The Problem
Detection rules are easy to write against clean, pre-packaged sample data. Proving a detection actually works means generating the attack yourself, capturing what it really looks like in the logs, and confirming the alert fires correctly — with no shortcuts.
Objective
To design, implement, and validate a set of custom detection alerts covering attacker behavior across the Authentication, Privilege Escalation, Execution, and Persistence MITRE ATT&CK tactics.
Approach
- Built a lab environment with Linux and Windows endpoints, forwarding authentication, process execution, PowerShell, and service-creation activity into Splunk.
- For each of the 9 alert scenarios, personally executed the corresponding attacker behavior on the endpoint — for example, running `sudo adduser test4` to simulate unauthorized local user creation — generating first-party telemetry rather than relying on a pre-built dataset.
- Wrote SPL detection logic per alert, including field extraction and scheduled trigger conditions with throttling tuned to reduce noise.
- Validated every alert against the logs generated from these live simulations, capturing evidence of the attack, the triggered alert, and the detection result for each.
Tools & Technologies
- Splunk
- SPL
Outcome
9 validated, MITRE ATT&CK-mapped detection alerts, each fully documented with its detection objective, log sources, SPL query, trigger condition, attack simulation steps, validation evidence, false-positive considerations, and SOC-style response guidance. Categories span SSH brute-force and successful-login-after-failure (Authentication), local user creation and privileged group additions on both Linux and Windows (Privilege Escalation), suspicious PowerShell and parent-child process execution (Execution), and suspicious service creation (Persistence).
Lessons Learned
- Good detections are tuned to reduce noise — throttling and trigger conditions matter as much as the underlying detection logic.
- Detections built around behavior patterns, rather than single events, hold up better against false positives.
- Documenting false-positive scenarios up front — like legitimate admin account provisioning — is what turns a detection from a proof-of-concept into something a real SOC team could actually run.