Operational Security Trumps Policy

▶ Watch (2:15)

Ukraine’s Department of Defense lost on-premises data centers in the first hours of the invasion. Their only option: migrate classified workloads to the cloud, despite a constitutional ban. A Norwegian researcher later found a 10–20% gap between reported security and actual operational security across countries. Ukraine’s organizations that survived bypassed policy-first approaches. They made systems where you were unable to do what you were not supposed to do. ISO certifications came after the operational defense worked.

Security Monitoring Fundamentals: Sources, Sinks, and Log Retention

▶ Watch (13:32)

Every endpoint generates logs. Central shipping prevents attackers from wiping evidence and protects against hardware failure or firewall log rotation. The source is any device; the sink is a SIEM, data lake, or platform like Sentinel One. Microsoft 365 includes only 30 days of logs. On day 31 after an incident, only SharePoint upload records remain. The analyst knows who got the file but not what the malware did. Cold storage for key logs fills that gap.

The Cost of Logging Everything

▶ Watch (19:42)

An international service provider shipped all logs into the most expensive tier. Only 10% of the data was used for detection. 30–40% were duplicates from different ingestion methods. They had deployed every built-in analytic rule and generated over a thousand medium and high incidents daily. The fix: reverse-engineer logs from detection needs. Start with what you are afraid of, write the query, then identify the tables and logs required. This saved the company about $100,000 monthly.

Over-Reliance on Tools and Template Pitfalls

▶ Watch (34:25)

EDR tools ship with lax defaults. The August 2024 malvertising campaign in the Nordics used a signed PDF editor that bypassed Sentinel One, Palo Alto Cortex, and Microsoft Defender. VirusTotal detection was zero for ten days. Deploying 200 built-in templates creates alert fatigue. One template compared unique requests to total requests to detect storage scanning. It failed because the vulnerable storage account was also being used for normal operations. Custom, tuned detections beat stock templates.

Improving Process Through Feedback and Questioning

▶ Watch (40:40)

Dahlsveen’s SOC team drew diagrams of the full monitoring pipeline from systems to ticketing. They pinpointed missing context and lack of control. The SIEM was the bottleneck; the ITSM was company-mandated and unchangeable. They replaced the SIEM and saw drastic improvement. They then hired a senior analyst and “gaslighted him into believing everything can change.” In three weeks he contributed more improvements than the team had made in the previous year.

Notable Quotes

I have [ __ ] up more than I made correct decisions Truls Dahlsveen · ▶ Watch (0:46)

humility is gone. everyone on on LinkedIn, on Twitter, every presenter is so sure these days. Truls Dahlsveen · ▶ Watch (4:57)

the first hit is always free Truls Dahlsveen · ▶ Watch (22:15)

10 specialized rules for your company that you have taken great care in crafting I think will be way more valuable than 200 [ __ ] rules Truls Dahlsveen · ▶ Watch (25:55)

we gaslighted him into believing everything can change Truls Dahlsveen · ▶ Watch (43:30)

Key Takeaways

  • Start security monitoring by identifying what you are afraid of, not by enabling all logs.
  • 10 tailored detection rules outperform 200 generic templates in real environments.
  • EDR tools can be bypassed; supplement with custom queries and threat modeling.

About the Speaker(s)

Truls Dahlsveen is a security engineer with a passion for automation and security. He is a Microsoft MVP in Security for the “SIEM & XDR” category. His experience spans system administration, development/automation engineering, and penetration testing. He speaks and writes on cloud security strategies, log ingestion, SIEM best practice, SOAR, and detection engineering.