28. The Eyes That Never Closed
Domain: Security Operations — Logging, SIEM, Detection Engineering, Threat Hunting POV: Thread Reading time: ~15 minutes
The Archive of Record had always kept logs, but the logs had been passive — a record of what had happened, stored on shelves and consulted only when someone needed to verify a fact or resolve a dispute. The logs had been the city’s memory, but they had not been its awareness. They recorded the past. They did not see the present.
Thread changed that.
The log aggregation system that Thread designed and built over the course of a month was unlike anything the Citadel had ever attempted. Every mechanism in the city — every gear-train and boundary controller and automaton and communication relay — was configured to send its operational data to a central collection point. Not just significant events — gate openings and access requests and system failures — but everything. Every heartbeat of every mechanism. Every message that crossed a network boundary. Every command issued to every automaton. The volume of data was enormous — far more than any human could process, far more than the Archive’s old system could have stored. But Thread was not relying on human processing.
The collection point — a reinforced chamber deep beneath the Spire, protected by the same segmentation and access controls that guarded the city’s most sensitive infrastructure — housed a mechanism of Thread’s own design: a specialized gear-train that processed the incoming data in real time, comparing every event to a library of known patterns. The patterns — “detection rules,” Quill called them, drawing on the terminology of the old treatises — were descriptions of behavior that indicated a potential compromise. A command issued to an automaton from an unauthorized source. A message crossing a segment boundary without proper authentication. A sequence of access requests that matched the pattern of Vale’s known agents.
When the mechanism detected a pattern match, it generated an alert. The alert was sent to a console in the shed, where one of the fellowship — usually Thread, sometimes Sable, occasionally Kip or Wren — was always on duty, monitoring the city’s operational status. Every alert was investigated. Not every alert was a genuine compromise — the system still generated false positives, patterns that looked like attacks but were actually ordinary operational variation — but every alert was checked, because the cost of missing a genuine compromise was too high to accept any false negatives.
“This is what the treatises call a SIEM,” Quill said, watching the system process its first batch of incoming data. “Security Information and Event Management. A centralized platform that collects operational data from across the organization, correlates it to identify patterns, and generates alerts for investigation.”
“It is also a detection engineering platform,” Sable added. “The rules that generate the alerts are not static. They evolve as we learn more about the adversary’s techniques. Every time Vale’s agents attempt a new kind of attack, we analyze the attack and develop new rules to detect similar attempts in the future. The system learns.”
The SIEM’s most significant detection came three weeks after it went online.
A pattern of access requests — subtle, distributed across multiple systems, designed to avoid triggering any single alert — was flagged by a correlation rule that Thread had written specifically to detect lateral movement: the adversary’s technique of compromising one system and then using it as a platform to attack adjacent systems. The pattern was faint — a single anomalous request in the Spire’s access log, a second in the Library’s restricted section, a third in the gear-works’ supply inventory — and individually, none of the requests would have triggered an alert. But the SIEM correlated the three requests, identified them as part of a single pattern, and generated an alert.
Thread investigated. The investigation led to an archivist — a woman named Dara, who had been working in the Library for fifteen years and who had never been flagged as a potential threat. Dara had been recruited by Vale not through blackmail or bribery but through ideology — she genuinely believed that the old laws needed to be rewritten, that Vale’s vision for the city was superior to the existing order, that the chaos of the Shroud was a necessary precursor to the new world that would emerge from its ashes. She was not acting on instructions from Vale — she had not been in contact with Vale for months, ever since the investigation had driven him deeper underground. She was acting on her own initiative, using the access she still possessed to probe the city’s defenses and look for weaknesses.
“Threat hunting,” Thread said, when the council convened to discuss the detection. “The SIEM detected a pattern that individual systems could not see. But the pattern was not predefined — it was discovered through active searching, through the investigation of anomalies that did not match any existing rule. That is the difference between detection engineering and threat hunting. Detection engineering waits for the adversary to trigger a known rule. Threat hunting actively searches for anomalies that might indicate an unknown threat.”
“And you found one,” Penric said.
“Yes. Dara was operating alone, without Vale’s direct guidance. She was experimenting — trying different techniques, seeing which ones would be detected and which ones would pass unnoticed. She was, in effect, testing our defenses. And because we were hunting rather than passively monitoring, we found her before she found a vulnerability she could exploit.”
The SIEM was not perfect. It generated too many alerts — the false positive rate, even after weeks of tuning, was higher than Thread wanted. It missed attacks that were too subtle or too novel to match any existing rule. And it required constant maintenance — new rules to be written, old rules to be tuned, the endless churn of a system that was always playing catch-up with an adversary who was always evolving.
But it was better than what had come before — infinitely better, because what had come before was nothing. Before the SIEM, there was no centralized monitoring, no correlation of events, no systematic detection of compromise. The city had been blind, navigating by memory and instinct, unaware of the attacks that were happening around it. Now the city had eyes — imperfect eyes, but eyes nonetheless — and the adversary could no longer move unseen.
“Logging,” Thread said, late one night in the shed, reviewing the latest batch of alerts. “That is the foundation. Without logs, there is no detection. Without detection, there is no response. And without response, there is no defense. Everything we have built — the walls, the barriers, the cryptographic systems, the access controls — depends on our ability to know when those defenses have been breached. The logs tell us. The SIEM interprets what the logs are saying. And we — the people watching the console — are the ones who decide what to do about it.”
Thread paused, and the only sound in the shed was the quiet hum of the monitoring console and the distant, steady beat of the gear-trains beneath the floor. “The adversary is always watching. Now, so are we.”