{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/telemetry-suppression/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Elastic Defend"],"_cs_severities":["high"],"_cs_tags":["defense-evasion","telemetry-suppression","endpoint-security"],"_cs_type":"advisory","_cs_vendors":["Elastic"],"content_html":"\u003cp\u003eThis detection logic focuses on identifying potential adversary attempts to impair security monitoring on an endpoint by detecting a lack of expected telemetry following a security alert. When an endpoint security agent generates an alert, the system is expected to continue logging routine activities such as process execution, network connections, file system modifications, and DNS queries. A sudden, complete silence in these event categories within a 10-minute window following an alert often indicates that the security agent has been tampered with, disabled, or that the host system has crashed as a result of malicious interference. This technique is a common defensive evasion strategy used to prevent further monitoring or attribution after an initial intrusion detection. Defenders should prioritize these events to differentiate between malicious tampering and benign operational events such as system reboots, agent upgrades, or network connectivity failures.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful suppression of security telemetry prevents SOC analysts from observing subsequent attacker actions, including lateral movement, credential access, and exfiltration. This leads to extended dwell time, potential loss of forensic visibility, and the possibility of undetected persistent access within the targeted network environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the detection logic to identify hosts that experience a complete cessation of telemetry following a security alert.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline of normal agent behavior to minimize false positives associated with legitimate system reboots or agent maintenance.\u003c/li\u003e\n\u003cli\u003eIntegrate host health monitoring (e.g., agent heartbeat status) with SIEM alerts to correlate telemetry gaps with potential service crashes or unauthorized service terminations.\u003c/li\u003e\n\u003cli\u003eInvestigate the root cause of the alert immediately preceding the telemetry silence to determine if it aligns with known adversary TTPs or malware execution patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T11:28:44Z","date_published":"2026-08-27T11:28:44Z","id":"https://feed.craftedsignal.io/briefs/2026-08-elastic-defend-telemetry-loss/","summary":"This detection identifies adversary attempts to impair security monitoring by detecting a complete cessation of host telemetry immediately following a security alert generated by the Elastic Defend agent.","title":"Detection of Potential Defense Evasion via Endpoint Telemetry Suppression","url":"https://feed.craftedsignal.io/briefs/2026-08-elastic-defend-telemetry-loss/"}],"language":"en","title":"CraftedSignal Threat Feed - Telemetry-Suppression","version":"https://jsonfeed.org/version/1.1"}