← CYBERNETICSINTERN.COMCYBERNETIC INTERN
Detection EngineeringFOUNDATION

The same command is not always malicious

Administrators and intruders run identical commands. Content alone cannot separate them, so a rule reading only content will alert on both.

An administrator enumerates domain accounts on a Tuesday afternoon. An intruder enumerates domain accounts at three on a Sunday morning. The command is byte for byte identical.

No amount of care with the command line separates those two, because the difference is not in the text. It is in everything around the text: who ran it, on what, from where, at what hour, and what happened in the minutes before.

This is why so many good detections produce so many bad alerts. The logic is right. The content genuinely is suspicious. It is also genuinely what the platform team does every week.

The way out is context, and context is a collection problem before it is a logic problem. Saying “this account has never done this before” needs history. Saying “this came from a jump host” needs the source. Saying “nobody raised a change for this” needs the change record reachable from the alert.

Most teams find out which of those they are missing in the middle of a triage, at the point where the answer would have been worth something.

Take the noisiest rule you own. Write down the three pieces of context that would let you decide it inside a minute. Then go and check whether you actually collect all three.

CHECK YOURSELF

A detection for a legitimate administrative tool fires forty times a week and is correct every time. Thirty nine of those are the platform team doing their job. What is the most useful change?

SHOW THE ANSWER

Add context so routine use is separated from unusual use rather than hidden

Why. The rule is already accurate, so the problem is that it cannot tell two true things apart, and the fix is to give it the information that distinguishes them: source host, account history, a change reference, time of day. Both exclusion answers work by making the rule blind, and an adversary using a platform account, or simply working during office hours, then walks through the gap that was built deliberately. Lowering severity keeps every alert and moves them somewhere they will be read less carefully, which is not a decision anyone would choose to write down.

← ALL DETECTION ENGINEERING