Sample outputs

What the agents hand your team.

This is a product preview: sample outputs in the format the agents produce, not customer data. They follow one public technique, T1543.003 (Create or Modify System Process: Windows Service), and use generic names such as index=wineventlog, hosts WKS-0xx and the domain example.local.

Each panel is an excerpt. Real outputs carry the full query and event links behind every line.

Numbers here are synthetic and chosen to show the format. They are not benchmarks and say nothing about your environment.
threat_brief · T1543.003 · excerptProduct preview · sample output · generic names
S1 Research

Threat brief: Windows Service creation and modification

Adversaries create or change Windows services to run their code at boot or with SYSTEM rights. Six procedures found, every one tied to a public source.

IDProcedureATT&CKSource
P1New service created from the command line with a service control toolT1543.003Atomic Red Team T1543.003-2
P2New service created through PowerShellT1543.003Atomic Red Team T1543.003-3
P3Existing service reconfigured to run a different binaryT1543.003Atomic Red Team T1543.003-1
P4Service configuration written directly to the registryT1543.003, T1112Atomic Red Team T1543.003-4; MITRE ATT&CK
P5Service created on a remote host to run a payloadT1543.003, T1569.002MITRE ATT&CK T1569.002
P6Service binary placed in a user-writable folderT1543.003MITRE ATT&CK T1543.003

Sources cited (excerpt, 4 of 9)

  • MITRE ATT&CK, T1543.003 Create or Modify System Process: Windows Service
  • MITRE ATT&CK, T1569.002 System Services: Service Execution
  • Atomic Red Team, tests T1543.003-1 to T1543.003-4
  • Microsoft documentation for service installation events

Open questions for the engineer

Does the environment log process command lines? P6 depends on it.

coverage_report · T1543.003Product preview · sample output · generic names
S2 Coverage

Coverage report: is the data there for each procedure?

Each source was checked with live searches in the lab. An empty result was re-checked with a smaller window and a known-positive control before it was marked missing.

ProcedureData sourceStatusGate
P1Service install events, Endpoint.Services datamodelavailable normalizedGREEN
P2Service install events, Endpoint.Services datamodelavailable normalizedGREEN
P3Registry events, Endpoint.Registry datamodelavailable normalizedGREEN
P4Registry events, Endpoint.Registry datamodelavailable normalizedGREEN
P5Remote logon and service events in index=wineventlog, not mapped to a datamodelavailable rawYELLOW
P6Process creation with command linemissingRED
Summary
4 detectable, 1 raw only, 1 missing log
Remediation
P5: map remote logon fields to the Authentication datamodel. P6: enable command-line process auditing on WKS-0xx hosts.
Effect
P6 variants are skipped in simulation and reported as a telemetry gap, not as a detection failure.
validation_report · 2 detectionsProduct preview · sample output · generic names
S4 Validate

Validation report: does it fire, and how noisy is it?

Six Atomic Red Team variants ran in the synthetic lab, each with a signed marker so only genuine test events count. The false-positive baseline covered 14 days of lab background activity.

VariantProcedureResult
T1543.003-1P3fired
T1543.003-2P1fired
T1543.003-3P2fired
T1543.003-4P4fired
remote variantP5fired
user-path variantP6telemetry gap
True positives
5 of 6 variants fired, 0 missed, 1 telemetry gap
False positives
0.4 per day over 14 days, against a team target of 1.0 per day
FP source
Service reinstalls by svc_backup on WKS-014 and WKS-027
PASS WITH TUNINGVerdict

Routing

  • Telemetry gap on P6 goes back to Coverage as an onboarding request, not to Build.
  • The svc_backup exception is proposed in the filter macro, with a justification, for the engineer at the approval gate.
tuning_diff · noisy_service_ruleProduct preview · sample output · generic names
S5 Tune

Tuning diff: which alerts would disappear, and why

A generic live rule produced 477 alerts in 30 days of synthetic lab history. The agent grouped them into clusters, labelled each one, and proposed the smallest change that removes only the benign clusters.

ClusterLabelAlertsProposal
C1Backup agent reinstalls its service (svc_backup, WKS-0xx)312drop
C2Software deployment tool updates its agent service140drop
C3Manual service installs by IT admins on servers22keep
C4Service binary in a user temp folder, unknown signer3keep
Tier chosen
FILTER: two scoped exceptions in the filter macro. No threshold change, no rewrite of the search.
Would disappear
452 alerts, all from C1 and C2. 0 from C3 or C4.
Projected reduction
94.8% (477 to 25 alerts in the same 30 days)

Must-keep checks

  • All 5 previously firing Atomic Red Team variants still fire after the change.
  • Every C4 alert is still raised.
  • Remaining volume is above zero, so the rule has not been silenced.
must-keep checks passedReady for engineer approval

Rollback plan

Revert the merge request to restore the previous filter macro. A post-check after 7 days live compares alert volume and confirms C3 and C4 alerts still arrive; any drop there reopens the proposal.

See these outputs produced live, on a technique you choose.

Book a 30-minute walkthrough