16 C
Canberra
Friday, October 24, 2025

The Energy of Endpoint Telemetry in Cybersecurity


A extreme cyberattack leveraging TrickBot malware compromises an organization’s defenses, resulting in important monetary losses. This was not as a consequence of a mere oversight, however reasonably a consequence of insufficient endpoint visibility. With efficient monitoring and real-time insights into endpoint exercise, the risk may have been detected and neutralized earlier than inflicting in depth injury. This underscores the vital significance of complete endpoint telemetry.

What’s endpoint telemetry?

In cybersecurity, endpoint telemetry refers to knowledge collected by monitoring actions on endpoint units, resembling computer systems and servers. This knowledge is essential for risk detection, incident response, and bettering the general cybersecurity posture by providing enhanced visibility.

Essential position of endpoint telemetry

Visibility is essential to stopping advanced cyberattacks early within the kill chain. Should you can’t see it, you may’t cease it. Relating to stopping an assault, it’s at all times higher to take action within the early levels of the assault chain.

In line with the MITRE ATT&CK framework, which is usually utilized by cybersecurity professionals, most enterprise-level assaults — resembling Turla, ToddyCat, and WizardSpider (TrickBot) — contain numerous levels, generally known as ways, which attackers can use in numerous sequences to attain their goals.

Example attack chain for an enterprise-level attack.

The MITRE framework catalogs an inventory of methods and sub-techniques that attackers use to hold out every of those ways on an endpoint. To detect malicious habits early within the assault chain, it’s important to observe the endpoint and file actions that resemble these generally used methods. Capturing telemetry is subsequently very important for figuring out these methods and intercepting assaults at an early stage. Endpoint telemetry additionally serves as a vital knowledge supply for XDR, enhancing its potential to detect, analyze and reply to safety threats throughout a number of environments.

Minimizing false positives

One of many predominant challenges in utilizing telemetry to detect threats is managing false positives. Attackers usually exploit Residing Off-the-Land (LOL) binaries — authentic instruments and utilities that include working techniques — to execute numerous methods or sub-techniques. For instance, the Lazarus Group, a extremely subtle and infamous state-sponsored hacking group, is thought to make use of Scheduled Duties or PowerShell in the course of the Persistence or Execution levels of an assault. Lazarus steadily employs these methods as a part of their broader Residing Off the Land (LOL) technique, which permits them to use authentic system instruments and binaries to mix in with common community exercise and keep away from detection by conventional safety options.

Since these actions mimic benign actions generally carried out in enterprises, detecting them incorrectly can result in a excessive fee of false positives. We may handle this problem is by correlating the occasions and telemetry triggered round that exercise or by utilizing an XDR (Prolonged Detection and Response) instrument, resembling Cisco XDR. Cisco XDR correlates telemetry from numerous detection sources to generate high-fidelity incidents, enhancing the power to establish and cease advanced assaults whereas lowering the chance of false positives.

Capturing telemetry utilizing Cisco Safe Endpoint

Cisco Safe Endpoint is an Endpoint Detection and Response (EDR) instrument that collects and information a variety of endpoint telemetry. It employs numerous detection engines to research this telemetry, establish malicious habits and set off detection occasions. We constantly fine-tune the product to seize extra telemetry and detect occasions of various criticality throughout completely different levels of the MITRE ATT&CK framework. Moreover, occasions from Cisco Safe Endpoint are ingested into the Cisco XDR analytics engine and correlated with different knowledge sources to generate high-fidelity incidents inside Cisco XDR.

Let’s discover the detection occasions captured by Cisco Safe Endpoint within the Occasions view, together with the telemetry recorded within the System Trajectory view. We’ll give attention to how Safe Endpoint gives visibility into the early levels of an assault and its functionality to cease advanced threats earlier than they escalate.

Exploring detection occasions

All of the occasions used on this instance might be considered from Administration->Occasions web page of the Cisco Safe Endpoint console.

Execution Tactic and Detection

Execution ways characterize the methods used to run attacker’s payload on a compromised endpoint to carry out some malicious actions.

Instance methods embody:

  • Encoded PowerShell — Utilizing obfuscated PowerShell instructions to execute code.
  • Home windows Administration Instrumentation (WMI) — Leveraging WMI for executing instructions and scripts.
  • Native APIs — Using built-in system APIs for code execution.

The screenshot under shows an occasion generated by the Behavioral Safety engine of Safe Endpoint, which detected a PowerShell command utilizing “Invoke-Expression” and triggered by “sdiagnhost.exe”.

An event generated by the behavioral protection engine of secure endpoint in response to a malicious PowerShell command.

Persistence Tactic and Detection

Persistence refers to ways that enable malicious payloads to stay on a compromised system and proceed their operations even after reboots or different system modifications. These methods allow the malware to keep up communication with a command-and-control server and obtain additional directions.

Instance methods embody:

  • Create or Modify System Course of — This method entails creating new companies or modifying current companies to execute malicious code at startup or at particular intervals.
  • Registry Modifications — Altering registry entries to make sure malicious packages execute on system startup.
  • Creating Scheduled Duties — Organising duties that run at specified instances or intervals.

The screenshot under illustrates an occasion generated when a brand new service was created to run malware at startup.

Screenshot of an event generated when a new service is created to run malware at startup.

Protection Evasion Tactic and Detection

Protection Evasion entails methods utilized by attackers to cover their malicious payloads and keep away from detection by safety techniques. The aim is to make it tough for safety instruments and analysts to establish and cease the assault.

Instance methods embody:

  • Course of Hollowing — It’s a method the place a suspended course of is created, and a malicious code is injected into the handle area of that suspended course of.
  • Impair Defenses — Modify sufferer’s setting and disable defenses, like turning off anti-virus, firewall or occasion logging mechanisms.
  • Masquerading — Making malicious recordsdata or actions seem authentic to evade detection.

The screenshot under reveals the Course of Hollowing method captured by the Exploit Prevention engine in the course of the Protection Evasion stage of the assault.

Screenshot of an event showing the Process Hollowing technique

Discovery Tactic and Detection

Discovery refers back to the completely different methods adversaries use to collect details about the sufferer’s setting.

Instance methods embody:

  • Course of Discovery — Enumerating operating processes to search out beneficial or susceptible targets.
  • System Info Discovery — Gathering particulars in regards to the working system, {hardware} and put in software program.
  • System Community Configuration Discovery — Figuring out the community settings, interfaces and related units.

The screenshot under depicts the occasion Safe Endpoint generated on observing “tasklist.exe” utilization within the endpoint in a suspicious method, run by “rundll32.exe”, and mapping the habits to Course of Discovery method.

Screenshot of an event showing .exe usage in the endpoint behaving in a suspicious manner

System trajectory telemetry

Cisco Safe Endpoint (CSE) captures two forms of telemetry underneath System Trajectory view: Exercise Telemetry and Behavioral Telemetry.

Exercise Telemetry

By filtering out undesirable knowledge, this telemetry reduces noise and provides clear visibility into endpoint actions, together with processes, parent-child course of relationships, triggered occasions, recordsdata and community exercise, whether or not malicious or benign.

The screenshot under reveals the System Trajectory view within the Safe Endpoint console, with the Exercise Telemetry captured.

Screenshot of the device trajectory view in the secure endpoint console, with the activity telemetry captured

Behavioral Telemetry

This particular sort of telemetry is displayed within the System Trajectory view after evaluation by the detection engine. It’s triggered when a malicious exercise is linked to an in any other case benign exercise, offering further context to assist distinguish between benign and malicious actions.

The screenshot under reveals the System Trajectory view within the Safe Endpoint console, highlighting Behavioral Telemetry recognized by the detection engine. On this instance, the rundll32.exe course of is related to suspicious community exercise.

Screenshot of the Device Trajectory view in the Secure endpoint console.

The telemetry particulars captured by Safe Endpoint on this view present essential context across the noticed exercise, permitting safety groups to rapidly assess the state of affairs. This enriched data not solely aids in figuring out the character and intent of the exercise but in addition empowers groups to conduct extra thorough and efficient investigations. By providing a deeper understanding of potential threats, Safe Endpoint helps to streamline the risk detection course of, lowering response instances and enhancing general safety posture.

Conclusion

The exploration of Cisco Safe Endpoint’s detection occasions and telemetry highlights the facility of visibility in early assault detection. By monitoring and analyzing endpoint habits, organizations acquire beneficial insights into potential threats, permitting them to detect and reply to assaults at their earliest levels. This enhanced visibility is vital to safeguarding vital techniques and fortifying defenses towards evolving cyber threats.

References


We’d love to listen to what you assume. Ask a Query, Remark Beneath, and Keep Linked with Cisco Safety on social!

Cisco Safety Social Channels

Instagram
Fb
Twitter
LinkedIn

Share:



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles