Australia’s Cyber Security Centre (ACSC), alongside 15 international agencies, has issued updated guidance on best practices for event logging and threat detection. The advice highlights a growing global consensus: effective cybersecurity depends not only on capturing log data but ensuring that logging systems are resilient, tamper-proof, and contextually rich enough to reveal emerging threats particularly living-off-the-land (LOTL) attacks.
The challenge, however, lies in the fact that traditional logging often falls short. Operational Technology (OT) systems, Internet of Things (IoT) devices, and even network appliances typically have limited or non-existent logging capabilities. For these environments, the ACSC guidance recommends supplementing event logs with external sensors and network telemetry to provide visibility where native logs cannot.
The Gaps in Traditional Logging
Event logs have long been the foundation of threat detection and forensic analysis. But as threat actors evolve often blending seamlessly into legitimate network traffic organisations face a critical problem: many attack vectors now bypass or disable standard logging mechanisms altogether.
According to the new ACSC-aligned guidance, effective logging should:
-
Capture data relevant to security, not just system performance
-
Indicate lateral movement and living-off-the-land (LOTL) techniques
-
Prevent unauthorised log modification or deletion
Unfortunately, most legacy systems and OT environments were never designed with these goals in mind. Without the ability to generate detailed or reliable logs, defenders are left with blind spots — gaps adversaries are all too ready to exploit.
As the guidance notes, log tampering remains “cyberattack 101”. Once inside a network, attackers frequently disable logging agents or erase evidence of intrusion. This reality underscores why reliance solely on endpoint or application logs is no longer sufficient.
The Case for Network-Derived Telemetry
This is where network-derived telemetry comes in. Unlike application logs, which depend on the host system’s integrity, telemetry data is observed externally meaning it cannot be modified or erased by an attacker operating within the compromised system.
Network-derived telemetry acts as both a sensor and a verification source, offering:
-
Visibility into OT, IoT, and network appliances with limited or no native logging
-
Protection against log tampering, since data is collected out-of-band
-
Deeper context for threat detection and correlation across multiple sources
-
Support for high-quality logging, as recommended by the ACSC and partner agencies
By pairing packet-level visibility with metadata analysis, organisations can detect early indicators of lateral movement, command-and-control communications, and LOTL activity that traditional systems overlook.
LOTL: The Hidden Threat
The ACSC’s updated guidance references living-off-the-land activity 17 times, reflecting its growing prominence as a global threat. LOTL attacks exploit legitimate tools — such as PowerShell, WMI, or system processes to hide malicious intent and evade detection.
These attacks rarely generate clear signatures, meaning conventional logging alone often fails to spot them. Network-level analysis, on the other hand, can reveal subtle deviations in behaviour: unusual data flows, authentication anomalies, or unauthorised administrative actions that betray an attacker’s presence.
By supplementing logs with telemetry, defenders gain behavioural visibility the ability to detect and correlate suspicious patterns even when attackers operate within legitimate processes.
Global Consensus, Local Imperative
The ACSC guidance was developed in partnership with 15 international cybersecurity agencies, including those from the US, UK, Canada, Singapore, and Germany. This unified stance reflects a recognition that visibility is now the cornerstone of cyber defence.
For Australian organisations, particularly those operating in critical infrastructure sectors such as energy, logistics, and manufacturing, the implications are clear:
-
OT and IoT devices require external visibility sources such as network sensors
-
Event logging must move beyond basic compliance and toward security-driven observability
-
Metadata and network telemetry should be integrated into threat detection frameworks
As hybrid networks become more complex and data volumes surge, this hybrid approach combining logs, telemetry, and analytics provides the most comprehensive picture of cyber risk.
From Compliance to Confidence
Traditional log management has reached its limits. As the ACSC’s latest guidance makes clear, achieving true cyber resilience requires organisations to see beyond what’s logged.
By adopting deep observability bringing together network-derived telemetry and high-quality event logs security teams can detect LOTL attacks earlier, reduce investigation times, and strengthen incident response capabilities.
In short, when it comes to defending Australia’s critical digital systems, visibility isn’t optional it’s foundational.








