SIEM

Commandline Activity Use Cases

Grouped by Detection Method

MITRE ATT&CK Framework: Command-Line Interface (T1059), PowerShell (T1086), Inhibit System Recovery

Aggregate Count

Match Alert

Question the use of these, as they are infrequently used legitimately

!!!! IMPORTANT NOTES !!!!


Blacklist Alert

Whitelist Alert

Levenshtein Score Alert

Rolling Whitelist Alert

Shannon Entropy Score Alert

Threshold Alert

Log Source Examples

Possible False Positives

References