Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Guided Defense Playbooks

Logging and Detection

Turn asset context and log generation into monitored telemetry, correlated analysis, declared incidents, and repeatable detection improvement.

5Guided phases
14CSF outcomes
76Mapped controls
30D3FEND techniques

Detection engineering playbook · Editorial sequence over source-controlled framework relationships

Open the complete Defense Map →

Mission and audience

Create reliable, timely, explainable detection from the data that matters most.

Collecting logs is not the same as detecting threats. This playbook connects telemetry design, monitoring coverage, analytic logic, triage, and continuous improvement.

Built forSOC teams · Detection engineers · Platform teams · Cloud teams · Incident responders
01

Guided phase

Define the telemetry foundation

Know what must be observed, why it matters, and how data should move from source to analyst.

Actions to take

  • Map critical assets, trust boundaries, and data flows.
  • Define required events, fields, timestamps, retention, and owners.
  • Document gaps, transformations, and failure handling.
ID.AM-03Identify · Asset Management

Network Communication and Data Flow Representations

Representations of the organization’s authorized network communication and internal and external network data flows are maintained

6 controls3 800-17111 800-1724 D3FEND6 mitigations
02

Guided phase

Monitor the operating environment

Cover networks, people, providers, workloads, and runtime behavior.

Actions to take

  • Prioritize monitoring by mission and threat exposure.
  • Validate provider and cloud telemetry contracts.
  • Test sensor health, data freshness, and blind-spot detection.
DE.CM-01Detect · Continuous Monitoring

Monitor Networks and Network Services

Networks and network services are monitored to find potentially adverse events

7 controls7 800-17113 800-1726 D3FEND8 mitigations
DE.CM-03Detect · Continuous Monitoring

Monitor Personnel Activity and Technology Use

Personnel activity and technology usage are monitored to find potentially adverse events

6 controls3 800-1713 800-1724 D3FEND5 mitigations
DE.CM-06Detect · Continuous Monitoring

Monitor External Service Providers

External service provider activities and services are monitored to find potentially adverse events

5 controls3 800-1715 800-1722 D3FEND3 mitigations
DE.CM-09Detect · Continuous Monitoring

Monitor Computing and Runtime Environments

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

12 controls6 800-17119 800-1727 D3FEND10 mitigations
03

Guided phase

Analyze and correlate events

Convert raw events into evidence-backed hypotheses and scoped adverse activity.

Actions to take

  • Document analytic logic, thresholds, assumptions, and expected false positives.
  • Correlate identity, endpoint, network, cloud, and threat-intelligence context.
  • Define impact and scope estimation methods.
DE.AE-02Detect · Adverse Event Analysis

Analyze Potentially Adverse Events

Potentially adverse events are analyzed to better understand associated activities

4 controls4 800-1719 800-1725 D3FEND5 mitigations
DE.AE-07Detect · Adverse Event Analysis

Integrate Threat Intelligence and Context

Cyber threat intelligence and other contextual information are integrated into the analysis

3 controls1 800-1715 800-1727 D3FEND4 mitigations
04

Guided phase

Operationalize detection decisions

Deliver usable event information and declare incidents with consistent criteria.

Actions to take

  • Route events to accountable people and systems.
  • Define severity, declaration, escalation, and handoff criteria.
  • Exercise detections against realistic scenarios.
DE.AE-06Detect · Adverse Event Analysis

Provide Event Information to Authorized Staff and Tools

Information on adverse events is provided to authorized staff and tools

5 controls1 800-1716 800-1723 D3FEND2 mitigations
DE.AE-08Detect · Adverse Event Analysis

Declare Incidents Using Defined Criteria

Incidents are declared when adverse events meet the defined incident criteria

2 controls2 800-1713 800-1723 D3FEND2 mitigations
05

Guided phase

Improve from operations

Treat detections as maintained engineering products rather than one-time rules.

Actions to take

  • Measure coverage, precision, latency, and investigation value.
  • Tune or retire detections using incident and analyst feedback.
  • Track detection debt and unresolved telemetry gaps.
ID.IM-03Identify · Improvement

Improvements from Operations

Improvements are identified from execution of operational processes, procedures, and activities

39 controls14 800-17113 800-17221 D3FEND17 mitigations

Completion evidence

What should exist when this playbook is working?

  • Telemetry requirements mapped to critical assets and threats.
  • Documented event schemas, retention, time synchronization, and data owners.
  • Monitored-source coverage and health dashboards.
  • Versioned analytic logic with test cases and expected outcomes.
  • Incident declaration and escalation criteria.
  • Metrics for data latency, false positives, coverage, and detection-to-response time.

Relationship boundaries

Use the playbook as a decision aid.

Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.