AN2038
Analytic 2038
Windows
Detects suspicious interactions with security products followed by service crashes, unexpected restarts, driver unloads, telemetry gaps, or tamper-state changes. Correlates exploit precursor behavior with immediate degradation of defensive services and follow-on process execution.
WinEventLog:System
EventCode=7035
WinEventLog:Sysmon
EventCode=1
WinEventLog:Sysmon
EventCode=6
WinEventLog:Security
EventCode=4688
[CrashCorrelationWindow]
Time between suspicious interaction and security service failure
[ProtectedServiceList]
Security agents/services expected to remain stable
[TelemetryGapThreshold]
Acceptable heartbeat silence duration
AN2039
Analytic 2039
Linux
Detects exploitation attempts against security daemons or kernel security modules followed by daemon termination, disabled logging, module unload, audit stoppage, or reduced endpoint telemetry. Correlates local execution or network input with control degradation.
auditd:EXECVE
execve, kill, ptrace, insmod, rmmod targeting security processes
auditd:DAEMON
auditd stopped, config changed, logging suspended
[ProtectedProcessNames]
Names of EDR, audit, AV, firewall daemons
[ModuleUnloadAllowlist]
Approved maintenance unload operations
[HealthGapThreshold]
Expected telemetry heartbeat tolerance
AN2040
Analytic 2040
macOS
Detects crafted activity resulting in crashes or impairment of endpoint security extensions, network filters, launch daemons, or telemetry agents. Correlates process activity, system extension state changes, and telemetry interruption.
macos:unifiedlog
Crash or abnormal termination of security agent or system extension host
macos:unifiedlog
Extension disabled, unloaded, failed to start
NSM:Flow
Traffic spike preceding control crash
[ExtensionList]
Protected security system extensions
[CrashBurstThreshold]
Multiple failures in short interval
AN2041
Analytic 2041
IaaS
Detects exploitation of cloud-native security boundaries or management components followed by disabled logging, detached agents, changed security groups, policy bypass, or telemetry suppression. Correlates suspicious API activity with reduced control coverage.
AWS:CloudTrail
StopLogging, DeleteTrail, or DisableSecurityService
AWS:CloudTrail
ModifyInstanceAttribute
AWS:CloudTrail
AuthorizeSecurityGroupIngress
[CriticalTrailList]
Audit trails that must remain enabled
[ControlChangeWindow]
Time after suspicious API sequence to inspect coverage loss
AN2042
Analytic 2042
SaaS
Detects exploitation or abuse of SaaS security workflows resulting in disabled alerts, reduced retention, bypassed enforcement, role escalation, or tokenized persistence that weakens monitoring. Correlates unusual admin/API activity with visibility reduction.
saas:okta
policy.rule.update;system.log.disable;admin.role.assign
m365:unified
Set-AdminAuditLogConfig;New-ApplicationAccessPolicy;ConsentToApplication
[PrivilegedActorAllowlist]
Approved admins allowed to change controls
[RetentionChangeThreshold]
Minimum acceptable logging retention