Threat Detection

EventSentry monitors every phase of an attack

Detection is malware-agnostic: instead of relying on signatures of known threats, EventSentry monitors hosts and networks from multiple vantage points and flags the behaviors every attack must perform.

5/5
Attack phases covered
20+
Detection features
24/7
Monitoring
Real-time
Alerting & dashboards

Source: EventSentry Threat Detection Guide, NETIKUS.NET ltd, 2025

The attack lifecycle

One chain of events, five chances to break it

Attacks progress left to right through predictable stages, and EventSentry places detection at every handoff. The earlier the attacker is detected, the smaller the impact.

0

Reconnaissance

Optional

Researching the target, often via social media or resource scanning

1

Delivery

Clipboard monitoring

Malware reaches the target through phishing, malvertising, and poisoned repos

2

Exploitation

Patch & port visibility

Code runs by exploiting a weakness such as zero-days, RDP, or USB

3

Persistence

Change detection

Embeds to survive reboots via tasks, services, registry, and DLLs

4

Propagation

Anomaly detection

Spreads laterally with stolen credentials and pass-the-hash

5

Execution

File auditing & entropy

Payload fires: ransomware, data theft, botnet, APT

Because detection is behavior-based rather than signature-based, even zero-day attacks with no known signature trip at least one wire.

1

Phase 1 of 5

Delivery

Attackers reach targets through phishing, social engineering, malvertising, watering-hole sites, and poisoned open-source repositories. EventSentry adds a real-time safeguard at the endpoint.

EventSentry benefits

Clipboard monitoring

Detects and protects against clipboard-based attacks by monitoring the clipboard in real time. When suspicious data appears, EventSentry can clear the clipboard immediately and alert both the user and the admin.

2

Phase 2 of 5

Exploitation

Delivered code exploits zero-days, unpatched software, weak configurations, malicious USB devices, or exposed RDP. EventSentry shrinks each of these openings and watches the ones that remain.

EventSentry benefits

OS & patch validation vs. unpatched software

Validation Scripts identify any Windows OS that is behind on patches or end-of-life; Patch Monitoring shows every installed patch per host with full history; Software Monitoring tracks installed software with version checks for common applications.

Port & log monitoring vs. vulnerable configuration

Port monitoring identifies new listening ports, and all open ports across the network can be queried to find unnecessary ones. Log files are monitored in real time so critical activity such as failed logins and configuration changes is alerted immediately.

Storage audit & USB inventory vs. malicious USB devices

Verifies Windows storage auditing is enabled on every endpoint, and detects and alerts when USB devices are attached or removed, with all storage devices visible in web-based reporting.

RDP auditing & anomaly detection vs. RDP abuse

All successful and failed logons are monitored with out-of-the-box reports; Netstat monitoring inventories hosts listening on port 3389; NetFlow captures RDP traffic. Anomaly monitoring flags logons from previously unknown users or IPs, and collector-side thresholds surface lateral movement.

3

Phase 3 of 5

Persistence

Malware embeds via scheduled tasks, services, registry autoruns, DLL injection, browser extensions, IFEO debuggers, and rootkits, usually disguised with innocuous names like "SystemUpdate". EventSentry treats every persistence write as a detectable change.

EventSentry benefits

Task Scheduler monitoring vs. scheduled tasks

Creation, deletion, or change of any scheduled task can be logged and alerted in near real-time, with a complete inventory and full change history in the Web Reports.

Service monitoring vs. malicious services & drivers

Service and driver creation, deletion, and status changes generate alerts, backed by a complete inventory and change history across the fleet.

Autorun monitoring vs. registry persistence

Monitors the many registry and file locations where applications can register to auto-start at logon, detecting changes in real time for investigation.

Sysmon-powered DLL detection vs. DLL injection / side-loading

Combines Sysmon ImageLoad events with anomaly detection to baseline which DLLs each process loads and alert on new ones, and with content filter rules that verify digital signatures, flagging unsigned DLLs loaded into signed processes. A Validation Script also identifies insecure AppInit settings.

Browser extension inventory vs. malicious extensions

Inventories every installed extension across Chrome, Firefox, and Edge fleet-wide in seconds, and alerts on extensions being added, updated, or removed.

IFEO validation vs. debugger persistence

The "Threat Intel: Persistence - Debugger" Validation Script identifies insecure Image File Execution Options settings before they can be abused.

Precursor detection vs. rootkits

Once installed, a kernel rootkit hides from everyone, so EventSentry focuses on catching the malicious activity that precedes installation, via anomaly detection, Sysmon integration, service & driver inventory, and advanced event log analysis.

4

Phase 4 of 5 ยท Optional

Propagation

Malware spreads laterally via credential theft, brute force, internal vulnerabilities, pass-the-hash, and abused admin tools ("living off the land"). EventSentry monitors the inside of the network as closely as the perimeter.

EventSentry benefits

Anomaly detection vs. credential theft & lateral movement

Flags processes never before seen on a host, unusual usage of administrative tools, and logons from previously unknown users or IP addresses. Collector-side threshold filters surface lateral movement, the classic symptom of a pass-the-hash attack.

Sysmon behavioral events vs. credential dumping

Detects suspicious behavior such as attempts to access the lsass.exe process, the go-to source for dumping Windows credentials.

Validation Scripts vs. brute force & weak baselines

Verify that all Windows domains and hosts enforce strong password policies and account lockout, and flag insecure protocols, services, and settings. Custom organization-specific checks integrate into the built-in scripts.

Syslog & SNMP log collection vs. attacks on non-Windows devices

Failed authentication attempts from network devices and other non-Windows systems raise alerts too; brute force doesn't get a free pass off the domain.

Service & software tracking vs. living off the land

Detects newly installed drivers in near real-time and tracks all installed software, helping identify unneeded admin utilities that widen the attack surface.

5

Phase 5 of 5

Execution

The payload fires: ransomware encryption, data theft, botnet activity, or a dormant APT. Fast detection is what contains the damage, and EventSentry watches the signals each outcome can't avoid producing.

EventSentry benefits

File auditing vs. ransomware encryption

NTFS write-access auditing on critical files, combined with monitoring for excessive activity, reveals the high rate of file writes that mass encryption produces.

File entropy alerting vs. ransomware encryption

Encrypted files have measurably higher entropy than plain files, so alerting on high entropy catches encryption in progress rather than after the ransom note.

Behavior & activity monitoring vs. data theft & botnets

Anomaly detection surfaces reads of confidential data at unusual times or from unusual sources, while network traffic analysis and resource monitoring expose the network chatter and CPU spikes typical of bots and crypto mining.

Inventory & audit trail vs. dormant APTs

Dormant threats blend into normal activity, so the best defense is preventing installation and auditing regularly. EventSentry's inventories of applications, services, and tasks make irregular entries stand out.

How it all fits together

Many vantage points, one platform

The phase-by-phase detections above are powered by a common set of monitoring capabilities that observe every host and the network simultaneously.

01

Real-time log monitoring

  • Anomaly detection
  • Advanced log correlation (chains, timers, thresholds)
  • File integrity monitoring

02

Inventory monitoring

  • Scheduled tasks, services & drivers
  • Browser extensions & permissions
  • Software, patches & USB storage devices

03

Security & Active Directory

  • Validation Scripts & audit policy monitoring
  • User, group & computer inventory
  • Object & Group Policy monitoring

04

Audit, forensics & network

  • Process, logon & file access activity (incl. Sysmon, RDP)
  • Real-time security dashboards & forensic data collection
  • Traffic to/from malicious IPs & new device detection

Recommendation

Validating these benefits in your environment

Step 1

Deploy an agent

Install EventSentry against representative workstations, servers, and domain controllers, with Sysmon integration enabled.

Step 2

Simulate each phase

Create a scheduled task, trigger RDP logon anomalies, load an unsigned DLL, run a mass file-write test, and confirm each alert fires.

Step 3

Tune for alert fatigue

Malware hides behind common task names, so verify the baseline-and-anomaly approach keeps alert volume actionable for our team.

Step 4

Review Reports

Dashboards and built-in reports highlight the change activities on your network and help inform your response.