Utilizing behavioral TTP’s in SIEM technologies to augment IoC based detection
Download resourcesAbout this session
Ben Cook, a global security architect at Google who joined via the Mandiant acquisition, argues that indicator-of-compromise detection alone is not enough: IOCs publish late, have short shelf lives, rarely get reused by threat actors, and lack context for an alert. His fix is behavioral, TTP-based detection layered into the SIEM, since it can correlate identity, network and endpoint data with one rule language and stays passive rather than blocking. He walks through building a threat profile from an organization's business, footprint and threat landscape, then demonstrates extracting a real technique, a PowerShell-driven credential dump on Exchange, from a threat intelligence campaign report and turning it into a reusable Google SecOps detection template, generalized beyond the original file path and process ID so it keeps matching variants. A second, anomaly-based method flags legitimate remote-access tools like AnyDesk running from unexpected folders or with mismatched hashes, rather than banning the tools outright. He closes with options for teams without in-house intelligence capacity: consultants, intel-focused MDR services, or a security-capable MSSP, and takes questions on automatic EDR updates and sourcing Sigma rules.
In this presentation we will discuss the challenges of IoC based detection, both past and emerging, and how we can augment our detection capabilities utilizing behavioral based techniques derived from Threat Intelligence providers.
Key takeaways
- Treat IOCs as low-hanging fruit, not a complete detection strategy; they publish late, decay fast, and are rarely reused (measured hash reuse of about 3.6% in one year of VirusTotal submissions).
- Build a threat profile first (business model, footprint, region, relevant threat actors and campaigns) before deciding which TTPs are worth hunting for in your environment.
- Extract behavioral detail (commands, file paths, certificates) from full campaign reports, not just the IOC list, then generalize it (broader paths, wildcards) into a reusable SIEM rule template.
- For anomaly-based hunting on allowed tools like remote-access software, flag executions from unexpected folders or with mismatched hashes instead of banning the tool outright.
- If you lack an in-house intel team, use outside consultants, an intel-focused MDR service, or a security-capable MSSP rather than skipping TTP-based detection altogether.
Speakers

Ben Cook is a Global Security Architect working in threat intelligence and risk. Ben specializes in Cyber Threat Profile development, threat intelligence operationalization & optimization, and risk based approach to security control gap analysis… Read moreRead less
Ben Cook is a Global Security Architect working in threat intelligence and risk. Ben specializes in Cyber Threat Profile development, threat intelligence operationalization & optimization, and risk based approach to security control gap analysis. Ben has spent the last ten years working for Google, Mandiant, and FireEye in multiple client-facing roles. Previous to this Ben spent time as an analyst for Canadian financial institutions working in security operations specializing in SIEM implementation and security control assessments. Today Ben works with our client teams as an advisor to deliver security platforms and process transformation for organizations with a specialization in intelligence integration.
