Skip to main content

4. Detection Methods

Detection methods overview

The detection logic below is defender-operable guidance. Where logic is directly supported by a documented case or primary source, it is cited. Where the correlation is an engineering synthesis, it is marked [Inferred].

Environment Validation Required
  • Windows Event IDs listed below are standard audit policy outputs; they require correct audit policy configuration and are not produced by default on all systems.
  • Validate all event IDs and M365 operation names in your environment — audit policy settings, licence tier, and tenant configuration affect what is actually generated.
  • Specific thresholds listed are illustrative starting points; production values must be calibrated to your environment.

Detection Method Index

SectionMethod ClassDeployment Tier
4.1 Deterministic RulesFire on specific artefact patterns with near-zero legitimate prevalenceTier 1 — Deploy first
4.2 Behavioural HeuristicsRequire baseline period; catch "authorised but abnormal" behaviourTier 2–3
4.3 Identity & Privilege AnomaliesPrivileged account creation, access creep, lateral movementTier 1–2
4.4 Exfiltration Path CoverageAll meaningful exfiltration channelsTier 1–3
4.5 Sabotage SignalsControl-plane monitoring for destructive actionsTier 1–2
4.6 UEBA and Anomaly ModelsEntity risk scoring, peer clustering, ML modelsTier 3–4
4.7 Covering-Tracks DetectionPhase 6 second detection opportunityTier 1