename catches an unrelated file that happens to share it.

None of this requires clever evasion. Most of it is ordinary variation produced by installers, scripts, and people typing.

Match against the field that is hardest to vary. A hash beats a filename. A process name beats a command-line substring. Where you have to match text, normalise before you compare: fold case in the pipeline, decode what can be decoded, then test.

Take one string-matching rule and run its pattern against the same event with the case changed. If the result differs, you just found a gap that has nothing to do with attackers.

CHECK YOURSELF

You inherit a rule matching the command-line substring Invoke-WebRequest. Which single change most reduces the chance it misses real activity?

SHOW THE ANSWER

Normalise the field to lowercase in the pipeline, then match against it

Why. Adding one more capitalisation fixes one variant and leaves every other one open, and you will be adding conditions forever. Normalising the field before comparison handles all capitalisation at once, and because it is a pipeline change rather than a rule change, every detection reading that field benefits. Matching the parent process answers a different question, and severity has no effect on whether the rule matches at all.

REFERENCE

← ALL DETECTION ENGINEERING