Endpoint Telemetry
The activity data collected from endpoints, process creation, file and registry changes, network connections, logons, that feeds detection and investigation. It is one of the richest and most important telemetry sources for defenders.
Concept Neighborhood
Start here
Sysmon
The most substantial related concept here, covered by 8 lessons.
LSASS Memory Dumping Detection
Detecting attempts to dump the memory of the Windows LSASS process, a strong sign of credential theft, by monitoring for suspicious processes accessing LSASS or known dumping techniques.
5
lessons
PowerShell Detection
Detecting malicious PowerShell use through behavioral signals like encoded commands, suspicious script content, unusual parent processes, and known abuse patterns, often mapped to ATT&CK to catch a heavily abused execution technique.
5
lessons
Behavioral Detection
Detecting threats by what an entity does, its behavior and sequences of actions, rather than by matching known-bad signatures. It catches novel and fileless attacks that signature-based detection misses.
1
lesson
SysmonStart here
8
lessons
Application Logs
6
lessons
Detection Coverage
6
lessons
Logs
6
lessons
Network Telemetry
6
lessons
Process ID
6
lessons
Show 4 more connections
Related Lessons
6 lessons cover this conceptDesign Security Telemetry
General Beginner
Build Reliable Source Coverage
General Beginner
Protect the Telemetry Pipeline
General Beginner
Store, Query, and Govern Telemetry
General Beginner
Make Telemetry Detection-Ready
General Beginner
Operate and Improve Telemetry
General Beginner
Sign in to open lesson content directly.
