Project Beat
- 2 days ago
- 2 min read
"Testing detection isn't about outsmarting the defenders; it's about ensuring the defense can see what matters."
đ§Why double down on Linux security right now?
With the sheer volume of Linux vulnerabilities hitting the headlines this year, resting on our security posture wasn't an option. Cybersift needed to know: When an attacker lands on our clientsâ Linux servers, can our SIEM actually see what's happening beneath the noise?
That was when we launched Project BEAT, a joint Purple Team exercise between our SOC and Pen-Testing department.
đĽ Breaking Down the Attack Vectors
Instead of chasing perimeter evasion tricks, we focused on testing real-world adversary behavior across key Linux attack vectors:
Enumeration & Discovery:Â Active port scans and local system reconnaissance
Authentication Attacks:Â SSH, FTP, and SMB brute-forcing
Execution & Exploitation:Â Web app exploits, command injection, and spawning reverse shells
Noise Generation:Â Blending malicious commands directly into heavy background traffic
Every command and timing window was meticulously logged down to the second, in order to be able to make direct comparisons to what the Blue Team discovers when triaging logs and assessing the alerts generated.
đ¤ CyberBot: Automated AI Triage in Action
Tracking raw system telemetry manually is tough, but CyberSift brought heavy firepower: CyberBot, CyberSift's proprietary AI-driven agent.
CyberBot automatically ingested, assessed, and triaged our raw Auditbeat (Linux) logs and endpoint telemetry, turning overwhelming process trees into clear, structured incident timelines.

The conclusion of CyberBot's report
"Raw telemetry is just noise until detection engineering turns it into actionable visibility."
đ Balancing Existing Rules with New Visibility

The results were eye-opening:
Solid Existing Baseline:Â We already had a substantial rule library in place that triggered plenty of alerts across standard attack vectors.
Hunting the Silent Gaps:Â By digging through raw Auditbeat process execution logs alongside CyberBot's analysis, we uncovered the stealthier actions that bypassed automated thresholds.
Permanent Defensive Upgrades:Â We didn't just observe, we wrote and deployed brand new detection rules throughout the exercise, turning newly discovered gaps into permanent, long-term defensive capabilities against real threats.

Project BEAT proved the value of bringing offensive and defensive teams together. By pairing Red Team attack simulations directly with Blue Team log analysis, CyberSift achieved three major milestones:
Clear Visibility:Â Verified that critical Linux system logs were capturing real-world attacks.
Stronger Defenses:Â Designed and deployed brand-new security rules to block stealthy attack paths. All new rules can be found at https://rules.cybersift.io/
Faster Response:Â Proved that CyberBot can automatically process heavy log traffic and surface actual threats without delay.
True security isn't about Red beating Blue, it's about working as a unified team to build lasting defenses. When defenders and testers share the same goals, security gets better, faster
-Written by Katrina Fenech and Brandon Spiteri



