Analyst ·

Use Cases

Current SIEM detection scenarios mapped from logs, alerts, threats, endpoints and network activity.

cloud
in-house
Detection use cases

30 SIEM scenarios continuously evaluated against live logs, alerts and threats.

0 / 30 triggered

#1File Download Monitoring

Endpoint & Server · MITRE T1105

Medium

Tracks files downloaded via browsers, curl, wget, BITS or PowerShell.

no activity

#2Privilege Escalation Attempt

Endpoint & Server · MITRE T1068

Critical

Unexpected sudo, UAC bypass, token theft, or elevated process creation.

Pre-req: Enable Windows Audit Policy

no activity

#3Brute Force Detection

Endpoint & Server · MITRE T1110

High

Repeated failed logons against SSH, RDP, or Windows accounts.

no activity

#4Suspicious Process Execution

Server · MITRE T1059

High

Processes flagged by EDR/Defender or known LOLBin abuse.

Pre-req: EDR/Defender integration required.

no activity

#5Failed Login Threshold

Endpoint & Server · MITRE T1110.001

High

Account exceeded permitted number of failed login attempts.

no activity

#6Malware Detection

Endpoint & Server · MITRE T1204

Critical

Known malware families, ransomware, or trojans detected on host.

Pre-req: EDR/Defender required for additional malware logs

no activity

#7File Integrity Monitoring (FIM)

Server · MITRE T1565.001

Medium

Changes to monitored system or application files.

Pre-req: Client to provide FIM target servers

no activity

#8Suspicious USB Activity

Endpoint & Server · MITRE T1052.001

Medium

Removable media insertion or data copy events.

Pre-req: Enable Windows Audit Policy on endpoints

no activity

#9Suspicious Archive Extraction

Endpoint & Server · MITRE T1140

Medium

Extraction of zip/rar/7z from temp or download folders.

Pre-req: Enable Sysmon

no activity

#10Anomalous File Deletion Patterns

Server · MITRE T1485

High

Large volume or rapid file deletion suggestive of wiper/ransomware.

no activity

#11Security Configuration Assessment (SCA)

Server

Medium

Host fails CIS / vendor hardening checks.

no activity

#12Suspicious Command Execution

Endpoint & Server · MITRE T1059

Medium

Commands typical of attacker tradecraft (whoami, net user, etc).

no activity

#13Excessive Admin Privilege

Server · MITRE T1078.003

High

User added to Administrators / Domain Admins or sudo group.

no activity

#14Suspicious VPN Connection

Endpoint

Medium

VPN client install or connection to non-corporate VPN.

Pre-req: Enable Wazuh agent configuration changes

no activity

#15User Account Create/Delete

Endpoint & Server · MITRE T1136

Medium

Local or domain account created, modified, or removed.

Pre-req: Enable Sysmon

no activity

#16Active Directory Enumeration

Server · MITRE T1087.002

High

BloodHound, SharpHound, LDAP queries enumerating AD objects.

no activity

#17Firewall Policy Change Detection

Endpoint & Server · MITRE T1562.004

High

Local or network firewall rules added, modified, or disabled.

no activity

#18Unusual Binary Execution (Temp)

Endpoint & Server · MITRE T1036

High

Executable launched from %TEMP%, /tmp, or download folders.

Pre-req: Integrate EDR/Defender

no activity

#19Remote Management Tool Usage

Endpoint & Server · MITRE T1219

Medium

AnyDesk, TeamViewer, ScreenConnect, RustDesk or similar installed/used.

no activity

#20Credential Harvesting Attempt

Endpoint & Server · MITRE T1003

Critical

Access to LSASS, browser cred stores, or Mimikatz indicators.

Pre-req: Enable Sysmon and integrate EDR/Defender

no activity

#21Application Installation

Endpoint & Server

Low

Software installed via MSI, EXE, package manager.

no activity

#22New Service Installation

Endpoint & Server · MITRE T1543.003

High

New Windows service or Linux systemd unit created.

no activity

#23Suspicious PowerShell Execution

Endpoint & Server · MITRE T1059.001

High

Encoded, hidden, or download-cradle PowerShell commands.

no activity

#24Port Scanning Activity

Server · MITRE T1046

Medium

Host attempting to scan ports across the network.

Pre-req: Enable Wazuh agent configuration changes

no activity

#25Credential Dumping Detection

Endpoint & Server · MITRE T1003.002

Critical

ntds.dit, SAM, or shadow file access indicative of dumping.

no activity

#26Unauthorized Network Share Access

Endpoint & Server · MITRE T1021.002

High

Access to administrative or unexpected SMB shares.

Pre-req: Enable Sysmon and Audit Policy

no activity

#27System Crash Dump Access

Endpoint & Server

Medium

Read or copy of memory.dmp / crash dump files.

no activity

#28Unusual Process Parent-Child Relationship

Server · MITRE T1055

High

e.g. winword.exe spawning powershell, sqlservr spawning cmd.

Pre-req: Integrate EDR/Defender

no activity

#29Opened Ports Monitoring

Endpoint & Server

Low

New listening port appeared on host.

no activity

#30DNS Timeout Detection

Server

Low

Repeated DNS resolution failures or timeouts.

no activity