Skip to content
English
  • There are no suggestions because the search field is empty.

Cross-Service Correlation Analysis [CHK-3021]

This ticket covers a Microsoft Defender incident that correlates related activity across more than one service, for example an endpoint detection alongside identity or email activity involving the same user, which Attic MDR routed for analysis.

Attic MDR handles incoming Defender incidents in two stages. L1 ingests and filters, concluding for each incident that it should be ticketed directly, dropped, sent for analysis, or ticketed directly and sent for analysis. L2 is where the analysis happens, and where IVON, the Attic analyst behind our MDR service, works. This ticket means the correlation reached L2 and IVON analysed it.

The ticket may look almost empty when it first appears. Incidents sent for analysis have their ticket registered up front, and the content arrives once IVON has finished.

Rationale

Attacks rarely stay in one place. A phishing email leads to a credential being used, which leads to a mailbox rule and a download from SharePoint, which leads to something running on an endpoint. Each service detects its own part, and each part alone can look minor.

The correlation is the signal. Activity spanning email, identity and endpoint around the same user in a short window is a far stronger indication of a real intrusion than any of the individual events, because it matches the shape of an actual attack chain rather than a single anomaly.

That is also why the analysis has to take the chain as a whole. Judging a correlation means working out what the sequence would mean in your environment: whether a user legitimately does all of these things, or whether the pattern only makes sense as an intrusion. It is exactly the kind of judgement where confidence matters, and where IVON will raise the incident to a human analyst at Attic if her own analysis or the quality checks against it leave room for doubt.

Follow-up

Follow these steps to adequately handle this ticket:

  1. If the ticket is empty, wait. The analysis is still running and the ticket will be filled in when it completes.
  2. Read the analysis. The findings and any recommended action are specific to this correlation.
  3. Be ready to answer questions about the user involved. Cross-service correlations very often hinge on whether one person's activity was legitimate: whether they were travelling, whether they set up a mail rule deliberately, whether they installed something. This is usually the fastest route to a conclusion.
  4. Do not dismiss the individual alerts separately. The value here is in the combination. Closing each contributing alert on its own merits is exactly how a real chain gets missed.
  5. Act quickly if the incident has been escalated. Where the analysis confirms the correlation represents genuine activity, a human analyst at Attic picks it up and the ticket is updated with containment steps. Cross-service chains involving identity usually call for revoking sessions rather than only resetting a password, because the attacker holds tokens rather than credentials.

More information