← CYBERNETICSINTERN.COMCYBERNETIC INTERN
Detection EngineeringFOUNDATION

You cannot detect what you never collected

Detection logic is downstream of telemetry. A rule that reads a field nobody collects is valid, ships cleanly, and matches nothing forever.

Detection work usually starts in the wrong place. Someone reads a threat report, opens the rule editor and writes logic. The logic is correct. The rule ships. It never fires.

It was downstream of a question nobody asked: does this environment actually produce the events the rule reads?

Three things have to be true before logic matters. The event has to be generated at the source, which is frequently a setting rather than a default. It has to reach your platform, through an agent or forwarder or API that can quietly stop. And it has to be retained long enough to be worth querying, because a thirty day window does not answer a question about last quarter.

Command-line arguments are the classic case. A great deal of detection content depends on them, and on Windows they are not recorded until process command-line auditing is switched on. Write the rule without it and the field is simply empty. The rule is valid. It matches nothing. Forever.

The failure is quiet, which is what makes it expensive. A rule that never fires looks identical to a rule watching a technique nobody is using, and the second reading is more comfortable, so it tends to be the one that sticks.

Before you write the next detection, query the data for the field it depends on. If nothing comes back, what you have is a collection ticket, not a detection.

CHECK YOURSELF

You write a rule that keys on process command-line arguments. It passes review and goes live. Six months later it has never fired once. What is the most likely explanation?

SHOW THE ANSWER

Command-line logging was never enabled, so the field is empty

Why. A rule reading a field that is never populated cannot match, and nothing errors to tell you so. Zero alerts and zero attacks look identical from the console, which is why the comfortable reading usually wins. Tuning and auto-close both assume the rule matched something in the first place, so neither explains a rule that has produced nothing at all. Query the field before you trust the silence.

REFERENCE

← ALL DETECTION ENGINEERING