Critical Information Missing from Timelines and SOC Visibility
R
Ryan Sipes
After having an incident where a device was registered by a threat actor, I noticed that this was not reflected in the timeline. A timeline missing events easily surfaced in the user's audit log isn't the most valuable. The timeline needs to reflect all surfaced threat actor activity - not omit events that thereby make the timeline inaccurate.
The reason this was omitted is even more concerning: rogue device registrations aren't monitored by ITDR. Not sure why this info isn't monitored by the SOC, but this is a major visibility gap.
The timeline should reflect all events from the IP associated with the threat actor's session, and the SOC should have visibility and utilize info present from user audit log events to surface info like rogue device registrations which apparently aren't monitored
R
Roy Denman
I’ve observed the same behavior with Graph-Spy device registrations found not noted in incidents. My understanding is that the initial activity triggered the critical signals, and because there was no manual SOC validation or review of the subsequent activity, follow-on events were not analyzed after data collection stopped when the critical signals were tripped.