SIEM

Service Creation Use Cases

Grouped by Detection Method

MITRE ATT&CK Framework: New Service (T1050), Service Execution (T1035)

Aggregate Count

Blacklist Alert

Whitelist Alert

Levenshtein Score Alert

Rolling Whitelist Alert

Shannon Entropy Score Alert

Threshold Alert

Log Source Examples

Possible False Positives