Lateral Movement
T1021.002
SMB / PsExec-style movement correlated across host and network telemetry
Credential Access
T1003.001
LSASS memory access flagged via EDR sensor, tuned against legitimate backup tooling
Identity Anomaly
T1078.004
Impossible-travel sign-ins enriched with GeoIP and user baselines
Persistence / Priv Esc
T1547 / T1068
New service binaries and privilege-escalation attempts in non-standard paths
Illustrative high-fidelity events
14:32:08HIGH
Anomalous PowerShell encoded payload — host: WIN-EXAMPLE-01SPLUNK
14:18:52MED
Impossible travel: sample account — two regions, <25min apartSENTINEL
13:54:31HIGH
Credential dumping via LSASS handle, flagged by EDR sensorCROWDSTRIKE
13:22:09LOW
Bulk file permission change on a monitored file shareQRADAR