SIEM

Service Modification Use Cases

Grouped by Detection Method

MITRE ATT&CK Framework: Modify Existing Service (T1031)

Aggregate Count

Blacklist Alert

Whitelist Alert

Levenshtein Score Alert

Rolling Whitelist Alert

Shannon Entropy Score Alert

Threshold Alert

Log Source Examples

Possible False Positives