Mission and audience
Create reliable, timely, explainable detection from the data that matters most.
Collecting logs is not the same as detecting threats. This playbook connects telemetry design, monitoring coverage, analytic logic, triage, and continuous improvement.
Guided phase
Define the telemetry foundation
Know what must be observed, why it matters, and how data should move from source to analyst.
Actions to take
- Map critical assets, trust boundaries, and data flows.
- Define required events, fields, timestamps, retention, and owners.
- Document gaps, transformations, and failure handling.
Generate and Provide Log Records
Log records are generated and made available for continuous monitoring
Network Communication and Data Flow Representations
Representations of the organization’s authorized network communication and internal and external network data flows are maintained
Guided phase
Monitor the operating environment
Cover networks, people, providers, workloads, and runtime behavior.
Actions to take
- Prioritize monitoring by mission and threat exposure.
- Validate provider and cloud telemetry contracts.
- Test sensor health, data freshness, and blind-spot detection.
Monitor Networks and Network Services
Networks and network services are monitored to find potentially adverse events
Monitor Personnel Activity and Technology Use
Personnel activity and technology usage are monitored to find potentially adverse events
Monitor External Service Providers
External service provider activities and services are monitored to find potentially adverse events
Monitor Computing and Runtime Environments
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Guided phase
Analyze and correlate events
Convert raw events into evidence-backed hypotheses and scoped adverse activity.
Actions to take
- Document analytic logic, thresholds, assumptions, and expected false positives.
- Correlate identity, endpoint, network, cloud, and threat-intelligence context.
- Define impact and scope estimation methods.
Analyze Potentially Adverse Events
Potentially adverse events are analyzed to better understand associated activities
Correlate Information from Multiple Sources
Information is correlated from multiple sources
Understand Event Impact and Scope
The estimated impact and scope of adverse events are understood
Integrate Threat Intelligence and Context
Cyber threat intelligence and other contextual information are integrated into the analysis
Guided phase
Operationalize detection decisions
Deliver usable event information and declare incidents with consistent criteria.
Actions to take
- Route events to accountable people and systems.
- Define severity, declaration, escalation, and handoff criteria.
- Exercise detections against realistic scenarios.
Provide Event Information to Authorized Staff and Tools
Information on adverse events is provided to authorized staff and tools
Declare Incidents Using Defined Criteria
Incidents are declared when adverse events meet the defined incident criteria
Guided phase
Improve from operations
Treat detections as maintained engineering products rather than one-time rules.
Actions to take
- Measure coverage, precision, latency, and investigation value.
- Tune or retire detections using incident and analyst feedback.
- Track detection debt and unresolved telemetry gaps.
Improvements from Evaluations
Improvements are identified from evaluations
Improvements from Operations
Improvements are identified from execution of operational processes, procedures, and activities
Completion evidence
What should exist when this playbook is working?
- Telemetry requirements mapped to critical assets and threats.
- Documented event schemas, retention, time synchronization, and data owners.
- Monitored-source coverage and health dashboards.
- Versioned analytic logic with test cases and expected outcomes.
- Incident declaration and escalation criteria.
- Metrics for data latency, false positives, coverage, and detection-to-response time.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.